FINDING · EVALUATION

Chameleon's defense remains robust against randomization-aware attackers who augment training with up to K=20 independently randomized defended variants per trace. On the GTT23 dataset, even at K=20, DF, Var-CNN, RF, and NetCLR achieve only 17.50%, 18.82%, 31.06%, and 17.04% accuracy respectively — well below the 100-class closed-world ceiling — confirming that protection does not depend on limiting the attacker's exposure to defended traffic samples.

From 2026-cui-chameleon-robust-defenseChameleon: Robust Defense Against Tor Website Fingerprinting via Many-to-Many Traffic Morphing · §V-E, Table VII · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
website-fingerprintml-classifier
defenses
randomizationpluggable-transporttor

Extracted by claude-sonnet-4-6 — review before relying.