arXiv AI By Runhan Song, Qiqi Liu, Chuanzhou Pan, Zhenquan Ding, Youquan Xian, Chongru Fan, Lei Cui, Wei Wang, Zhiyu Hao

CipherSight: Robust Website Fingerprinting via Record-Resource Semantic Supervision under Distribution Shifts

Read the original on arXiv AI →

arXiv:2608. 13905v1 Announce Type: cross Abstract: HTTPS website fingerprinting (WF) aims to identify visited websites from metadata observable in encrypted traffic.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv Machine Learning
Jun 17

ResAware: Cross-Environment Website Fingerprinting via Resource-Privileged Distillation

arXiv:2606. 17462v1 Announce Type: new Abstract: While Website Fingerprinting (WF) attacks achieve high accuracy in controlled laboratory settings, they often degrade substantially in real-world environments due to spatio-temporal drift, browser heterogeneity, proxy obfuscation and etc.

By Chongru Fan, Wei Wang, Wentao Huang, Zhenquan Ding, Jinqiao Shi, Lei Cui, Zhiyu Hao, Xiaochun Yun
arXiv Machine Learning
Sep 25

FlowAtom: Atom-Based Evidence Aggregation for Multi-Label Website Fingerprinting

FlowAtom is a new method for multi‑label website fingerprinting that aggregates evidence from encrypted traffic flows into shared prototypes called Atoms. It pre‑trains a flow encoder on unlabeled traffic, then combines Atom responses across flows within each observation window to produce a fixed‑dimensional, permutation‑invariant representation for predicting which monitored websites were visited. In closed‑world tests on Direct HTTPS, Trojan, and VMess traffic, FlowAtom achieves micro‑F1 scores of 97.82%, 94.43%, and 93.92% respectively, and consistently outperforms baseline approaches in open‑world scenarios involving monitored visits.

By Chongru Fan, Wentao Huang, Wei Wang, Zhenquan Ding, Jinqiao Shi, Wei Cai, Zhiyu Hao
arXiv Machine Learning
Jun 29

CO-DEFEND: Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection

arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.

By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga