Using only 1,000-packet windows of signed packet lengths and inter-arrival times (no payload, no URLs, no cookies), a passive adversary achieves approximately 84% accuracy at inferring behavioral persona in a mixed-site open-world setting spanning 10 modern websites and 15 canonical personas plus an open-world class. Per-site persona macro-F1 typically ranges from about 0.78 to 0.91 across representative platforms including Bilibili, eBay, Yahoo, Zhihu, and LinkedIn.
From 2026-song-personafingerprint-measuring-persona — PersonaFingerprint: Measuring Persona Inference on Modern Websites with LLM-Driven Browsing
· §5.3, §5.5, Abstract
· 2026
· arXiv preprint
Implications
Traffic shaping for Tor/VPN circumvention must disrupt session-level behavioral rhythms (interaction cadence, dwell-and-scroll patterns, navigation breadth), not just per-packet size distributions, since these behavioral signatures persist across sites and are learnable from short 1,000-packet windows.
Circumvention tools should evaluate defenses against persona-level fingerprinting in addition to site-level fingerprinting, as both attack surfaces coexist at the same network vantage point (ISP, VPN provider, enterprise gateway).