FINDING · DETECTION

An adaptive censor that retrains classifiers on both unmodified and GAN-transformed Meek traffic ('informed NN') partially recovers detection capability: informed NN achieves a PR-AUC of 0.440 against modified traffic versus 0.309 for the naive NN, and achieves FPR of 0.667 versus 1.000 for the naive NN. However, the informed NN suffers from catastrophic interference and performs worse on FPR than the naive classifier on unmodified data (0.545 vs. 0.002).

From 2019-sheffey-improvingImproving Meek With Adversarial Techniques · §5 Results, §6 Discussion · 2019 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
ml-classifier
defenses
randomizationmeek

Extracted by claude-sonnet-4-6 — review before relying.