Mockingbird: Defending Against Deep-Learning-Based Website Fingerprinting Attacks With Adversarial Traces

Mockingbird: Defending Against Deep-Learning-Based Website Fingerprinting Attacks With Adversarial Traces
复制标题

DOI:
10.1109/tifs.2020.3039691
复制
发表时间:
2019-02
影响因子:
6.8
通讯作者:
Mohammad Saidur Rahman;M. Imani;Nate Mathews;M. Wright
Mohammad Saidur Rahman;M. Imani;Nate Mathews;M. Wright
中科院分区:
计算机科学1区
文献类型:
--
作者:
Mohammad Saidur Rahman;M. Imani;Nate Mathews;M. Wright

文献摘要

被引文献

相似文献

网站指纹识别(WF)是一种流量分析攻击,即使流量受到VPN或像TOR这样的匿名系统的保护,也可以推断受害者的活动。在本文中,我们可以在本文中获得超过98%的准确性。机器学习分类器在其他域中。然后,我们提出了模拟鸟可预测的梯度。该技术降低了最先进的攻击的精度,而对抗性训练从98%到42-58%,而只有58%的带宽上限。 - 在考虑TOP-2准确性时进行防御和较低,同时会产生较低的带宽开销。
Website Fingerprinting (WF) is a type of traffic analysis attack that enables a local passive eavesdropper to infer the victim’s activity, even when the traffic is protected by a VPN or an anonymity system like Tor. Leveraging a deep-learning classifier, a WF attacker can gain over 98% accuracy on Tor traffic. In this paper, we explore a novel defense, Mockingbird, based on the idea of adversarial examples that have been shown to undermine machine-learning classifiers in other domains. Since the attacker gets to design and train his attack classifier based on the defense, we first demonstrate that at a straightforward technique for generating adversarial-example based traces fails to protect against an attacker using adversarial training for robust classification. We then propose Mockingbird, a technique for generating traces that resists adversarial training by moving randomly in the space of viable traces and not following more predictable gradients. The technique drops the accuracy of the state-of-the-art attack hardened with adversarial training from 98% to 42–58% while incurring only 58% bandwidth overhead. The attack accuracy is generally lower than state-of-the-art defenses, and much lower when considering Top-2 accuracy, while incurring lower bandwidth overheads.