Research Article

Defending against Deep-Learning-Based Flow Correlation Attacks with Adversarial Examples

Table 5

The protection success rate of various adversarial examples against website fingerprint attacks with the same bandwidth overhead. PSR presents the protection success rate.

Data setMethodBandwidth overhead (L_∞)K-NN (PSR) (%)K-FP (PSR) (%)Var-CNN (PSR) (%)

SirinamFGSM0.2097.297.480.3
C&W0.2099.499.588.8
Deepfool0.2099.799.394.5
BIM0.2098.598.886.7

RimmerFGSM0.2097.296.786.7
C&W0.2099.999.393.2
Deepfool0.2098.798.197.5
BIM0.2098.297.589.4