1.北京邮电大学网络空间安全学院,北京 100876
2.中国科学院信息工程研究所,北京 100085
李泽禹 男,1995年5月出生于重庆市。现为北京邮电大学网络空间安全学院博士研究生。主要研究方向为加密流量分析。E-mail: lzreal@bupt.edu.cn
黄文涛 男,1999年12月出生于山东省德州市。现为北京邮电大学网络空间安全学院博士研究生。主要研究方向为匿名通信、加密流量分析等。E-mail: hyangwentao@bupt.edu.cn
刘凯 男,1986年12月出生于山东省济南市。现为北京邮电大学网络空间安全学院博士研究生。主要研究方向为网络性能测量和网络资源管理。E-mail: liukai@bupt.edu.cn
时金桥 男,1978年1月出生于黑龙江省哈尔滨市。现为北京邮电大学教授、博士生导师。主要研究方向为网络与信息安全,尤其专注于隐私增强技术和数据泄露检测。中国电子学会会员编号:E190158671M。E-mail: shijinqiao@bupt.edu.cn
收稿:2026-01-26,
录用:2026-03-09,
网络首发:2026-05-21,
纸质出版:2026-04-25
移动端阅览
李泽禹, 黄文涛, 王学宾, 等. 基于信元序列重建的暗网流量远程指纹识别技术[J]. 电子学报, 2026, 54(04): 1529-1547.
LI Zeyu, HUANG Wentao, WANG Xuebin, et al. Remote Traffic Fingerprinting Attack Based on Cell Sequence Reconstruction[J]. Acta Electronica Sinica, 2026, 54(04): 1529-1547.
李泽禹, 黄文涛, 王学宾, 等. 基于信元序列重建的暗网流量远程指纹识别技术[J]. 电子学报, 2026, 54(04): 1529-1547. DOI:10.12263/DZXB.20251035
LI Zeyu, HUANG Wentao, WANG Xuebin, et al. Remote Traffic Fingerprinting Attack Based on Cell Sequence Reconstruction[J]. Acta Electronica Sinica, 2026, 54(04): 1529-1547. DOI:10.12263/DZXB.20251035
流量指纹攻击可以应用于第二代洋葱网络(The second onion router,Tor)的隐藏服务溯源。由于Tor网络协议设计的限制,隐藏服务侧流量难以获得,因此需要利用电路中其他位置的流量作为隐藏服务侧流量的替代来开展远程指纹攻击。然而,指纹模型面临Tor中继中数据缓存、加解密与重封装带来的报文序列的结构性变化,导致指纹模型在位点迁移时存在性能衰减。已有的方法在一定程度上可以从模型层面和数据层面缓解随机噪声,却难以精准拟合由协议机制导致的结构性差异。本文深入剖析了暗网流量的转发机理,提出了上下文感知的远程信元序列重建(Remote Cell Estimator,RemoCellEst)。该方法引入了跨报文的残留补偿机制,动态修正报文起始处的载荷偏移,从而重建成跨位点一致的信元序列,使模型具备更稳定的位置迁移能力。实验结果表明,在隐藏服务溯源场景下,基于RemoCellEst方法重建的信元序列构建的远程指纹模型可达94.85%的准确率,相较于基于桶分割方法或直接使用传输控制协议(Transmission Control Protocol,TCP)/传输层安全协议(Transport Layer Security protocol,TLS)层流量构建的模型提升了6%~16%的准确率。本文将远程指纹攻击的位点迁移问题归因到可解释、可建模的报文序列结构性差异,可为后续加密流量分析、流关联等相关研究提供新的视角。
Traffic fingerprinting attacks can be applied to hidden services de-anonymization in the Tor (The Second Onion Router) network. Due to the limitations of the Tor network protocol
traffic on the hidden service-side is difficult to obtain. Therefore
traffic from other positions is used as a substitute for hidden service-side traffic to train remote fingerprinting models. However
fingerprinting models face structural changes in packet sequences caused by data caching
encryption/decryption
and repackaging at Tor relays
leading to performance degradation during position migration. Existing methods
whether at the model or data level
can partially mitigate random noise but struggle to accurately fit structural differences induced by protocol mechanisms. This paper delves into the forwarding mechanisms of Tor traffic and proposes a context-aware remote cell sequence estimator method
called remote cell estimator (RemoCellEst). This approach introduces a cross-packet residual compensation mechanism to dynamically adjust payload offsets at boundaries of each packet
thereby reconstructing consistent cell sequences across position and enhancing the model’s capability for positional migration. Experimental results demonstrate that remote fingerprinting attacks based on cell sequences reconstructed using the RemoCellEst method achieve an accuracy of 94.85%
representing a 6% to 16% improvement over which using bucket-based estimator methods or directly using TCP (Transmission Control Protocol)/TLS (Transport Layer Security Protocol) layer traffic. This paper attributes the position migration challange in remote fingerprinting attacks to interpretable and modelable structural differences in packet sequences
offering a novel perspective for subsequent research such as encrypted traffic analysis and flow correlation.
SOCRadar Cyber Intelligence Inc . SOCRadar 2024 annual dark web report - SOCRadar [EB/OL ] . ( 2025-02-27 )[ 2026-01-25 ] . https://socradar.io/resources/report/socradar-2024-annual-dark-web-report/ https://socradar.io/resources/report/socradar-2024-annual-dark-web-report/ .
DeepStrike . Dark web daily activity: What really happens in 2025 [EB/OL ] . ( 2025-11-18 )[ 2026-01-25 ] . https://deepstrike.io/blog/dark-web-daily-activity-2025 https://deepstrike.io/blog/dark-web-daily-activity-2025 . DOI: 10.1093/9780198972877.003.0043 http://dx.doi.org/10.1093/9780198972877.003.0043
Qin Yi , Zheng Tianming , Wu Yue , et al . Tracing Tor hidden service through protocol characteristics [C ] // 2022 International Conference on Computer Communications and Networks . Piscataway : IEEE , 2022 : 1 - 9 . DOI: 10.1109/icccn54977.2022.9868859 http://dx.doi.org/10.1109/icccn54977.2022.9868859
Chen Muqian , Wang Xuebin , Shi Jinqiao , et al . Napping guard: Deanonymizing Tor hidden service in a stealthy way [C ] // 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications . Piscataway : IEEE , 2020 : 699 - 706 . DOI: 10.1109/TrustCom50675.2020.00097 http://dx.doi.org/10.1109/TrustCom50675.2020.00097
Nasr M , Bahramali A , Houmansadr A . DeepCorr: Strong flow correlation attacks on Tor using deep learning [C ] // Proceedings of 2018 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2018 : 1962 - 1976 . DOI: 10.1145/3243734.3243824 http://dx.doi.org/10.1145/3243734.3243824
Lopes D , Dong Jindong , Medeiros P , et al . Flow correlation attacks on Tor onion service sessions with sliding subset sum [C ] // Proceedings of the 31st Annual Network and Distributed System Security Symposium . The Internet Society , 2024 . DOI: 10.14722/ndss.2024.24337 http://dx.doi.org/10.14722/ndss.2024.24337
Zhou Qiang , Wang Liangmin , Zhu Huijuan , et al . WF-transformer: Learning temporal features for accurate anonymous traffic identification by using transformer networks [J ] . IEEE Transactions on Information Forensics and Security , 2024 , 19 : 30 - 43 . DOI: 10.1109/tifs.2023.3318966 http://dx.doi.org/10.1109/tifs.2023.3318966
Gong Jiajun , Cai Wei , Liang Siyuan , et al . WFCAT: Augmenting website fingerprinting with channel-wise attention on timing features [J ] . IEEE Transactions on Dependable and Secure Computing , 2026 , 23 ( 1 ): 149 - 163 . DOI: 10.1109/tdsc.2025.3605197 http://dx.doi.org/10.1109/tdsc.2025.3605197
Li J , Wang D , Liu Y , et al . Cross-environmental website fingerprinting [C ] // IEEE Conference on Computer Communications . 2025 : 1 - 10 . DOI: 10.1109/infocom55648.2025.11044569 http://dx.doi.org/10.1109/infocom55648.2025.11044569
Deng Xinhao , Li Qi , Xu Ke . Robust and reliable early-stage website fingerprinting attacks via spatial-temporal distribution analysis [C ] // Proceedings of 2024 on ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2024 : 1997 - 2011 . DOI: 10.1145/3658644.3670272 http://dx.doi.org/10.1145/3658644.3670272
Zhao Xiyuan , Deng Xinhao , Li Qi , et al . Towards fine-grained webpage fingerprinting at scale [C ] // Proceedings of 2024 on ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2024 : 423 - 436 . DOI: 10.1145/3658644.3690211 http://dx.doi.org/10.1145/3658644.3690211
Shen Meng , Liu Yiting , Zhu Liehuang , et al . Fine-grained webpage fingerprinting using only packet length information of encrypted traffic [J ] . IEEE Transactions on Information Forensics and Security , 2021 , 16 : 2046 - 2059 . DOI: 10.1109/tifs.2020.3046876 http://dx.doi.org/10.1109/tifs.2020.3046876
Wang Meiqi , Chen Muqian , Li Zeyu , et al . Deanonymize Tor hidden services using remote website fingerprinting [C ] // 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications . Piscataway : IEEE , 2023 : 998 - 1005 . DOI: 10.1109/trustcom60117.2023.00140 http://dx.doi.org/10.1109/trustcom60117.2023.00140
Zhao Can , Zhang Qingfeng , Qin Yefeng , et al . Quadruplet fingerprinting: Onion website fingerprinting through quadruplet network [C ] // 2025 28th International Conference on Computer Supported Cooperative Work in Design . Piscataway : IEEE , 2025 : 2563 - 2568 . DOI: 10.1109/cscwd64889.2025.11033514 http://dx.doi.org/10.1109/cscwd64889.2025.11033514
Li Zeyu , Wang Yipeng , Wang Xuebin , et al . Proxied traffic fingerprinting for hidden service de-anonymization with burst reshaping [J ] . IEEE Transactions on Information Forensics and Security , 2025 , 20 : 7663 - 7678 . DOI: 10.1109/TIFS.2025.3588248 http://dx.doi.org/10.1109/TIFS.2025.3588248
Khajehpour A , Zandi F , Malekghaini N , et al . Deep inside tor: Exploring website fingerprinting attacks on Tor traffic in realistic settings [C ] // 2022 12th International Conference on Computer and Knowledge Engineering . Piscataway : IEEE , 2022 : 148 - 156 . DOI: 10.1109/iccke57176.2022.9960104 http://dx.doi.org/10.1109/iccke57176.2022.9960104
Yuqi Qing , Yin Qilei , Deng Xinhao , et al . Training robust classifiers for classifying encrypted traffic under dynamic network conditions [C ] // Proceedings of 2025 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2025 : 3564 - 3578 . DOI: 10.1145/3719027.3765073 http://dx.doi.org/10.1145/3719027.3765073
Sirinam P , Mathews N , Rahman M S , et al . Triplet fingerprinting: More practical and portable website fingerprinting with n-shot learning [C ] // Proceedings of 2019 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2019 : 1131 - 1148 . DOI: 10.1145/3319535.3354217 http://dx.doi.org/10.1145/3319535.3354217
Shen Meng , Ji Kexin , Gao Zhenbo , et al . Subverting website fingerprinting defenses with robust traffic representation [C ] // 32nd USENIX Security Symposium . USENIX Association , 2023 : 607 - 624 .
Mitseva A , Panchenko A . Stop, don’t click here anymore: Boosting website fingerprinting by considering sets of subpages [C ] // 33rd USENIX Security Symposium . USENIX Association , 2024 : 4139 - 4156 .
Bahramali A , Bozorgi A , Houmansadr A . Realistic website fingerprinting by augmenting network traces [C ] // Proceedings of 2023 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2023 : 1035 - 1049 . DOI: 10.1145/3576915.3616639 http://dx.doi.org/10.1145/3576915.3616639
Jansen R , Wails R , Johnson A . Repositioning real-world website fingerprinting on tor [C ] // Proceedings of the 23rd Workshop on Privacy in the Electronic Society . New York : ACM , 2024 : 124 - 140 . DOI: 10.1145/3689943.3695047 http://dx.doi.org/10.1145/3689943.3695047
Fu Chuanpu , Li Qi , Bertino E , et al . Training with only 1.0‰ samples: Malicious traffic detection via cross-modality feature fusion [C ] // Proceedings of 2025 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2025 : 3930 - 3944 . DOI: 10.1145/3719027.3765143 http://dx.doi.org/10.1145/3719027.3765143
Liu Zixuan , Zhao Yi , Liu Zhuotao , et al . A hard-label black-box evasion attack against ML-based malicious traffic detection systems [C ] // Proceedings of Network and Distributed System Security Symposium . The Internet Society , 2026 . DOI: 10.14722/ndss.2026.230916 http://dx.doi.org/10.14722/ndss.2026.230916
Shen Meng , Wu Jinhe , Ai Junyu , et al . Swallow: A transfer-robust website fingerprinting attack via consistent feature learning [C ] // Proceedings of 2025 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2025 : 1574 - 1588 . DOI: 10.1145/3719027.3744795 http://dx.doi.org/10.1145/3719027.3744795
Wang Tao , Goldberg I . Improved website fingerprinting on Tor [C ] // Proceedings of the 12th ACM Workshop on Workshop on Privacy in the Electronic Society . New York : ACM , 2013 : 201 - 212 . DOI: 10.1145/2517840.2517851 http://dx.doi.org/10.1145/2517840.2517851
Panchenko A , Lanze F , Pennekamp J , et al . Website fingerprinting at internet scale [C ] // Proceedings of the 23rd Annual Network and Distributed System Security Symposium . The Internet Society , 2016 . DOI: 10.14722/ndss.2016.23477 http://dx.doi.org/10.14722/ndss.2016.23477
Wang Meiqi , Li Yanzeng , Wang Xuebin , et al . 2ch-TCN: A website fingerprinting attack over Tor using 2-channel temporal convolutional networks [C ] // Proceedings of 2020 IEEE Symposium on Computers and Communications . Piscataway : IEEE , 2020 : 1 - 7 . DOI: 10.1109/ISCC50000.2020.9219717 http://dx.doi.org/10.1109/ISCC50000.2020.9219717
Fu Chuanpu , Li Qi , Shen Meng , et al . Detecting tunneled flooding traffic via deep semantic analysis of packet length patterns [C ] // Proceedings of 2024 on ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2024 : 3659 - 3673 . DOI: 10.1145/3658644.3670353 http://dx.doi.org/10.1145/3658644.3670353
Zhou Guangmeng , Guo Xiongwen , Liu Zhuotao , et al . TrafficFormer: An efficient pre-trained model for traffic data [C ] // 2025 IEEE Symposium on Security and Privacy . Piscataway : IEEE , 2025 : 1844 - 1860 . DOI: 10.1109/sp61157.2025.00102 http://dx.doi.org/10.1109/sp61157.2025.00102
Wang Tao , Cai Xiang , Nithyanand R , et al . Effective attacks and provable defenses for website fingerprinting [C ] // Proceedings of the 23rd USENIX Conference on Security Symposium . USENIX Association , 2014 : 143 - 157 .
Abe K , Goto S . Fingerprinting attack on Tor anonymity using deep learning [C ] // Proceedings of the APAN . Semantic Scholar , 2016 : 15 - 20 .
Rimmer V , Preuveneers D , Juárez M , et al . Automated website fingerprinting through deep learning [C ] // 25th Annual Network and Distributed System Security Symposium . The Internet Society , 2018 . DOI: 10.14722/ndss.2018.23105 http://dx.doi.org/10.14722/ndss.2018.23105
Sirinam P , Imani M , Juarez M , et al . Deep fingerprinting: Undermining website fingerprinting defenses with deep learning [C ] // Proceedings of 2018 ACM SIGSAC Conference on Computer and Communications Security . New York : ACM , 2018 : 1928 - 1943 . DOI: 10.1145/3243734.3243768 http://dx.doi.org/10.1145/3243734.3243768
Kwon A , AlSabah M , Lazar D , et al . Circuit fingerprinting attacks: Passive deanonymization of Tor hidden services [C ] // Proceedings of the 24th USENIX Security Symposium . USENIX Association , 2015 : 287 - 302 . DOI: 10.1016/S1164-6756(97)80087-4 http://dx.doi.org/10.1016/S1164-6756(97)80087-4
Jansen R , Juárez M , Gálvez R , et al . Inside job: Applying traffic analysis to measure Tor from within [C ] // 25th Annual Network and Distributed System Security Symposium . The Internet Society , 2018 . DOI: 10.14722/ndss.2018.23261 http://dx.doi.org/10.14722/ndss.2018.23261
Mohd Aminuddin M A I , Zaaba Z F , Samsudin A , et al . The rise of website fingerprinting on Tor: Analysis on techniques and assumptions [J ] . Journal of Network and Computer Applications , 2023 , 212 : 103582 . DOI: 10.1016/j.jnca.2023.103582 http://dx.doi.org/10.1016/j.jnca.2023.103582
Cherubin G , Jansen R , Troncoso C . Online website fingerprinting: Evaluating website fingerprinting attacks on Tor in the real world [C ] // 31st USENIX Security Symposium . USENIX Association , 2022 .
The Tor Project . Tor source code: Buffers. c [Z ] . 2025 .
Bhat S , Lu D , Kwon A , et al . Var-CNN: A data-efficient website fingerprinting attack based on deep learning [J ] . Proceedings on Privacy Enhancing Technologies , 2019 , 2019( 4 ): 292 - 310 . DOI: 10.2478/popets-2019-0070 http://dx.doi.org/10.2478/popets-2019-0070
Rahman M S , Sirinam P , Mathews N , et al . Tik-Tok: The utility of packet timing in website fingerprinting attacks [J ] . Proceedings on Privacy Enhancing Technologies , 2020 , 2020( 3 ): 5 - 24 . DOI: 10.2478/popets-2020-0043 http://dx.doi.org/10.2478/popets-2020-0043
Chen Zixuan , Zheng Chao , Li Zhao , et al . Seeing the attack paths: Improved flow correlation scheme in stepping-stone intrusion [C ] // 2024 27th International Conference on Computer Supported Cooperative Work in Design . Piscataway : IEEE , 2024 : 2116 - 2121 . DOI: 10.1109/cscwd61410.2024.10580831 http://dx.doi.org/10.1109/cscwd61410.2024.10580831
Yin Haoyu , Liu Yingjian , Guo Zhongwen , et al . From traces to packets: Realistic deep learning based multi-tab website fingerprinting attacks [J ] . Tsinghua Science and Technology , 2025 , 30 ( 2 ): 830 - 850 . DOI: 10.26599/tst.2024.9010073 http://dx.doi.org/10.26599/tst.2024.9010073
Meng Wenwen , Ma Chuan , Ding Ming , et al . Beyond single tabs: A transformative few-shot approach to multi-tab website fingerprinting attacks [C ] // Proceedings of ACM on Web Conference 2025 . New York : ACM , 2025 : 1068 - 1077 . DOI: 10.1145/3696410.3714811 http://dx.doi.org/10.1145/3696410.3714811
Gu Xiaodan , Yang Ming , Song Bingchen , et al . A practical multi-tab website fingerprinting attack [J ] . Journal of Information Security and Applications , 2023 , 79 : 103627 . DOI: 10.1016/j.jisa.2023.103627 http://dx.doi.org/10.1016/j.jisa.2023.103627
Cui Yuwen , Wang Guangjing , Vu K , et al . A comprehensive survey of website fingerprinting attacks and defenses in tor: Advances and open challenges [PP/OL ] . V3. arXiv ( 2025-11-22 )[ 2025-12-20 ] . https://arxiv.org/abs/2510.11804 https://arxiv.org/abs/2510.11804 . DOI: 10.1109/ic-eeta66496.2025.11548449 http://dx.doi.org/10.1109/ic-eeta66496.2025.11548449
Xiao Xi , Zhou Xiang , Yang Zhenyu , et al . A comprehensive analysis of website fingerprinting defenses on Tor [J ] . Computers & Security , 2024 , 136 : 103577 . DOI: 10.1016/j.cose.2023.103577 http://dx.doi.org/10.1016/j.cose.2023.103577
Shen Meng , Ji Kexin , Wu Jinhe , et al . Real-time website fingerprinting defense via traffic cluster anonymization [C ] // 2024 IEEE Symposium on Security and Privacy . Piscataway : IEEE , 2024 : 3238 - 3256 . DOI: 10.1109/sp54263.2024.00247 http://dx.doi.org/10.1109/sp54263.2024.00247
0
浏览量
5
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621