Flow side channel information shaping defense method and system aiming at website fingerprint attack
By preprocessing the original traffic and generating adversarial network training, generating clear-purpose perturbations, the existing defense methods are solved, and efficient website fingerprint attack defense is achieved, suitable for a variety of deep learning models.
Patent Information
- Application Number
- CN202510290920.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-12-05
- Filing Date
- 2025-03-12
- Publication Date
- 2025-07-18
AI Technical Summary
The existing website fingerprint attack defense methods have problems such as low randomized perturbation efficiency, significant abnormal patterns and insufficient confusion, making it difficult to effectively defend against deep learning-based website fingerprint attacks.
By preprocessing the original traffic, a generative adversarial network is built, using the burst sequence as input data, the generator and discriminator are trained to generate clear-targeted perturbations, making the traffic disguised as a specified category, and using a comprehensive loss function to guide the generation of minimum perturbations, improving defense efficiency and confusion.
It significantly improves the defense effect against perturbations, reduces the accuracy of the attack model, enhances the concealment and confusion of defense, and is suitable for a variety of deep learning attack models, with high universality and defense capabilities.
Smart Images

Figure CN120342656A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network communication security, and particularly relates to a traffic side-channel information shaping defense method and system for website fingerprint attacks. Background Art
[0002] With the enhancement of network security awareness and the popularization of data encryption technology, the TLS protocol and its related applications (such as HTTPS and QUIC) are widely used to protect the privacy and integrity of network communication data. These protocols encrypt data at the transport layer and application layer, effectively preventing attackers from directly obtaining the communication content. However, the widespread application of encrypted traffic also brings new challenges, that is, traditional content-based network traffic analysis methods fail and cannot directly parse the actual content of data packets. This enables attackers to gradually shift their attention to the side-channel information in encrypted traffic and infer network behavior by analyzing the transmission characteristics of traffic.
[0003] Side-channel information refers to the non-content features exposed during the transmission of encrypted data packets, such as the size of data packets, time intervals, transmission directions, traffic patterns, etc. These features are usually not protected by encryption but can reflect the network behavior characteristics of users. For example, the loading order and resource request patterns of certain websites have certain uniqueness, and these features can be identified by analyzing side-channel information, thereby inferring the website that the user is accessing. This technology is called website fingerprint analysis (WF). In the environment of the increasing popularity of encrypted traffic, website fingerprint analysis has become a widely used tool for traffic classification and behavior inference.
[0004] However, the abuse of website fingerprint analysis technology has brought serious privacy and security problems. For example, by analyzing the encrypted traffic of users, attackers can identify the websites visited by users and even speculate on their behavior habits. This attack method based on side-channel information poses a serious threat to personal privacy, business secrets, and the anonymity of organizational behavior.
[0005] Traditional defense means mainly use methods such as traffic padding and time delay to confuse traffic characteristics, thereby reducing the success rate of attacks. However, with the development of machine learning and deep learning technologies, attack models can automatically learn traffic characteristics and extract high-dimensional feature representations, making the defense effect of traditional confusion methods limited. In this context, defense technologies based on adversarial sample generation and traffic deformation have gradually attracted attention. By introducing fine-grained perturbations and changing the side-channel characteristics of traffic, these technologies can effectively mislead attack models and thus protect user privacy.
[0006] In the prior art, the mainstream methods for website fingerprint attack defense mainly rely on the idea of randomization or non-target transformation (for example, masking the original traffic characteristics through random padding, traffic obfuscation, or other traffic perturbation methods). Although these methods can, to a certain extent, disrupt the classification ability of the attack model, they inherently have the following deficiencies:
[0007] (1) Prone to introducing abnormal patterns: Randomization or non-target transformation methods greatly perturb traffic characteristics, easily generating abnormal patterns inconsistent with real traffic. These abnormal patterns may attract the attention of attackers and even be exploited as new features for traffic classification, rendering the defense ineffective.
[0008] (2) Lack of pertinence and low perturbation efficiency: Randomization methods usually cannot clearly transform traffic characteristics into a specific pattern, resulting in excessive perturbation amplitude and low efficiency. In addition, this method fails to effectively utilize the feedback information of the target model to optimize the transformation strategy, thus not fully suppressing the misclassification ability of the attack model.
[0009] (3) Insufficient confusing ability: The results of non-target transformation are difficult to be consistent with real legitimate traffic patterns, and may cause further analysis or enhanced attacks by attackers due to lack of confusing ability, thereby reducing the defense effect. Summary of the Invention
[0010] The object of the present invention is to propose a traffic side-channel information shaping defense method and system for website fingerprint attacks, aiming to achieve a more efficient and confusing defense effect through targeted traffic characteristic transformation, and solve the technical problems such as low randomization perturbation efficiency, significant abnormal patterns, and insufficient confusing ability of existing website fingerprint attack defense methods.
[0011] The technical solution adopted by the present invention to achieve its object is as follows:
[0012] A traffic side-channel information shaping defense method for website fingerprint attacks, comprising the following steps:
[0013] 1) Preprocess the original traffic data to obtain burst sequences in the traffic data; each burst sequence is composed of the direction bursts of a network flow, and each direction burst represents the number of consecutive packets in the same direction in the data stream, and the positive or negative value is used to distinguish the transmission direction of the packets;
[0014] 2) Use the burst sequences as input data to train a deep learning-based website fingerprint attack model, and optimize its classification accuracy through iterative training;
[0015] 3) Construct a generative adversarial network. Its generator generates perturbations based on the gradient information of the website fingerprint attack model, making the perturbed traffic close to the target category. Its discriminator is used to distinguish the authenticity of the input traffic. Through joint adversarial training of the generator and the discriminator, generate the minimum perturbation that can deceive the website fingerprint attack model.
[0016] 4) Preprocess the network traffic to be defended, and input the obtained burst sequence into the trained generator to generate perturbed traffic, making it disguise as the target category traffic.
[0017] Further, the steps of preprocessing the original traffic data in step 1) include:
[0018] Segment the original traffic in units of network flows and divide it into multiple data blocks.
[0019] Remove duplicate traffic data.
[0020] Extract side-channel features, which are the packet directions of the packets in the network flow.
[0021] Scan continuously co-directional packets to generate burst values and obtain a burst sequence. Positive and negative values represent directions, and the value size represents the number of consecutive packets.
[0022] Further, the website fingerprint attack model in step 2) is a classifier based on a convolutional neural network or a long short-term memory network.
[0023] Further, when training the generator in step 3), minimizing the generator loss is the training objective. The generator loss includes forged traffic loss, perturbation distance loss, and transformation loss, where the transformation loss consists of weight loss and target category loss.
[0024] Further, the perturbation distance loss minimizes the size of the perturbation through the L1 norm.
[0025] Further, the calculation steps of the weight loss include:
[0026] Calculate the cross-entropy loss between the category of the perturbed traffic and the target category as the target category loss.
[0027] For each non-target category, calculate the cross-entropy loss between it and the classification result of the perturbed traffic as the non-target category loss.
[0028] Calculate the loss difference between the target category loss and each non-target category loss. When the loss difference is not zero, take the difference value, otherwise take zero.
[0029] If the standard deviation is greater than zero, normalize the loss difference.
[0030] Calculate the weighted loss difference to obtain the weighted loss.
[0031] Further, when training the discriminator in step 3), the training objective is to minimize the discriminator loss; the discriminator loss includes the real original class loss, the real target class loss, and the forged traffic loss, and all these three losses are calculated by the binary cross-entropy loss function.
[0032] A traffic side-channel information shaping defense system against website fingerprint attacks, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, it implements the steps of the above method.
[0033] The technical effects achieved by the present invention are as follows:
[0034] 1. The present invention proposes a traffic transformation method based on the target class, enabling the side-channel features of the traffic to be directly disguised as a specified legal class. For example, the target traffic is disguised as the mainstream traffic pattern, thereby inducing the website fingerprint attack model to misclassify the original traffic as the target class, avoiding the problem that the existing randomization-based defense methods are prone to introducing abnormal patterns, significantly reducing the accuracy of the attack model, and enhancing the concealment and confusion of the defense.
[0035] 2. The present invention integrates the number of consecutive packets in the same direction into a single feature, compresses the direction sequence into a burst sequence, and uses the burst sequence as the core feature of the traffic side-channel information, significantly reducing data redundancy, reducing processing complexity, and improving the efficiency of feature processing and the expression ability of side-channel information.
[0036] 3. The present invention designs a generative adversarial network. By jointly training its generator and discriminator, using the gradient information of the website fingerprint attack model to guide the generator to generate the minimum perturbation, and generating adversarial perturbations that can effectively confuse the website fingerprint attack model by superimposing targeted adversarial samples, thereby realizing the target-oriented transformation of traffic, and significantly improving the efficiency and pertinence of the defense.
[0037] 4. The present invention proposes a comprehensive loss function including weighted loss, which not only considers the direct loss difference between the target class and other classes, but also improves the targetness and concealment of perturbation generation through normalization and weighting, enabling the generated adversarial perturbations to achieve a higher success rate in target class transformation.
[0038] 5. The present invention is verified for multiple datasets and various traffic classification models, proving that it can be widely adapted to deep learning attack models in different scenarios, and has high universality and effectiveness, especially showing excellent defense capabilities in both white-box and black-box scenarios. Description of the Drawings
[0039] Figure 1It is the flowchart of the traffic side-channel information shaping defense method for website fingerprint attacks according to the present invention.
[0040] Figure 2 It is the transformation effect diagram in the white-box scenario.
[0041] Figure 3 It is the transformation effect diagram in the black-box scenario. Specific implementation manners
[0042] To make the technical features and advantages or technical effects in the above technical solutions of the present invention more obvious and understandable, the following will be described in detail through embodiments.
[0043] In the embodiments of the present invention, for website fingerprint attacks based on deep learning, a traffic side-channel information shaping defense method is proposed. The purpose is to disguise the original category traffic as the target category traffic. The original category refers to the true category of the traffic, while the target category refers to the category that wants to be disguised as. For example, to make traffic of category A disguised as traffic of category B, the processing method is to add the generated perturbation to the traffic of category A so that it is detected as category B by the website fingerprint attack model. The formulaic description is as follows:
[0044] F(x) = class A
[0045] F(x') = class B, x' = x + δ
[0046] Where F represents the website fingerprint attack model, x represents the original traffic, δ represents the generated perturbation, and x' is the traffic after perturbation (i.e., forged traffic).
[0047] The overall process of this method is as Figure 1 shown, and the specific processing steps are as follows:
[0048] S1: Preprocessing of original traffic data
[0049] Mainstream website fingerprint attack models based on deep learning usually use the sequence of network flow packet directions in encrypted traffic as the model input. The packet direction sequence is a sequence composed of +1 and -1, where +1 represents a traffic packet from the client (C) to the server (S) (i.e., C2S, upstream traffic), and -1 represents a traffic packet from the server (S) to the client (C) (i.e., S2C, downstream traffic). Its drawback is that the analysis and transformation efficiency of side-channel information is very low.
[0050] To improve the analysis and transformation efficiency of side-channel information, this method preprocesses the collected original network traffic data, including traffic fragmentation, traffic deduplication, side-channel feature extraction, and data format conversion, etc., converting the packet direction sequence into a burst sequence. Among them, by scanning consecutive packets in the same direction in the direction sequence, they are aggregated into burst values. A burst refers to the number of consecutive traffic packets in the same direction in a network flow. In a network flow, multiple consecutive traffic packets with the same direction can be regarded as a burst sequence. The burst sequence is a high-level representation of the traffic direction sequence and can more compactly reflect the side-channel features (such as packet direction) in the network flow. The representation method of the burst sequence is similar to that of the packet direction sequence, using positive and negative values to represent the traffic direction. Among them, a positive value (such as +2) represents C2S traffic, and a negative value (such as -3) represents S2C traffic. The difference is that the numerical size represents the number of consecutive packets. Compared with directly using the packet direction sequence, the burst sequence can compress the direction information, making the side-channel features more intuitive and facilitating the subsequent generation of adversarial perturbations. For example, in a network direction sequence [+1, +1, -1, -1, -1, +1, -1, -1], the first segment of consecutive packets with a direction of +1 forms a burst with a size of +2; the second segment of consecutive packets with a direction of -1 forms a burst with a size of -3; and so on. The final burst sequence is [+2, -3, +1, -2]. This processing step can effectively compress the traffic features, improve the efficiency of subsequent adversarial perturbation generation and traffic shaping, and at the same time retain the key side-channel information of the traffic.
[0051] S2: Website fingerprint attack model training
[0052] First, select a standard classifier based on deep learning as the website fingerprint attack model, such as a classifier based on a convolutional neural network (CNN) or a long short-term memory network (LSTM), to learn the features of classifying traffic side-channel information, aiming to accurately classify the categories of traffic and form an adversarial reference for subsequent perturbation generation. Then, use the processed burst sequence as the input data, divide the dataset into a training set and a test set, and optimize the classification accuracy of the model through iterative training.
[0053] S3: Generative adversarial network training
[0054] Build a Generative Adversarial Network (GAN), which includes three main modules: a Generator, a Discriminator, and a target model (website fingerprint attack model). The task of the Generator is to generate the smallest perturbation and superimpose it on the original traffic so that the perturbed traffic is misclassified as the target category. By optimizing the loss function, adversarial perturbations that can deceive the Discriminator are generated. The task of the Discriminator is to distinguish between real traffic and forged traffic, and the optimization goal is to maximize the classification ability. The target model is a trained website fingerprint attack model, which is used to identify the category of traffic and feedback it to the training of the Generator. The Generator and the Discriminator need to be jointly trained adversarially to achieve a game balance between them, so that the generated perturbation has strong concealment and target orientation.
[0055] (1) Generator
[0056] During the training process of the Generator, guided by the gradient information of the website fingerprint attack model, perturbations with target type characteristics are generated. Therefore, the Generator loss needs to include the loss that the website fingerprint attack model identifies the perturbed traffic as the target category, that is, the target category loss (Cross-entropy loss is used here). Specifically, the Generator loss consists of three parts: The first part is the forged traffic loss That is, the loss that the Discriminator distinguishes the perturbed traffic as forged traffic; the second part is the distance loss of the perturbation To find the smallest possible perturbation, the L1 norm is used here; the third part is the transformation loss Used to make the perturbed traffic as close as possible to the target category and far from all other categories. The training goal of the Generator is to minimize the Generator loss, and the formula is as follows:
[0057]
[0058] Among them, Is the weight loss, which is used to measure the loss difference between the target category loss and the losses of other categories. Specifically, it is the cross-entropy loss difference, ensuring that the generated perturbation can make the traffic be classified as the target category. Is the target category loss, which calculates the difference between the category of the perturbed traffic and the target category, and is used to ensure that the generated perturbation can make the traffic close to the target category.
[0059] Weight loss The calculation process is as follows:
[0060] First, calculate the target category loss And the loss difference Between the target category loss and the loss of each other category The loss difference is specifically the cross - entropy loss when the website fingerprint attack model detects that the traffic data belongs to a specified category. When the loss difference is non - zero, its difference value is taken; otherwise, zero is taken. When the difference is non - zero, for the website fingerprint attack model, the class confidence of the perturbed traffic relative to the original traffic is closer to the specified target category rather than other categories; when the difference is zero, it means that the perturbed traffic has not successfully made the classification result closer to the target category, or it has been misclassified as other categories.
[0061] Then, normalize the difference to obtain the normalized loss difference where normalization is only performed when the standard deviation S > 0.
[0062] Finally, calculate the weighted loss difference, that is, the weighted loss
[0063] Weighted loss The calculation formula is as follows:
[0064]
[0065] (2) Discriminator
[0066] The discriminator is optimized during training and can distinguish the authenticity of the input traffic, that is, it performs a binary classification task of distinguishing true from false. The discriminator loss consists of three parts: The first part is the real original class loss This is the loss when the discriminator correctly classifies the traffic as the original class traffic; the second part is the real target class loss This is the loss when the discriminator classifies the perturbed traffic as the target class traffic; the forged traffic loss This is the loss when the discriminator classifies the perturbed traffic as forged traffic. By maximizing this loss, the discriminator can learn and improve its ability to distinguish real traffic from forged traffic. The above three parts are all calculated through the binary cross - entropy loss function. The training objective of the discriminator is to minimize the discriminator loss, and the formula is as follows:
[0067]
[0068] where x s is the original traffic, x d is the traffic recognized as the target class by the website fingerprint attack model, and x′ s is the perturbed traffic.
[0069] S4: Use the generator to perturb the network traffic
[0070] After the generator is trained, the network traffic to be defended is preprocessed and then input into the generator to generate perturbations. The perturbations are superimposed on the original traffic to obtain the perturbed traffic, which is disguised as the specified target category, thereby interfering with the classification of the website fingerprint attack model.
[0071] Experimental verification:
[0072] The present invention verifies the adversarial effect of the target model in white-box and black-box scenarios and compares it with existing related methods. In the white-box scenario, the structure of the target model is known, so precise adversarial attacks can be carried out against this model; while in the black-box scenario, since the structure of the target model is unknown, only similar surrogate models can be used to implement adversarial attacks.
[0073] Before testing the corresponding scenarios, the following relevant metrics need to be clarified first, mainly focusing on the confusion ratio and the transformation ratio.
[0074] 1. Confusion ratio = (Number of original successful detections - Number of successful detections after confusion) / Number of original successful detections;
[0075] 2. Transformation ratio = Number of samples detected as the target category / Number of samples of the original category in the dataset;
[0076] 3. Bandwidth overhead = Number of packets with perturbations added / Number of packets in the original flow.
[0077] Two publicly available traffic direction datasets collected from the Tor browser are used in the dataset. One is the dataset from Sirinam (the traffic collected by the work "Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep Learning"), and the other is the dataset from Rimmer (the traffic collected by the work "Automated Website Fingerprinting through Deep Learning"). The dataset from Sirinam contains traffic of 95 classes, with 1000 direction sequences for each class. For the dataset from Rimmer, the dataset containing 200 classes is used, and this dataset has 2500 direction sequences for each class.
[0078] White-box scenario: The target model is used for training and the confusion results are verified using the target model. Two datasets are used to test three models, namely DF, AWF, and VarCNN. The samples with class label 0 in the selected dataset are regarded as the original category traffic, and the remaining all classes are used as the target traffic for transformation experiments. The confusion ratio and the transformation ratio are as Figure 2As shown in Table 1, the results show the perturbation rate and morphing rate of three models (DF, AWF, VarCNN) on two datasets (Sirinam, Rimmer200). Each subgraph represents the performance of a model on a certain dataset, where the blue line represents the perturbation rate and the orange line represents the morphing rate. From the above results, it can be seen that the morphing ratio is different when transforming different data as the target, but the perturbation ratio is close to 1 for most data.
[0079] Table 1 Comprehensive results of confusion and transformation in the white-box scenario
[0080]
[0081] Black-box scenario: Train with the target model and test the confusion results with other models. Use DF as the target model for TMGAN training, use AWF and VarCNN as the test models, and use two datasets for testing. Select the samples with class label 0 in the dataset as the original class traffic, and perform transformation experiments on the remaining all classes as the target traffic. The perturbation ratio and morphing ratio are as Figure 3 shown. This set of graphs shows the results of the perturbation rate and morphing rate of using the DF model for training against the AWF and VarCNN models on the Sirinam and Rimmer200 datasets. From these graphs, it can be seen that in the black-box scenario, the method of the present invention still has a certain effectiveness. The morphing ratio has decreased, but the perturbation ratio is still mostly close to 1, and the perturbation ratio of individual data has decreased significantly.
[0082] Although the present invention has been disclosed above by way of examples, it is not intended to limit the present invention. Any appropriate modification or equivalent replacement of the technical solutions of the present invention by those of ordinary skill in the art shall be covered within the protection scope of the present invention. The protection scope of the present invention shall be subject to that defined by the claims.
Claims
1. A traffic side-channel information shaping defense method against website fingerprint attacks, characterized in that It includes the following steps: 1) Preprocess the original traffic data to obtain the burst sequences in the traffic data; each burst sequence consists of the direction bursts of a network flow, and each direction burst represents the number of consecutive packets in the same direction in the data stream, and the positive or negative value of the number is used to distinguish the transmission direction of the packets; 2) Use the burst sequences as input data to train a website fingerprint attack model based on deep learning, and optimize its classification accuracy through iterative training; 3) Construct a generative adversarial network, and its generator generates perturbations according to the gradient information of the website fingerprint attack model, so that the perturbed traffic is close to the target category; Its discriminator is used to distinguish the authenticity of the input traffic; through joint adversarial training of the generator and the discriminator, generate the minimum perturbation that can deceive the website fingerprint attack model; 4) Preprocess the network traffic to be defended, and input the obtained burst sequences into the trained generator to generate perturbed traffic, so that it is disguised as traffic of the target category.
2. The method according to claim 1, wherein The steps of preprocessing the original traffic data in step 1) include: Segment the original traffic in units of network flows into multiple data blocks; Remove duplicate traffic data; Extract side-channel features, and the side-channel features are the packet directions of the packets in the network flow; Scan consecutive packets in the same direction to generate burst values to obtain burst sequences, where positive and negative values represent directions and the value size represents the number of consecutive packets.
3. The method according to claim 1, characterized in that In step 2), the website fingerprint attack model is a classifier based on a convolutional neural network or a long short-term memory network.
4. The method according to claim 1, wherein When training the generator in step 3), the training objective is to minimize the generator loss; the generator loss includes forged traffic loss, perturbation distance loss, and transformation loss, where the transformation loss consists of weight loss and target category loss.
5. The method according to claim 4, wherein The perturbation distance loss minimizes the size of the perturbation through the L1 norm.
6. The method according to claim 4, wherein The calculation steps of the weight loss include: Calculate the cross-entropy loss between the category of the perturbed traffic and the target category as the target category loss; For each non-target category, calculate the cross-entropy loss between it and the classification result of the perturbed traffic as the non-target category loss; Calculate the loss difference between the target category loss and each non-target category loss, and when the loss difference is not zero, take the difference value, otherwise take zero; If the standard deviation is greater than zero, normalize the loss difference; Calculate the weighted loss difference to obtain the weight loss.
7. The method according to claim 1, wherein When training the discriminator in step 3), the training objective is to minimize the discriminator loss; the discriminator loss includes real original category loss, real target category loss, and forged traffic loss, and these three losses are all calculated by the binary cross-entropy loss function.
8. A traffic side-channel information shaping defense system against website fingerprinting attacks, characterized in that, It includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the steps of the method described in any one of claims 1-7.