Being deanonymised during normal Tor browsing is extremely difficult and I'd challenge you to post cases where Tor itself lead to it.
There's no doubt in my mind that state actors have been putting similar techniques to use.
But that's not what gp asked.
Has the work you linked to been shown to lead to the successful deanonymization of a normal user during normal Tor browsing? It's a simple yes or no question. I don't follow tor news like I used to but I'm willing to bet a months-worth of salary that the answer is still no.
Or it could leaked, on accident or by a whistleblower. But that's pretty uncommon.
It’s almost certain that some state has an application exploit sitting on a shelf somewhere, which might only be useful in some extremely niche use case, but it’s unlikely that it’s routinely ‘compromised’ in the way that sensationalised media might put it.
What’s more likely is that an exit node has been owned, or is actually operated by some nation state. Even then, you might not even see the actually traffic if it has been re-routed.
The most likely scenario is an OPSEC failure - turns out you need to be very, very good at operations and online hygiene if you want to hide your illicit activities online shocked pikachu.
Disclaimer: am a Tor developer and employee.
One potential problem is that it's suspected state actors run a large amount of exit nodes.
The community does a lot of active monitoring to kick out misbehaving relays. "Misbehaving" includes running multiple relays without correctly setting the family attribute to identify them as being run by a single entity.
The main danger of malicious exit relays beyond other relays is that they perform some man-in-the-middle active attack. This is largely mitigated by end-to-end encryption. Tor Browser will soon be HTTPS only (other than explicit manual overrides) to help avoid inavertent non-e2e protected connections.
More in another recent blog post: https://blog.torproject.org/malicious-relays-health-tor-netw...
How do know who is the actual real owner behind a machine on the internet?
https://arstechnica.com/information-technology/2013/08/tor-u...
The larger concern for deanonymization is typically flooding the network with relays, since it increases the ability to do e.g. timing-based de-anonymization attacks. This is a bit of an arms race. As @ajvs points out though, the known cases of tor users being de-anonymized were not due to attacking Tor itself, but via other channels. I'm not aware of any known real-world cases of users being deanonymized by attacking or analyzing Tor itself, let alone users being "arrested regularly"