Defense-aware autoencoder (DAAE) attacks can recover website fingerprinting accuracy against defenses that successfully resist adversarial training. On the GTT23 dataset, DAAE-based DF attacks achieve over 90% accuracy against RegulaTor and over 80% against Palette and Adaptive Tamaraw, despite those defenses reducing unaugmented DF attack accuracy from 93.2% to 2–35%. Adversarial training robustness and DAAE robustness are distinct and non-interchangeable properties.
From 2026-cui-chameleon-robust-defense — Chameleon: Robust Defense Against Tor Website Fingerprinting via Many-to-Many Traffic Morphing
· §I, Figure 1
· 2026
· arXiv preprint
Implications
Do not rely on defenses that apply deterministic or stable traffic transformations; an attacker with access to paired original/defended traces can train an autoencoder to strip the defense pattern.
Treat DAAE-resistance as a separate, required evaluation criterion alongside adversarial-training resistance when assessing any traffic-shaping defense.