FINDING · EVALUATION

A GAN-based adversarial transformer applied to Meek traffic signatures increases mean classifier FPR from 0.183 to 0.834 and decreases mean area under the precision-recall curve (PR-AUC) from 0.990 to 0.414 across naive neural network, informed neural network, and CART decision tree classifiers evaluated on three geographically distinct datasets (residential, university, AWS).

From 2019-sheffey-improvingImproving Meek With Adversarial Techniques · §5 Results, Tables 1–2 · 2019 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
ml-classifiertraffic-shape
defenses
randomizationmeek

Extracted by claude-sonnet-4-6 — review before relying.