FINDING · DEFENSE
The detector constructs its 'typical ratio' baseline exclusively from the 50 largest jurisdictions, then discards outliers beyond four inter-quartile ranges of the median before fitting N(m,v). This ensures a jurisdiction undergoing active censorship cannot bias the global model and mask its own anomaly.
From 2011-danezis-anomaly-based — An anomaly-based censorship-detection system for Tor · §4 · 2011 · The Tor Project
Implications
- Censorship-detection pipelines should apply IQR-based outlier removal on large-jurisdiction baselines so that a censored country cannot corrupt the reference distribution.
- Strictly separate the model-building population from the tested population to prevent adversarial drift of the 'normal' baseline.
Tags
Extracted by claude-sonnet-4-6 — review before relying.