Defense Against AI-Guided Traffic Analysis (Daita)
mullvad.net
mullvad.net
Seems to me like a self-perpetuating broken-window fallacy taken to its logical extreme.
https://renegadeotter.com/2024/04/22/artificial-intelligence...
We know that taking antibiotics leads to stronger bacteria. But we still should have developed it and incorporated it into our medicine. AI will do some amazing things, and as a tool it will be used by some bad people to do bad things. But overall society improves/grows with the creation and use of tools.
It’s certainly looks to be a step above prior efforts to inject noise that I’ve seen such as having an instrumented browser “randomly browse the web” to add noise.
[1]: https://proprivacy.com/vpn/guides/openvpn-scramble-xor-obfus...
Unfortunately with symmetrical consumer internet services still being rare in many countries, fully masking your traffic when trying to download a large amount of content is made more difficult or time consuming.
Or are people training neural nets on traffic analysis now?
Broadly speaking, traffic analysis benefits a lot from work in computer vision: view a network trace as a one-dimensional picture. There are some fun visualizations here if you scroll down a bit: https://github.com/pylls/padding-machines-for-tor/tree/maste... . Every 1-pixel high line is a website visit, where each pixel corresponds to a packet (or cell in Tor) sent or received.
(Disclosure: I work with Mullvad on DAITA.)
It's similar to how encryption was viewed as too expensive a decade or two ago. Today, it is a necessity. Seeing how available bandwidth keeps growing to accommodate things like video, I hope traffic analysis defenses won't be as detrimental in the long run for most internet use.
This is tricky. We have hardly started dealing with traffic analysis issues in protocols. In general, we have spent the last decade+ getting encryption sort of right with amazing efforts like TLS 1.3 and WireGuard, etc. Expect another decade for traffic analysis.