of course an untrusted router can do many things, it's one reason you use a VPN at all. your provider's router is ... untrustworthy. i believe the point of the paper is that even if you use VPN, the router can detect
that and classify you. VPN is illegal in some countries so this is relevant. let's avoid a "security must be absolute" mindset. like, thing A is not worth doing because thing B is still flawed. the paper seeks to address a specific thing A and things B,C,D are out of scope.
in the paper abstract they specifically and only talk about the CPE router, which can identify LAN clients uniquely, but very similar thing applies to the upstream edge/border router. I believe (I only scanned it, didn't read it in detail) the paper focuses on the CPE router because the fingerprinting load is distributed and free in that case, and most often the provider owns the CPE anyway. so this is a reasonable place to focus on. however they've neglected netflow records (from provider owned upstream border/edge router) which can similarly be analyzed, offline at a leisurely pace, with arbitrary resources able to be thrown at it, and unlike a CPE firmware action cannot be detected. so i don't know how important the "router" part is.
the ability to detect VPN itself isn't novel or even interesting, but i guess their claim is in presenting a traffic analysis that requires little sophistication and few resources, something lightweight enough that it can be run at the CPE.