Beyond a Single Perspective: Towards a Realistic Evaluation of Website Fingerprinting Attacks
Xinhao Deng, Jingyou Chen, Linxiao Yu, Yixiang Zhang, Zhongyi Gu, Changhao Qiu, Xiyuan Zhao, Ke Xu, Qi Li
TL;DR
Website Fingerprinting threats persist even as defenses and complex browsing behaviors evolve. The authors introduce a multidimensional evaluation framework that tests WF attacks across six realistic conditions—defense mechanisms, traffic drift, multi-tab browsing, early-stage detection, open-world settings, and few-shot scenarios—using six specialized datasets. Across these conditions, state-of-the-art WF methods exhibit substantial degradation outside isolated setups, with no single approach remaining robust in all scenarios; deep models excel in controlled settings but falter under distribution shifts and mixed traffic. The work provides a unified benchmarking platform and actionable directions (multi-task learning, dynamic adversarial strategies, standardized datasets) to advance more robust and practical WF attacks and defenses, guiding researchers and practitioners toward realistic threat modeling and evaluation.
Abstract
Website Fingerprinting (WF) attacks exploit patterns in encrypted traffic to infer the websites visited by users, posing a serious threat to anonymous communication systems. Although recent WF techniques achieve over 90% accuracy in controlled experimental settings, most studies remain confined to single scenarios, overlooking the complexity of real-world environments. This paper presents the first systematic and comprehensive evaluation of existing WF attacks under diverse realistic conditions, including defense mechanisms, traffic drift, multi-tab browsing, early-stage detection, open-world settings, and few-shot scenarios. Experimental results show that many WF techniques with strong performance in isolated settings degrade significantly when facing other conditions. Since real-world environments often combine multiple challenges, current WF attacks are difficult to apply directly in practice. This study highlights the limitations of WF attacks and introduces a multidimensional evaluation framework, offering critical insights for developing more robust and practical WF attacks.
