Flow feature confusion method based on AI virtual human
By generating obfuscated traffic through AI-driven virtual human agents, the problem of resisting traffic fingerprinting in existing technologies is solved, enabling the ability to resist traffic fingerprint analysis and protect user privacy.
Patent Information
- Application Number
- CN202511143147.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-04-21
- Filing Date
- 2025-08-15
- Publication Date
- 2025-11-14
AI Technical Summary
Existing host fingerprinting spoofing schemes are difficult to counter traffic fingerprinting-based tracking technologies. Advertisers can identify and track users by analyzing the dynamic signal characteristics of network traffic, making it difficult to protect users' online privacy.
Using an AI-driven virtual human agent, obfuscated traffic is generated. By configuring the virtual human's basic attributes and behavioral strategies, it simulates human access to target sites, generating characteristic traffic. LLM-driven dynamic adjustment of behavioral parameters is used to disguise browser fingerprints and adjust traffic characteristics, generating fake traffic to cover up the real user characteristics.
It significantly enhances the ability to resist traffic fingerprinting analysis, protects users' online privacy, and the virtual human can generate obfuscated traffic around the clock to interfere with traffic signal feature analysis and prevent users from being tracked.
Smart Images

Figure CN120956479A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of information security, and in particular relates to a method for obfuscating traffic features based on AI virtual humans. Background Technology
[0002] Internet advertisers are constantly seeking new user identification and tracking technologies to more accurately target their ads. Currently, two main fingerprinting methods are used: host fingerprinting and traffic fingerprinting. Host fingerprinting is an identification method based on the attributes of the internet device, typically including the user's browser request headers, cookies, fonts, and display engine. Due to the static nature of host fingerprints, this information can be easily modified or erased by users through technical means. To overcome the limitations of this method, internet advertisers have begun to apply user identification methods based on traffic fingerprinting: instead of relying on the static attributes of the internet device, it constructs user fingerprints by analyzing the dynamic signal characteristics of network traffic. For example, the temporal characteristics of traffic, target distribution characteristics, and frequency domain characteristics (such as traffic spectrum analysis). These signal characteristics often directly reflect the user's online behavior habits, thus possessing high stability and difficulty in tampering.
[0003] For ordinary internet users, traditional device fingerprinting schemes (such as browser incognito mode) are no longer effective against traffic fingerprinting-based tracking technologies. To address this issue, this patent proposes a traffic feature obfuscation method based on virtual humans. Summary of the Invention
[0004] The purpose of this application is to overcome the problems of existing technologies by disclosing a traffic feature obfuscation method based on AI virtual humans. This method uses AI to drive a virtual human agent to autonomously generate obfuscated traffic on the network. This effectively interferes with and obfuscates user tracking methods based on traffic signal characteristics. This method significantly enhances the ability to resist traffic fingerprinting analysis, thereby effectively protecting users' online privacy.
[0005] The objective of this application is achieved through the following technical solution: A traffic feature obfuscation method based on AI virtual humans, the traffic feature obfuscation method based on AI virtual humans includes: S1. Configure the basic attributes and preset behavior policies of the virtual human, and automatically obtain the fingerprint of the user's Internet access device; S2. Virtual human environment fingerprint spoofing is achieved by configuring a containerized runtime environment and adjusting the browser fingerprint. S3. Based on preset parameters, LLM-driven dynamic generation determines the behavioral parameters of the virtual human in online tasks; S4: Based on the behavioral parameters obtained from S3, the virtual human calls the local browser driver online to simulate human access to the target site and generate characteristic traffic.
[0006] According to a preferred embodiment, step S1 includes: S11. Configure the basic attributes of the virtual human, including: gender, age, nationality, occupation, and hobbies; S12. Configure virtual human behavior strategies, including: activity time, target site, action interval rhythm, keywords and themes; S13. Obtain the user device fingerprint, including operating system version, browser header, time zone, language, and automation features.
[0007] According to a preferred embodiment, in step S2, the virtual human environment fingerprint is disguised as: cloning the static fingerprint of the real user's internet access device that is connected to the network with the virtual human, wherein the static fingerprint includes: browser header, hardware features, operating system version, and language environment.
[0008] According to a preferred embodiment, step S3 includes: S31. Construct prompt words that conform to the characteristics of virtual humans based on preset virtual human parameters and use them as LLM driver input; S32, LLM-driven autonomous generation of virtual human behavior parameters, including: language, target site, activity time, operation rhythm, search keywords, and access content preferences.
[0009] According to a preferred embodiment, step S4 includes: S41. The virtual human loads behavioral parameters and executes a list of tasks in a loop; S42. Determine if the task is within the specified execution time range. If not, wait for the task execution interval and then put the task back into the task loop list. If it is, proceed to S43. S43. Verify whether the task behavior policy configuration changes dynamically. If it changes, add the corresponding task to the task scheduling management engine and proceed to S46; if it does not change, proceed to S44. S44. Obtain the user's browser fingerprint and verify whether the fingerprint matches the browser driver. If they do not match, perform fingerprint spoofing in the browser driver once and then proceed to S45. If they match, proceed directly to S45. S45. Call the browser driver to asynchronously execute the virtual human task and return the browser window session handle of the current task; S46. The task scheduling engine determines whether the task behavior parameters have changed or whether the task has exceeded the execution time. If yes, the corresponding browser window is closed and the process proceeds to S47; otherwise, it continues to wait for the virtual human to execute the task. S47. Determine whether the virtual human has successfully executed the subtask. If successful, end the subtask. If unsuccessful, return the task to the task loop queue and proceed to S41.
[0010] According to a preferred embodiment, the process of generating characteristic traffic in step S4 includes: the traffic generated based on the network behavior of the virtual human agent and the real traffic generated by the user are combined into a traffic obfuscation module with a preset obfuscation strategy to generate characteristic traffic.
[0011] According to a preferred embodiment, step S4 further includes: the virtual human intelligently and adaptively adjusts the obfuscation strategy between virtual human traffic and real user traffic based on the current network environment, user operation behavior, and potential threat scenarios.
[0012] According to a preferred embodiment, the obfuscation strategy includes: 1) Traffic padding: On top of normal traffic, forged network packets are injected to fill idle time periods, increasing the uncertainty and randomness of traffic and masking the actual communication pattern; 2) Delayed traffic transmission: A random delay is set before the request is sent to disrupt the time series characteristics of the original traffic, making it difficult for traffic analysis tools to identify the real communication behavior time pattern. 3) Fake traffic: Regularly or randomly generate irrelevant traffic to simulate the diverse network behaviors of normal users, confuse traffic analysis systems and reduce the distinguishability of traffic characteristics; 4) Traffic pattern mimicry: Disguising sensitive communication traffic as typical non-sensitive traffic; 5) Multi-channel distribution: The original traffic is divided into several small traffic segments and transmitted through different paths or protocols.
[0013] According to a preferred embodiment, the irrelevant traffic includes: HTTP requests, video traffic, or DNS queries.
[0014] According to a preferred embodiment, the process of disguising sensitive communication traffic as typical non-sensitive traffic includes disguising file transfers as video streams.
[0015] The aforementioned main solution and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and are claimed in this application. Those skilled in the art, after understanding the solution of this application, will realize that there are many combinations based on the prior art and common general knowledge, all of which are technical solutions to be protected in this application, and will not be exhaustively listed here.
[0016] The beneficial effects of this application are: Using the method described in this application, when a user visits a target website, a virtual avatar accompanying them can generate spoofed traffic to mask the user's traffic signal characteristics, preventing advertisers from identifying and tracking the user through these characteristics. The virtual avatar can generate obfuscated traffic around the clock, continuing to do so even after the user logs off, constantly interfering with the target's analysis of the user's traffic signal characteristics. This significantly enhances the ability to counter traffic fingerprinting analysis, effectively protecting the user's online privacy. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating the traffic feature obfuscation method based on virtual humans used in this application; Figure 2 This is a schematic diagram illustrating the optimization of virtual human behavior characteristics based on LLM driving in this application; Figure 3 This is a schematic diagram of the autonomous action process of the virtual human-driven browser in this application; Figure 4 This is a schematic diagram of the operating environment structure of the virtual human behavior engine in this application. Detailed Implementation
[0018] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, unless otherwise specified, the following embodiments and features in the embodiments can be combined with each other.
[0019] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0020] refer to Figure 1 As shown, this application discloses a traffic feature obfuscation method based on AI virtual human, which mainly includes user configuration of virtual human basic attributes, fingerprint, target site and behavior strategy, virtual human agent engine generating network behavior and browser driver executing network operation, and entering the traffic obfuscation engine together with the traffic generated by the user and the traffic generated by the virtual human, and integrating the obfuscated traffic generated after traffic obfuscation into the Internet.
[0021] Specifically, the traffic feature obfuscation method based on AI virtual human in this application includes the following steps.
[0022] Step 1: Configure Basic Virtual Person Attributes. Users first need to define the virtual person's basic attributes, such as gender, nationality, occupation, and interests. These attributes can be entered manually or quickly generated based on predefined templates. These attributes determine the virtual person's identity characteristics and directly affect their online activities and behavioral style.
[0023] Step 2: Obtain user environment fingerprint. After completing the basic attribute settings, obtain the real user's internet access device environment fingerprint configuration, such as the browser header (User-Agent, Accept-Language, Referer), time zone and language (time, time zone, language), and masking of automated features.
[0024] Step 3: Configure Virtual Human Behavior Policy. Users need to pre-configure the target sites and behavior policies for the virtual human's access: a) Target site configuration: Specify the sites that the virtual human needs to visit, such as social media, news websites, or specific search engines.
[0025] b) Behavioral strategy configuration: Define the virtual human's operating mode, activity time (active all day or active during a specified period), content access preferences (browsing news, watching videos, or social interaction), and behavioral rhythm (fast-paced operation or simulating more natural user habits).
[0026] Step 4: Virtual Human Environment Fingerprint Spoofing. This step simulates the user's browser environment using a virtual human within a virtual container environment. The core of environment fingerprint spoofing lies in user environment consistency, browser fingerprint spoofing, and traffic fingerprint obfuscation.
[0027] Specifically, the method of generating obfuscated traffic by simulating a user's browser environment using virtual humans within a virtual container environment relies on achieving environmental consistency, browser fingerprint spoofing, and traffic fingerprint obfuscation. By configuring a containerized runtime environment and adjusting browser fingerprint characteristics, advertisers can effectively be unable to distinguish the actual source of traffic, mistakenly believing that the traffic generated by the virtual human is behavioral data from real users. This method uses traffic obfuscation technology to mask the traffic signal characteristics of real internet users, thereby preventing advertisers from building accurate user profiles based on the dynamic signal characteristics of network traffic.
[0028] 1) Environment Consistency: By deploying a virtualized browser environment within a container, it maintains a high degree of consistency with the host environment in terms of hardware, network, and software configuration, including but not limited to operating system version, display resolution, language settings, time zone configuration, and network protocol stack characteristics.
[0029] 2) Browser fingerprint spoofing: This aims to dynamically adjust key browser characteristics to evade detection and enhance the spoofing of traffic. Specific operations include, but are not limited to, the following: a. Modify or dynamically generate the User-Agent string to disguise the browser version and device type; b. Accept-Language spoofing, matching the target user's language preferences, such as zh-CN, zh;q=0.8; c. Dynamically adjust the local time zone setting to keep the browser's local time consistent with the geographical location; d. Disable the webdriver flag or modify automation tool flags such as the navigator.webdriver property; e. Adjusting hardware features such as Canvas, WebGL, and audio fingerprints to generate fake data; 3) Traffic fingerprint obfuscation: Traffic fingerprint obfuscation adjusts traffic characteristics at the network level, uses proxy servers or tunneling technology to ensure consistency with the user's exit IP address, uses a virtual agent to intelligently call a virtual browser to generate obfuscated traffic, and the virtual agent autonomously executes and dynamically adjusts the virtual agent's task execution strategy to further improve the traffic obfuscation effect.
[0030] Step 5: Invoke the LLM driver to optimize the virtual human's behavior strategy. The virtual human LLM driver is the core of this method, connecting the LLM model driver and the browser driver, seamlessly integrating all modules. The LLM intelligently optimizes the virtual human's behavior strategy based on the preset target site and behavior strategy, assigning the virtual human to perform specific tasks (such as accessing a website or performing an operation within a certain time period).
[0031] Specifically, the LM model autonomously generates behavioral parameters for the virtual human's online tasks based on preset parameters. When the virtual human generates characteristic traffic while performing tasks, if these preset parameters are used to mechanically generate traffic, it is easy for the opponent to identify it. Therefore, it is necessary to dynamically load and adjust the task execution parameters in real time through the virtual human LLM driver.
[0032] Specifically, such as Figure 2 As shown, by loading the preset configurations of virtual human-related features, including virtual human basic attribute configuration, behavior strategy configuration, target site configuration, and user internet browsing habits, a large model-driven input is constructed through a specific prompt word engineering template.
[0033] The LLM driver outputs the virtual human's execution parameters, including: native language used (e.g., Chinese, English, etc.), target site (Baidu, Taobao, Weibo, etc.), activity schedule (e.g., active time periods), task execution interval rhythm (e.g., click interval, scrolling speed), web search engine keywords, preferences and themes of accessed content (e.g., access frequency of certain specific websites or content types), access frequency, etc.
[0034] Step Six: The virtual human autonomously invokes the browser driver to execute tasks and generates obfuscated virtual human traffic. The virtual human engine drives remote browsing to perform real browser operations. The virtual human autonomously performs network tasks such as browsing, searching, and watching videos, constructing complex behavioral patterns and network traffic patterns that more closely resemble those generated by ordinary internet users.
[0035] The virtual human's online behavior is generated by calling the locally running Chrome browser driver to realistically simulate human behavior when visiting target websites. It can also flexibly adjust its behavior according to dynamically changing network environments, ensuring that its actions are more natural, logical, and difficult for tracking systems to identify as non-human activity.
[0036] Virtual agents can operate independently 24 / 7. Even when real users are offline, virtual agents can continue to generate network traffic autonomously. Virtual agents do not rely on real-time human user behavior and can continuously produce seemingly real network activity without human intervention. This characteristic allows virtual agents to effectively confuse tracking technologies based on real-time user behavior monitoring, ensuring that advertisers cannot accurately target and track users' online behavior.
[0037] Specific implementation process, such as Figure 3 As shown. Includes: Step a: Dynamically load the virtual human behavior parameters optimized by LLM; Step b: Iterate through the subtask execution loop list; Step c: Determine if the task is within the specified execution time range. If not, wait for the task execution interval and then put the task back into the task loop list. If it is within the execution time range, proceed to the next step. Step d: Dynamically load the virtual human behavior strategy configuration, determine if it has changed, and if it has changed, add this task to the task scheduling management engine; if it has not changed, proceed to the next step. Step e: Obtain the user's browser fingerprint and verify whether the fingerprint matches the browser driver. If they do not match, perform fingerprint spoofing by the browser driver once. Step f: Call the browser driver to asynchronously execute the virtual human task, generate real obfuscated traffic, and return the browser window session handle corresponding to the current task; Step g: The task scheduling management engine obtains the handle of the task execution browser window and manages and schedules the virtual human's behavior in a unified manner, including calculating task execution time, action rhythm, updating and closing tasks, etc. Step h: The task scheduling engine determines whether the task behavior parameters have changed or whether the task has exceeded its execution time. If so, it closes the corresponding window using the browser session's unique handle; otherwise, it continues to wait for the virtual human to execute the task. Step i: Determine whether the virtual human has successfully executed the subtask and generated the expected specific traffic. If successful, end the subtask. If unsuccessful, return the task to the task loop queue.
[0038] Step j: Determine if there are still tasks to be executed in the loop list. If there are, continue looping to execute the next virtual human task. If there are no tasks, end the current autonomous action process.
[0039] Traffic generated by the network behavior of virtual agents is integrated with real traffic generated by users into the traffic obfuscation module. The virtual agent autonomously executes and dynamically adjusts its task execution strategy through predefined traffic fingerprint features to reduce the salience of traffic features, thereby preventing the user's true intentions from being identified and analyzed in the network.
[0040] Furthermore, based on the current network environment, user behavior, and potential threat scenarios, the virtual human intelligently and adaptively adjusts the obfuscation strategy between virtual human traffic and real user traffic to achieve maximum concealment.
[0041] Preferably, the main network behavior obfuscation strategies include: 1) Traffic stuffing refers to injecting forged network packets into the normal traffic to fill idle time periods, increase the uncertainty and randomness of traffic, and mask the actual communication pattern; 2) Delayed traffic transmission refers to setting a random delay before the request is sent to disrupt the time series characteristics of the original traffic, making it difficult for traffic analysis tools to identify the real communication behavior time pattern. 3) Forged traffic is the periodic or random generation of irrelevant traffic (such as HTTP requests, video traffic, or DNS queries) to simulate the diverse network behaviors of normal users, confuse traffic analysis systems, and reduce the distinguishability of traffic characteristics; 4) Traffic pattern imitation is the process of disguising sensitive communication traffic as a typical non-sensitive traffic (such as disguising file transfer as video stream). 5) Multi-channel distribution divides the original traffic into multiple small traffic segments and transmits them through different paths or protocols, reducing the salience of concentrated traffic in a single channel, thereby avoiding centralized analysis and tracking.
[0042] The virtual human behavior traffic obfuscation environment and the real user environment are in the same secure access gateway environment. The traffic generated by the two is further obfuscated by the traffic obfuscation module, which increases the difficulty for advertisers to profile the communication traffic and meets the user network behavior privacy protection needs in various scenarios.
[0043] Step 7: Simultaneously, the user conducts actual work and business on a computer in a real internet environment, generating network traffic that requires privacy protection. The traffic generated by the virtual user and the traffic generated by the user in real life are sent together to the local gateway and integrated into the target website.
[0044] Step 8: The system will log the virtual human's operation behavior, mainly including the sites visited, the behaviors performed, and the traffic characteristics generated. When the virtual human performs tasks, it can be displayed through a visualization tool (VNC).
[0045] Internet advertisers analyze the dynamic signal characteristics of users' web traffic, which directly reflect users' online behavior habits and preferences, thus easily building user profiles and precisely targeting advertisements. The core goal of the virtual human behavior engine is to intelligently infiltrate the traffic of virtual humans, obscuring the tracking and analysis of real users' online behavior by advertisers or third parties, thereby achieving traffic anonymization and privacy protection.
[0046] Using the method described in this application, when a user visits a target website, a virtual avatar accompanying them can generate spoofed traffic to mask the user's traffic signal characteristics, preventing advertisers from identifying and tracking the user through these characteristics. The virtual avatar can generate obfuscated traffic around the clock, continuing to do so even after the user logs off, constantly interfering with the target's analysis of the user's traffic signal characteristics. This significantly enhances the ability to counter traffic fingerprinting analysis, effectively protecting the user's online privacy.
[0047] like Figure 4 As shown, the virtual human behavior engine and real user online behavior can run simultaneously without interference. Users can customize the virtual human's basic attributes and behavior strategies according to their needs. The virtual human behavior engine simulates the device fingerprint of real users and uses Large Language Model (LLM) to optimize the virtual human's behavior strategy, ensuring that its network behavior is closer to that of real users. Finally, through automated browser technology, it drives the virtual human to perform simulated real user operations, generating network traffic that is confused with real users.
[0048] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A method for obfuscating traffic characteristics based on AI virtual humans, characterized in that, The traffic feature obfuscation method based on AI virtual humans includes: S1. Configure the basic attributes and preset behavior policies of the virtual human, and automatically obtain the fingerprint of the user's Internet access device; S2. Virtual human environment fingerprint spoofing is achieved by configuring a containerized runtime environment and adjusting the browser fingerprint. S3. Based on preset parameters, LLM-driven dynamic generation determines the behavioral parameters of the virtual human in online tasks; S4: Based on the behavioral parameters obtained from S3, the virtual human calls the local browser driver online to simulate human access to the target site and generate characteristic traffic.
2. The traffic feature obfuscation method based on AI virtual human as described in claim 1, characterized in that, Step S1 includes: S11. Configure the basic attributes of the virtual human, including: gender, age, nationality, occupation, and hobbies; S12. Configure virtual human behavior strategies, including: activity time, target site, action interval rhythm, keywords and themes; S13. Obtain the user device fingerprint, including operating system version, browser header, time zone, language, and automation features.
3. The traffic feature obfuscation method based on AI virtual human as described in claim 1, characterized in that, In step S2, the virtual human's environment fingerprint is disguised as: cloning the static fingerprint of the real user's internet access device that is connected to the network with the virtual human. The static fingerprint includes: browser header, hardware features, operating system version, and language environment.
4. The traffic feature obfuscation method based on AI virtual human as described in claim 1, characterized in that, Step S3 includes: S31. Construct prompt words that conform to the characteristics of virtual humans based on preset virtual human parameters and use them as LLM driver input; S32, LLM-driven autonomous generation of virtual human behavior parameters, including: language, target site, activity time, operation rhythm, search keywords, and access content preferences.
5. The traffic feature obfuscation method based on AI virtual human as described in claim 1, characterized in that, Step S4 includes: S41. The virtual human loads behavioral parameters and executes a list of tasks in a loop; S42. Determine if the task is within the specified execution time range. If not, wait for the task execution interval and then put the task back into the task loop list. If it is, proceed to S43. S43. Verify whether the task behavior policy configuration changes dynamically. If it changes, add the corresponding task to the task scheduling management engine and proceed to S46; if it does not change, proceed to S44. S44. Obtain the user's browser fingerprint and verify whether the fingerprint matches the browser driver. If they do not match, perform fingerprint spoofing in the browser driver once and then proceed to S45. If they match, proceed directly to S45. S45. Call the browser driver to asynchronously execute the virtual human task and return the browser window session handle of the current task; S46. The task scheduling engine determines whether the task behavior parameters have changed or whether the task has exceeded the execution time. If yes, the corresponding browser window is closed and the process proceeds to S47; otherwise, it continues to wait for the virtual human to execute the task. S47. Determine whether the virtual human has successfully executed the subtask. If successful, end the subtask. If unsuccessful, return the task to the task loop queue and proceed to S41.
6. The traffic feature obfuscation method based on AI virtual human as described in claim 1, characterized in that, The process of generating characteristic traffic in step S4 includes: the traffic generated based on the network behavior of the virtual human agent and the real traffic generated by the user are combined into the traffic obfuscation module with a preset obfuscation strategy to generate characteristic traffic.
7. The traffic feature obfuscation method based on AI virtual human as described in claim 6, characterized in that, Step S4 also includes: the virtual human intelligently and adaptively adjusts the obfuscation strategy between virtual human traffic and real user traffic based on the current network environment, user operation behavior, and potential threat scenarios.
8. The traffic feature obfuscation method based on AI virtual human as described in claim 6, characterized in that, The obfuscation strategy includes: 1) Traffic padding: On top of normal traffic, forged network packets are injected to fill idle time periods, increasing the uncertainty and randomness of traffic and masking the actual communication pattern; 2) Delayed traffic transmission: A random delay is set before the request is sent to disrupt the time series characteristics of the original traffic, making it difficult for traffic analysis tools to identify the real communication behavior time pattern. 3) Fake traffic: Regularly or randomly generate irrelevant traffic to simulate the diverse network behaviors of normal users, confuse traffic analysis systems and reduce the distinguishability of traffic characteristics; 4) Traffic pattern mimicry: Disguising sensitive communication traffic as typical non-sensitive traffic; 5) Multi-channel distribution: The original traffic is divided into several small traffic segments and transmitted through different paths or protocols.
9. The traffic feature obfuscation method based on AI virtual human as described in claim 8, characterized in that, The irrelevant traffic includes: HTTP requests, video traffic, or DNS queries.
10. The traffic feature obfuscation method based on AI virtual human as described in claim 8, characterized in that, Disguising sensitive communication traffic as typical non-sensitive traffic includes disguising file transfers as video streams.