{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T13:48:00Z","timestamp":1782308880709,"version":"3.54.5"},"reference-count":182,"publisher":"Association for Computing Machinery (ACM)","issue":"13","license":[{"start":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T00:00:00Z","timestamp":1782259200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"CAIR DRDO"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,10,31]]},"abstract":"<jats:p>Anonymity networks like Tor protect the end users privacy by hiding the browsing activity. However, this protection is often abused for online activities which are not legal. We find works in the literature, which tend to reveal the identities of users with advanced traffic analysis. Contrary to these, there are also works which thwart such traffic analysis to protect users\u2019 identities. The first class of work is known as website fingerprinting (WF) and mainly rely on machine learning and deep learning algorithms to analyze encrypted traffic. The second class of work has several defense mechanisms to counter website fingerprinting attacks. In this article, we provide an in-depth analysis of both website fingerprinting attacks and defenses covering recent advancements in the domain. First, we look at WF attacks by dividing them into two groups: those using traditional machine learning techniques, and the others using deep learning models. Next, we provide detailed coverage of defense mechanisms. We also cover details of publicly available datasets, commonly used evaluation metrics for assessing the robustness of the WF, and experimental tools used for traffic analysis. Finally, we highlight some important research gaps that need to be filled to make progress towards designing robust attack frameworks.<\/jats:p>","DOI":"10.1145\/3817115","type":"journal-article","created":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T11:20:41Z","timestamp":1779448841000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Website Fingerprinting Attacks and Defense Techniques: A Survey"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-7984-585X","authenticated-orcid":false,"given":"Pankaj","family":"Chaudhary","sequence":"first","affiliation":[{"name":"Computer Science and Engineering, Indian Institute of Technology Indore","place":["Indore, India"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0340-8480","authenticated-orcid":false,"given":"Aditi","family":"Aralkar","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Indian Institute of Technology Indore","place":["Indore, India"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9669-9773","authenticated-orcid":false,"given":"Neminath","family":"Hubballi","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Indian Institute of Technology Indore","place":["Indore, India"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-8131-3114","authenticated-orcid":false,"given":"Vinduja","family":"T","sequence":"additional","affiliation":[{"name":"Computer Science and Engineering, Indian Institute of Technology Indore","place":["Indore, India"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9536-037X","authenticated-orcid":false,"given":"Paromita","family":"Choudhury","sequence":"additional","affiliation":[{"name":"Center for Artificial Intelligence and Robotics, DRDO","place":["Bengaluru, India"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1807-5487","authenticated-orcid":false,"given":"Manjesh Kumar","family":"Hanawal","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Bombay","place":["Mumbai, India"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,24]]},"reference":[{"key":"e_1_3_4_2_2","unstructured":"Cloudflare annual report. 2023. Retrieved May 12 2026 from https:\/\/blog.cloudflare.com\/radar-2023-year-in-review"},{"key":"e_1_3_4_3_2","unstructured":"Statista report. 2025. Retrieved May 12 2026 from https:\/\/www.statista.com\/topics\/1145\/internet-usage-worldwide\/"},{"key":"e_1_3_4_4_2","doi-asserted-by":"publisher","DOI":"10.21236\/ADA465464"},{"key":"e_1_3_4_5_2","unstructured":"Tor Project. 2026. Retrieved May 12 2026 from https:\/\/www.torproject.org\/"},{"key":"e_1_3_4_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44702-4_4"},{"key":"e_1_3_4_7_2","unstructured":"The Invisible Internet Project. 2026. Retrieved May 12 2026 from https:\/\/geti2p.net\/en\/"},{"key":"e_1_3_4_8_2","unstructured":"JAP Anonymity & Privacy. 2026. Retrieved May 12 2026 from https:\/\/anon.inf.tu-dresden.de\/index_en.html"},{"key":"e_1_3_4_9_2","unstructured":"Tor Metrics. 2026. Retrieved May 12 2026 from https:\/\/metrics.torproject.org\/"},{"key":"e_1_3_4_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/1655008.1655013"},{"key":"e_1_3_4_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2046556.2046570"},{"issue":"0","key":"e_1_3_4_12_2","first-page":"15","article-title":"Fingerprinting attack on tor anonymity using deep learning","volume":"42","author":"Abe Kota","year":"2016","unstructured":"Kota Abe and Shigeki Goto. 2016. Fingerprinting attack on tor anonymity using deep learning. Proceedings of the Asia-Pacific Advanced Network 42, 0 (2016), 15\u201320.","journal-title":"Proceedings of the Asia-Pacific Advanced Network"},{"key":"e_1_3_4_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2021.3093615"},{"key":"e_1_3_4_14_2","doi-asserted-by":"publisher","DOI":"10.5555\/1765299.1765312"},{"key":"e_1_3_4_15_2","first-page":"143","volume-title":"Proceedings of the 23rd USENIX Security Symposium (USENIX Security 14)","author":"Wang Tao","year":"2014","unstructured":"Tao Wang, Xiang Cai, Rishab Nithyanand, Rob Johnson, and Ian Goldberg. 2014. Effective attacks and provable defenses for website fingerprinting. In Proceedings of the 23rd USENIX Security Symposium (USENIX Security 14). 143\u2013157."},{"key":"e_1_3_4_16_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23477"},{"key":"e_1_3_4_17_2","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2016-0027"},{"key":"e_1_3_4_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103980"},{"key":"e_1_3_4_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3433586"},{"key":"e_1_3_4_20_2","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0039"},{"key":"e_1_3_4_21_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45744-4_2"},{"key":"e_1_3_4_22_2","first-page":"1375","volume-title":"Proceedings of the 26th USENIX Security Symposium (USENIX Security 17)","author":"Wang Tao","year":"2017","unstructured":"Tao Wang and Ian Goldberg. 2017. Walkie-Talkie: An efficient defense against passive website fingerprinting attacks. In Proceedings of the 26th USENIX Security Symposium (USENIX Security 17). 1375\u20131390."},{"key":"e_1_3_4_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486875"},{"key":"e_1_3_4_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00247"},{"key":"e_1_3_4_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM52122.2024.10621205"},{"key":"e_1_3_4_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3457904"},{"key":"e_1_3_4_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3208196"},{"key":"e_1_3_4_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3386040"},{"key":"e_1_3_4_29_2","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/3363335"},{"key":"e_1_3_4_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2453434"},{"key":"e_1_3_4_31_2","first-page":"1","volume-title":"Proceedings of the ITASEC","author":"Cambiaso Enrico","year":"2019","unstructured":"Enrico Cambiaso, Ivan Vaccari, Luca Patti, and Maurizio Aiello. 2019. Darknet security: A categorization of attacks to the tor network.. In Proceedings of the ITASEC. 1\u201312."},{"key":"e_1_3_4_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIoT48696.2020.9089497"},{"key":"e_1_3_4_33_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2023.103582"},{"key":"e_1_3_4_34_2","volume-title":"Comparing Website Fingerprinting Attacks and Defenses","author":"Wang Tao","year":"2014","unstructured":"Tao Wang and Ian Goldberg. 2014. Comparing Website Fingerprinting Attacks and Defenses. Technical Report. University of Waterloo."},{"key":"e_1_3_4_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179289"},{"key":"e_1_3_4_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3253559"},{"key":"e_1_3_4_37_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103577"},{"key":"e_1_3_4_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC53001.2021.9631528"},{"key":"e_1_3_4_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC50000.2020.9219717"},{"key":"e_1_3_4_40_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23105"},{"key":"e_1_3_4_41_2","first-page":"1187","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security 16)","author":"Hayes Jamie","year":"2016","unstructured":"Jamie Hayes and George Danezis. 2016. k-fingerprinting: A robust scalable website fingerprinting technique. In Proceedings of the 25th USENIX Security Symposium (USENIX Security 16). 1187\u20131203."},{"key":"e_1_3_4_42_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0070"},{"key":"e_1_3_4_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243768"},{"key":"e_1_3_4_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS59830.2024.10575874"},{"key":"e_1_3_4_45_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2024.110217"},{"key":"e_1_3_4_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3520014"},{"key":"e_1_3_4_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180437"},{"key":"e_1_3_4_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660368"},{"key":"e_1_3_4_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSCWD.2015.7230964"},{"key":"e_1_3_4_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2017.2762825"},{"key":"e_1_3_4_51_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2019.09.008"},{"key":"e_1_3_4_52_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS) 2021","author":"Kim Donghoon","year":"2021","unstructured":"Donghoon Kim, Loc Ho, Young-Ho Kim, Won-gyum Kim, and Doosung Hwang. 2021. Poster: A pilot study on real-time fingerprinting for Tor onion services. In Proceedings of the Network and Distributed System Security Symposium (NDSS) 2021."},{"key":"e_1_3_4_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243832"},{"key":"e_1_3_4_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.1900366"},{"key":"e_1_3_4_55_2","unstructured":"CUMUL. 2016. Retrieved May 12 2026 from https:\/\/www.informatik.tu-cottbus.de\/andriy\/zwiebelfreunde\/"},{"key":"e_1_3_4_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488676"},{"key":"e_1_3_4_57_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109780"},{"key":"e_1_3_4_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/2517840.2517851"},{"key":"e_1_3_4_59_2","first-page":"753","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security 22)","author":"Cherubin Giovanni","year":"2022","unstructured":"Giovanni Cherubin, Rob Jansen, and Carmela Troncoso. 2022. Online website fingerprinting: Evaluating website fingerprinting attacks on Tor in the real world. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22). 753\u2013770."},{"key":"e_1_3_4_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338498.3358650"},{"key":"e_1_3_4_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2023.3318508"},{"key":"e_1_3_4_62_2","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/SECPRI.2002.1004359","volume-title":"Proceedings 2002 IEEE Symposium on Security and Privacy","author":"Sun Qixiang","year":"2002","unstructured":"Qixiang Sun, Daniel R. Simon, Yi-Min Wang, Wilf Russell, Venkata N. Padmanabhan, and Lili Qiu. 2002. Statistical identification of encrypted web browsing traffic. In Proceedings 2002 IEEE Symposium on Security and Privacy. 19\u201330."},{"key":"e_1_3_4_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939918.2939922"},{"key":"e_1_3_4_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-64185-0_4"},{"key":"e_1_3_4_65_2","first-page":"199","volume-title":"Proceedings of the 2020 IFIP Networking Conference (Networking)","author":"Ghi\u00ebtte Vincent","year":"2020","unstructured":"Vincent Ghi\u00ebtte and Christian Doerr. 2020. Scaling website fingerprinting. In Proceedings of the 2020 IFIP Networking Conference (Networking). 199\u2013207."},{"key":"e_1_3_4_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382260"},{"key":"e_1_3_4_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICICS60529.2023.10330516"},{"key":"e_1_3_4_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00015"},{"key":"e_1_3_4_69_2","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329802"},{"key":"e_1_3_4_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274697"},{"key":"e_1_3_4_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3104869"},{"key":"e_1_3_4_72_2","doi-asserted-by":"publisher","DOI":"10.1504\/IJICS.2025.148112"},{"key":"e_1_3_4_73_2","first-page":"4139","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24)","author":"Mitseva Asya","year":"2024","unstructured":"Asya Mitseva and Andriy Panchenko. 2024. Stop, don\u2019t click here anymore: Boosting website fingerprinting by considering sets of subpages. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24). 4139\u20134156."},{"key":"e_1_3_4_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM55648.2025.11044569"},{"key":"e_1_3_4_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSCWD.2014.6846826"},{"key":"e_1_3_4_76_2","doi-asserted-by":"publisher","DOI":"10.23919\/TST.2017.8195352"},{"key":"e_1_3_4_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/3267323.3268960"},{"key":"e_1_3_4_78_2","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489253"},{"key":"e_1_3_4_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3158086"},{"key":"e_1_3_4_80_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.123236"},{"key":"e_1_3_4_81_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0043"},{"key":"e_1_3_4_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/LCN48667.2020.9314785"},{"key":"e_1_3_4_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_4_84_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0043"},{"key":"e_1_3_4_85_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2022.108770"},{"key":"e_1_3_4_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM52122.2024.10621235"},{"key":"e_1_3_4_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179464"},{"key":"e_1_3_4_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00154"},{"key":"e_1_3_4_89_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485891"},{"key":"e_1_3_4_90_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623107"},{"key":"e_1_3_4_91_2","doi-asserted-by":"publisher","DOI":"10.26599\/TST.2024.9010073"},{"key":"e_1_3_4_92_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2025.104125"},{"key":"e_1_3_4_93_2","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690211"},{"key":"e_1_3_4_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN52387.2021.9534421"},{"key":"e_1_3_4_95_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3050608"},{"key":"e_1_3_4_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCCN.2024.3350531"},{"key":"e_1_3_4_97_2","doi-asserted-by":"publisher","DOI":"10.1109\/IRI51335.2021.00044"},{"key":"e_1_3_4_98_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS47774.2020.00058"},{"key":"e_1_3_4_99_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354217"},{"key":"e_1_3_4_100_2","doi-asserted-by":"publisher","DOI":"10.1109\/IPCCC55026.2022.9894323"},{"key":"e_1_3_4_101_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108298"},{"key":"e_1_3_4_102_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.108739"},{"key":"e_1_3_4_103_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0029"},{"key":"e_1_3_4_104_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616639"},{"key":"e_1_3_4_105_2","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645575"},{"key":"e_1_3_4_106_2","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670272"},{"key":"e_1_3_4_107_2","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3357993"},{"key":"e_1_3_4_108_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3318966"},{"key":"e_1_3_4_109_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2025.3538895"},{"key":"e_1_3_4_110_2","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620272"},{"key":"e_1_3_4_111_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS)","volume":"9","author":"Wright Charles V.","year":"2009","unstructured":"Charles V. Wright, Scott E. Coull, and Fabian Monrose. 2009. Traffic morphing: An efficient defense against statistical traffic analysis.. In Proceedings of the Network and Distributed System Security Symposium (NDSS), Vol. 9."},{"key":"e_1_3_4_112_2","doi-asserted-by":"publisher","DOI":"10.1145\/3422337.3447835"},{"key":"e_1_3_4_113_2","doi-asserted-by":"publisher","DOI":"10.1145\/3696410.3714811"},{"key":"e_1_3_4_114_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.28"},{"key":"e_1_3_4_115_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3304528"},{"key":"e_1_3_4_116_2","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660362"},{"key":"e_1_3_4_117_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_4_118_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC50000.2020.9219593"},{"key":"e_1_3_4_119_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2023.3337270"},{"key":"e_1_3_4_120_2","first-page":"2705","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security 21)","author":"Nasr Milad","year":"2021","unstructured":"Milad Nasr, Alireza Bahramali, and Amir Houmansadr. 2021. Defeating DNN-based traffic analysis systems in real-time with blind adversarial perturbations. In Proceedings of the 30th USENIX Security Symposium (USENIX Security 21). 2705\u20132722."},{"key":"e_1_3_4_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3436818"},{"key":"e_1_3_4_122_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0049"},{"key":"e_1_3_4_123_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3186743"},{"key":"e_1_3_4_124_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS)","volume":"11","author":"Luo Xiapu","year":"2011","unstructured":"Xiapu Luo, Peng Zhou, Edmond W. W. Chan, Wenke Lee, Rocky K. C. Chang, and Roberto Perdisci. 2011. HTTPOS: Sealing information leaks with browser-side obfuscation of encrypted flows. In Proceedings of the Network and Distributed System Security Symposium (NDSS), Vol. 11."},{"key":"e_1_3_4_125_2","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2017-0023"},{"key":"e_1_3_4_126_2","doi-asserted-by":"publisher","DOI":"10.1145\/2665943.2665949"},{"key":"e_1_3_4_127_2","doi-asserted-by":"publisher","DOI":"10.1145\/2665943.2665950"},{"key":"e_1_3_4_128_2","doi-asserted-by":"publisher","DOI":"10.1007\/11863908_2"},{"key":"e_1_3_4_129_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-46677-9_8"},{"key":"e_1_3_4_130_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2018.00175"},{"key":"e_1_3_4_131_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2907240"},{"key":"e_1_3_4_132_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3327662"},{"key":"e_1_3_4_133_2","unstructured":"Tobias Pulls. 2020. Towards effective and efficient padding machines for tor. arXiv:2011.13471. Retrieved from https:\/\/arxiv.org\/abs\/2011.13471"},{"key":"e_1_3_4_134_2","first-page":"771","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security 22)","author":"Smith Jean-Pierre","year":"2022","unstructured":"Jean-Pierre Smith, Luca Dolfi, Prateek Mittal, and Adrian Perrig. 2022. QCSD: A QUIC client-side website-fingerprinting defence framework. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22). 771\u2013789."},{"key":"e_1_3_4_135_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423351"},{"key":"e_1_3_4_136_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0019"},{"key":"e_1_3_4_137_2","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2019.8802772"},{"key":"e_1_3_4_138_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833722"},{"key":"e_1_3_4_139_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM41043.2020.9155465"},{"key":"e_1_3_4_140_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3074295"},{"key":"e_1_3_4_141_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278493"},{"key":"e_1_3_4_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3039691"},{"key":"e_1_3_4_143_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796685"},{"key":"e_1_3_4_144_2","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0047"},{"key":"e_1_3_4_145_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2023.103733"},{"key":"e_1_3_4_146_2","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/7330465"},{"key":"e_1_3_4_147_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2024.3360082"},{"key":"e_1_3_4_148_2","unstructured":"DF. 2018. Retrieved May 12 2026 from https:\/\/github.com\/deep-fingerprinting\/df"},{"key":"e_1_3_4_149_2","unstructured":"AWF. 2018. Retrieved May 12 2026 from https:\/\/tor-wf-dl.distrinet-research.be\/"},{"key":"e_1_3_4_150_2","unstructured":"Mockingbird. 2021. Retrieved May 12 2026 from https:\/\/github.com\/msrocean\/mockingbird\/"},{"key":"e_1_3_4_151_2","unstructured":"Var-CNN. 2019. Retrieved May 12 2026 from https:\/\/github.com\/sanjit-bhat\/Var-CNN"},{"key":"e_1_3_4_152_2","unstructured":"Tik-Tok. 2020. Retrieved May 12 2026 from http:\/\/surl.li\/qyevm"},{"key":"e_1_3_4_153_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134005"},{"key":"e_1_3_4_154_2","unstructured":"GANDaLF. 2021. Retrieved May 12 2026 from https:\/\/github.com\/traffic-analysis\/gandalf"},{"key":"e_1_3_4_155_2","unstructured":"Wangs dataset. 2013. Retrieved May 12 2026 from https:\/\/www.cs.sfu.ca\/taowang\/wf\/index.html"},{"key":"e_1_3_4_156_2","unstructured":"CrossTraceWF. 2021. Retrieved May 12 2026 from http:\/\/surl.li\/qyewm"},{"key":"e_1_3_4_157_2","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0125"},{"key":"e_1_3_4_158_2","unstructured":"Wireshark. 2026. Retrieved May 12 2026 from https:\/\/www.wireshark.org\/"},{"key":"e_1_3_4_159_2","unstructured":"tcpdump. 2025. Retrieved May 12 2026 from https:\/\/www.tcpdump.org\/"},{"key":"e_1_3_4_160_2","unstructured":"Scapy. 2026. Retrieved May 12 2026 from https:\/\/scapy.net\/"},{"key":"e_1_3_4_161_2","unstructured":"dpkt Python Library. 2022. Retrieved May 12 2026 from https:\/\/dpkt.readthedocs.io\/en\/latest\/"},{"key":"e_1_3_4_162_2","unstructured":"Shadowsocks. 2025. Retrieved May 12 2026 from https:\/\/shadowsocks.org\/"},{"key":"e_1_3_4_163_2","unstructured":"SOCKS Protocol. 1996. Retrieved May 12 2026 from https:\/\/datatracker.ietf.org\/doc\/html\/rfc1928"},{"key":"e_1_3_4_164_2","unstructured":"Torsocks. 2026. Retrieved May 12 2026 from https:\/\/gitlab.torproject.org\/tpo\/core\/torsocks\/"},{"key":"e_1_3_4_165_2","unstructured":"Project V. 2019. Retrieved May 12 2026 from https:\/\/www.v2ray.com\/"},{"key":"e_1_3_4_166_2","unstructured":"Selenium Browser Automation. 2025. Retrieved May 12 2026 from https:\/\/www.selenium.dev\/"},{"key":"e_1_3_4_167_2","unstructured":"Tor Browser automation with Selenium. 2023. Retrieved May 12 2026 from https:\/\/github.com\/webfp\/tor-browser-selenium"},{"key":"e_1_3_4_168_2","unstructured":"Scrapy. 2016. Retrieved May 12 2026 from https:\/\/scrapy.org\/"},{"key":"e_1_3_4_169_2","unstructured":"PyAutoGUI module. 2023. Retrieved May 12 2026 from https:\/\/pypi.org\/project\/PyAutoGUI\/"},{"key":"e_1_3_4_170_2","unstructured":"Tampermonkey. 2010. Retrieved May 12 2026 from https:\/\/www.tampermonkey.net\/"},{"key":"e_1_3_4_171_2","unstructured":"Scriptish. 2013. Retrieved May 12 2026 from https:\/\/scriptish.github.io\/"},{"key":"e_1_3_4_172_2","doi-asserted-by":"publisher","DOI":"10.1109\/CARS61786.2024.10778686"},{"key":"e_1_3_4_173_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2988369"},{"key":"e_1_3_4_174_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2025.111811"},{"key":"e_1_3_4_175_2","first-page":"399","volume-title":"Proceedings of the 2025 USENIX Annual Technical Conference","author":"Wang Zihao","year":"2025","unstructured":"Zihao Wang, Qing Li, Guorui Xie, Dan Zhao, Kejun Li, Zhuochen Fan, Lianbo Ma, and Yong Jiang. 2025. Minos: A lightweight and dynamic defense against traffic analysis in programmable data planes. In Proceedings of the 2025 USENIX Annual Technical Conference. 399\u2013415."},{"key":"e_1_3_4_176_2","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627191"},{"key":"e_1_3_4_177_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3565994"},{"key":"e_1_3_4_178_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-021-01605-0"},{"key":"e_1_3_4_179_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.52"},{"key":"e_1_3_4_180_2","doi-asserted-by":"crossref","unstructured":"NIST Privacy Framework. 2020. Retrieved May 12 2026 from https:\/\/www.nist.gov\/privacy-framework","DOI":"10.6028\/NIST.CSWP.40.ipd"},{"key":"e_1_3_4_181_2","unstructured":"DPF. 2023. Retrieved May 12 2026 from https:\/\/www.dataprivacyframework.gov\/"},{"key":"e_1_3_4_182_2","unstructured":"WCAG. 2025. Retrieved May 12 2026 from https:\/\/www.w3.org\/TR\/WCAG21\/"},{"key":"e_1_3_4_183_2","unstructured":"GDPR. 2016. Retrieved May 12 2026 from https:\/\/gdpr-info.eu\/"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3817115","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T13:05:48Z","timestamp":1782306348000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3817115"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,24]]},"references-count":182,"journal-issue":{"issue":"13","published-print":{"date-parts":[[2026,10,31]]}},"alternative-id":["10.1145\/3817115"],"URL":"https:\/\/doi.org\/10.1145\/3817115","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,24]]},"assertion":[{"value":"2025-03-18","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-26","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-06-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}