Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Var-CNN: A Data-Efficient Website Fingerprinting Attack Based on Deep Learning

About

In recent years, there have been several works that use website fingerprinting techniques to enable a local adversary to determine which website a Tor user visits. While the current state-of-the-art attack, which uses deep learning, outperforms prior art with medium to large amounts of data, it attains marginal to no accuracy improvements when both use small amounts of training data. In this work, we propose Var-CNN, a website fingerprinting attack that leverages deep learning techniques along with novel insights specific to packet sequence classification. In open-world settings with large amounts of data, Var-CNN attains over $1\%$ higher true positive rate (TPR) than state-of-the-art attacks while achieving $4\times$ lower false positive rate (FPR). Var-CNN's improvements are especially notable in low-data scenarios, where it reduces the FPR of prior art by $3.12\%$ while increasing the TPR by $13\%$. Overall, insights used to develop Var-CNN can be applied to future deep learning based attacks, and substantially reduce the amount of training data needed to perform a successful website fingerprinting attack. This shortens the time needed for data collection and lowers the likelihood of having data staleness issues.

Sanjit Bhat, David Lu, Albert Kwon, Srinivas Devadas• 2018

Related benchmarks

TaskDatasetResultRank
Website FingerprintingMulti-tab Website Fingerprinting Open-world 2-tab
P@270.5
20
Website FingerprintingMulti-tab Website Fingerprinting Closed-world 3-tab
Precision@356.32
20
Website FingerprintingMulti-tab Website Fingerprinting Closed-world 5-tab
P@538.75
20
Website FingerprintingMulti-tab Website Fingerprinting Open-world 5-tab
P@539.39
20
Website FingerprintingMulti-tab Website Fingerprinting Open-world 4-tab
P@440.32
20
Binary Anomaly DetectionTor traffic dataset binary perturbation detection (test)
Accuracy74.46
12
Website FingerprintingTrafficSliver (2-tab)
AUC98.6
10
Multi-tab Website Fingerprinting AttackMulti-tab Website Fingerprinting Open-world 3-tab
AUC92.4
10
Website FingerprintingMulti-tab Website Fingerprinting Closed-world 2-tab
P@272.94
10
Website FingerprintingMulti-tab Website Fingerprinting Open-world 3-tab
P@357.89
10
Showing 10 of 15 rows

Other info

Follow for update