Establishing efficient and robust covert channels is crucial for secure communication within insecure network environments. With its inherent benefits of decentralization and anonymization, blockchain has gained considerable attention in developing covert channels. To guarantee a highly secure covert channel, channel negotiation should be contactless before the communication, carrier transaction features must be indistinguishable from normal transactions during the communication, and communication identities must be untraceable after the communication. Such a full-lifecycle covert channel is indispensable to defend against a versatile adversary who intercepts two communicating parties comprehensively (e.g., on-chain and off-chain). Unfortunately, it has not been thoroughly investigated in the literature. We make the first effort to achieve a full-lifecycle covert channel, a novel blockchain-based covert channel named ABC-Channel. We tackle a series of challenges, such as off-chain contact dependency, increased masquerading difficulties as growing transaction volume, and time-evolving, communicable yet untraceable identities, to achieve contactless channel negotiation, indistinguishable transaction features, and untraceable communication identities, respectively. We develop a working prototype to validate ABC-Channel and conduct extensive tests on the Bitcoin testnet. The experimental results demonstrate that ABC-Channel achieves substantially secure covert capabilities. In comparison to existing methods, it also exhibits state-of-the-art transmission efficiency.
The domain name system (DNS) is indispensable to nearly every Internet service. It has been extensively utilized for network activity characterization in passive and active approaches. Compared to the passive approach, active DNS cache probing is lightweight and non-cooperative, enabling world-wide characterization of remote network activities in different networks. Unfortunately, existing probing-based methods are too coarse-grained to characterize the time-varying features of network activities, substantially limiting their applications in time-sensitive tasks. In this paper, we advance DNSScope, a temporally fine-grained DNS cache probing framework by addressing three key challenges: cache entanglement, sample sparsity, and observational distortion. DNSScope introduces three novel probing strategies, extending active DNS cache probing from single-cache to heterogeneous recursive DNS (R-DNS) resolvers. It synthesizes statistical learning and transfer learning to achieve time-varying characterization of remote network activity. Extensive evaluations demonstrate DNSScope’s adaptability for R-DNS resolvers with diverse cache structures and its effectiveness in accurately estimating time-varying DNS query arrival rates, achieving an average mean absolute error of 0.124, as low as one-sixth that of the baseline methods. We also demonstrate DNSScope’s application to network anomaly detection.
Recent knowledge graph (KG)-enhanced large language models (LLMs) move beyond purely textual knowledge augmentation by encoding retrieved subgraphs into continuous soft prompts via graph neural networks, introducing a graph-conditioned channel that operates alongside the standard text interface. However, existing backdoor attacks are largely designed for the textual channel, and their effectiveness against this dual-channel architecture remains unclear. We show that this architecture creates a robustness gap: text-channel backdoor attacks that readily compromise textual KG prompting systems become largely ineffective against soft-prompt-based counterparts. We interpret this gap through semantic anchoring, whereby graph-derived soft prompts bias the generation-driving hidden state toward query-consistent semantics and suppress surface-level malicious instructions. Because this anchoring effect is itself induced by the graph channel, an attacker who manipulates graph-level representations can in turn redirect it toward adversarial semantics. To demonstrate this risk, we propose BadSKP, a backdoor attack that targets the graph-to-prompt interface through a multi-stage optimization strategy: it constructs adversarial target embeddings, optimizes poisoned node embeddings to steer the induced soft prompt, and approximates the optimized representations with fluent adversarial node attributes. Experiments on two soft-prompt KG-enhanced LLMs across four datasets show that BadSKP achieves high attack success under both frozen and trojaned settings, while text-only attacks remain unreliable even under perplexity-based defenses.
Establishing efficient and robust covert channels is crucial for secure communication within insecure network environments. With its inherent benefits of decentralization and anonymization, blockchain has gained considerable attention in developing covert channels. To guarantee a highly secure covert channel, channel negotiation should be contactless before the communication, carrier transaction features must be indistinguishable from normal transactions during the communication, and communication identities must be untraceable after the communication. Such a full-lifecycle covert channel is indispensable to defend against a versatile adversary who intercepts two communicating parties comprehensively (e.g., on-chain and off-chain). Unfortunately, it has not been thoroughly investigated in the literature. We make the first effort to achieve a full-lifecycle covert channel, a novel blockchain-based covert channel named ABC-Channel. We tackle a series of challenges, such as off-chain contact dependency, increased masquerading difficulties as growing transaction volume, and time-evolving, communicable yet untraceable identities, to achieve contactless channel negotiation, indistinguishable transaction features, and untraceable communication identities, respectively. We develop a working prototype to validate ABC-Channel and conduct extensive tests on the Bitcoin testnet. The experimental results demonstrate that ABC-Channel achieves substantially secure covert capabilities. In comparison to existing methods, it also exhibits state-of-the-art transmission efficiency.
Synthetic traffic generation is a fundamental technique for evaluating system performance and security resilience. However, existing approaches fail to capture the complex, interactive traffic patterns of modern applications. While recent deep learning models can synthesize individual traffic flows with high fidelity, they are fundamentally restricted to these isolated behaviors. They cannot reproduce the system-level interactions among multiple nodes, due to the state space of multi-node systems, which grows exponentially with the number of participants and renders direct modeling computationally intractable. To break this scalability barrier, we introduce NEST, a node-interactive generative emulation framework that enables multi-node synthetic traffic generation. Its key innovation circumvents exponential complexity by decomposing the problem: rather than modeling the global network, a generative model learns each node’s local behavior, which a lightweight scheduler then orchestrates into coherent, interactive traffic. Evaluations show that NEST not only achieves high statistical fidelity but, for the first time, successfully reconstructs the multi-node interaction graphs of real-world applications. These generated graphs replicate the complex dependency structures of real traffic with an average similarity of 97.7%, a task fundamentally unattainable by prior single-flow models.
Despite the traditional perception that Wi-Fi communications are secure and resistant to eavesdropping, recent advancements in wireless fingerprinting have challenged this view. Emerging wireless app fingerprinting techniques exploit side-channel traffic features to infer fine-grained, privacy-sensitive user behaviors. If left unresolved, this threat could expose nearly all Wi-Fi users to pervasive app fingerprinting attacks. While several defense strategies show potential, each suffers from inherent limitations. For example, in-app traffic obfuscation (client-side) can effectively conceal traffic patterns but requires modifying individual apps, making it impractical for rapid deployment at scale. On the other hand, encrypted proxy-based defenses (cloud-side) offer certain traffic shaping capabilities, but their encapsulation and multi-hop forwarding introduce additional latency and degrade overall performance. To address this pressing need, we pioneer an edge-side traffic obfuscation architecture, and develop AirCloak, an immediately deployable defense middleware that avoids app-level modification and minimizes performance overhead, making it especially practical for privacy-conscious users demanding high-security Wi-Fi environments. AirCloak relies on the cooperation between mobile terminals (e.g., smartphones) and the local Wi-Fi access point (AP), enabling real-time traffic cloaking while remaining transparent to the apps themselves. Despite its promise, AirCloak faces critical challenges: traffic heterogeneity and defense evasion. To overcome these challenges, a harmonization shaping obfuscation approach is proposed. It unifies traffic behaviors of structurally similar apps through adaptive generative synthesis, enabling efficient and resilient obfuscation that conceals discriminative fingerprints with minimal performance cost. We prototype AirCloak as a one-click installable app on mobile terminals and lightweight scripts on the AP. Extensive evaluations demonstrate AirCloak’s superior defensive effectiveness. It reduces the average F1-score of four WAF attacks from 0.77 to 0.19, while imposing negligible runtime overhead on both mobile terminals and the AP.
The Internet of Things (IoT) commonly adopts IEEE 802.11 wireless communication. However, the latest studies have revealed the advanced attacks that can analyze side-channel behavioral fingerprints of wireless frames to infer privacy-sensitive user behaviors. Obfuscating such fingerprints at the originating device has been widely regarded as the most fundamental defense strategy. However, this device-to-air approach conflicts with the realities of IoT: extreme heterogeneity, proprietary firmware, and limited resources render device-level modification impractical. As a result, what appears conceptually natural becomes a key barrier to scalable defense, leaving IoT users broadly exposed to the latest advanced attacks. To counter these emerging threats while enabling practical, wide-scale deployment, we present AirMask, the first air-to-air defense system that works transparently to IoT devices while protecting them adaptively. AirMask passively senses fingerprints in the air and injects carefully crafted frames into the air to mask occurring traffic fingerprints as needed. Despite its promise, the air-to-air defense faces three challenges: i) observing time-varying traffic of all devices while adaptively sensing occurring fingerprints for each device, ii) promptly injecting crafted frames that can mask fingerprints once they occur, and iii) camouflaging crafted frames to withstand adversarial filtering. To address these challenges, AirMask operates in a predict-inject-assess loop. This loop iteratively adapts to changing traffic patterns, proactively injects principally crafted frames upon the prediction of occurring fingerprints, and continuously refines device-specific obfuscation strategies against attacks. The injection removes fingerprints while maintaining the crafted frames’ context indistinguishability (e.g., protocol fields and sequence states) from authentic ones. We have implemented AirMask as a functional hardware prototype, offering Integrated, TAP, and Air modes for flexible deployment within WiFi networks to protect surrounding IoT devices. Extensive evaluations on 90 types of IoT devices and 53 fine-grained behaviors confirm AirMask’s defensive effectiveness, while incurring negligible bandwidth and latency overhead.
The DNS protocol, which is typically not blocked by firewalls, enables attackers to easily and efficiently establish tunnels and exfiltrate user information. Despite extensive research on DNS tunnel detection with promising results, a significant gap remains between experimental settings and real-world scenarios. This gap stems from the fact that existing methods predominantly depend on the quality of the training set, while attackers can adapt evasion techniques to create more covert and previously unknown tunnel types. To narrow this gap, we propose EvaSense, a real-time alert system for detecting DNS tunnels that employ diverse, potentially unseen evasion strategies. Our approach combines a behavior-based tunnel detection method with an agent-based online labeling method. We designed multiple DNS tunnels employing evasion strategies and conducted experiments on both real campus network traffic and public datasets. The experimental results demonstrate that EvaSense effectively detects these tunnels.
Despite the widespread adoption of encryption, such as TLS, encrypted proxies, and Tor, website fingerprinting (WF) has long been proven to be able to recognize web sites from encrypted traffic. However, existing WF methods were generally developed and evaluated under the implicit assumption that traffic samples for training and recognition are captured in the same environment. When applied to diverse environments affected by practical factors, such as various browsers and proxy software, they will be hampered by three-fold challenges: i) feature drift, ii) sampling dilemma, and iii) few-shot generalization. None of existing WF methods can fully address them. In this paper, we take the first step to cross-environmental WF and advance a systematic framework, dubbed X-EPRINT, to tackle the above challenges. X - EPRINT generates cross-environmentally invariant features to address feature drift. It mitigates sampling dilemma via potential-aware traffic resampling. X-EPRINT capitalizes on inter-flow data augmentation to solve few-shot generalization. We conduct extensive experiments to evaluate X-EPRINT. The experimental results demonstrate that X - EPRINT achieves a robust performance in zero-shot cross-environmental recognition, with an F1-score of 0.719, which is 58.4% higher than the top-performing baseline method. It also attains an F1-score of 0.925 in 3-shot recognition, fulfilling few-shot environment adaptation.
With the increasing popularity of autonomous driving systems (ADS) in autonomous vehicles (AV), in recent years, there have been many attacks targeting AVs and ADSs. Meanwhile, recent studies have attempted to improve the safety and security of AVs from different perspectives, and they mainly focus on the spoofing attacks against the sensors and the injection attacks against the vehicle chassis and actuators. However, direct attacks on ADSs (i.e., communication hijacking and malicious codes) remain inadequately addressed, and even worse, such attacks can cause AVs to make unsafe driving decisions rapidly. In this paper, we introduce DSAD, a driving state-aware anomaly detection framework designed to enhance AV safety and security by identifying ADS attacks, such as communication hijacking and malicious codes, through chassis states. First, DSAD models ADS operations (i.e., driving states) as a two-layer state machine, utilizing real-time chassis data to infer driving states and detect anomalies in ADS outputs. This reduces false positives and negatives by aligning detection with the diverse operational modes of AVs. To achieve this, we develop a prototype system, DSAD, incorporating a Detection Policy Update mechanism that dynamically adjusts detection policies based on the vehicle's driving states, such as lane changing and obstacle avoidance. Second, DSAD considers both collision avoidance and control stability, addressing potential conflicts through hard and soft requirements. Furthermore, DSAD integrates a fault handling module compatible with existing autonomous driving fault handling mechanisms, ensuring timely response to detected anomalies. We develop a prototype anomaly detection system called DSAD and deploy it on four ADSs. We evaluate DSAD using various attack scenarios, and the results show that DSAD can identify over 90% of attacks on ADSs.
The growing adoption of large pre-trained models in edge computing has made deploying model inference on mobile clients both practical and popular. These devices are inherently vulnerable to direct adversarial attacks, which pose a substantial threat to the robustness and security of deployed models. Federated adversarial training (FAT) has emerged as an effective solution to enhance model robustness while preserving client privacy. However, FAT frequently produces a generalized global model, which struggles to address the diverse and heterogeneous data distributions across clients, resulting in insufficiently personalized performance, while also encountering substantial communication challenges during the training process. In this paper, we propose Sylva, a personalized collaborative adversarial training framework designed to deliver customized defense models for each client through a two-phase process. In Phase 1, Sylva employs LoRA for local adversarial fine-tuning, enabling clients to personalize model robustness while drastically reducing communication costs by uploading only LoRA parameters during federated aggregation. In Phase 2, a game-based layer selection strategy is introduced to enhance accuracy on benign data, further refining the personalized model. This approach ensures that each client receives a tailored defense model that balances robustness and accuracy effectively. Extensive experiments on benchmark datasets demonstrate that Sylva can achieve up to 50x improvements in communication efficiency compared to state-of-the-art algorithms, while achieving up to 29.5% and 50.4% enhancements in adversarial robustness and benign accuracy, respectively.
Fingerprinting is a network reconnaissance technique utilized for gathering information about online computing systems, including operation systems and applications. Unfortunately, attackers typically leverage fingerprinting techniques to locate, enumerate, and subsequently target vulnerable systems, which is the first primary stage of a cyber attack. In this work, we explore the susceptibility of machine learning (ML)-based classifiers to misclassification, where a slight perturbation in the packet is included to spoof OS fingerprints. We propose SOFI (Spoof OS Fingerprints), an adversarial example generation algorithm under TCP/IP specification constraints, to create effective perturbations in a packet for deceiving an OS fingerprint. Specifically, SOFI has three major technical innovations: (1) it is the first to utilize adversarial examples to automatically perturb fingerprinting techniques; (2) it complies with constraints and integrity of network packets; (3) it achieves a high success rate in spoofing OS fingerprints. We validate the effectiveness of adversarial packets against active and passive OS fingerprints, verifying the transferability and robustness of SOFI. Comprehensive experimental results demonstrate that SOFI automatically identifies applicable and available OS fingerprint features, unlike existing tools relying on expert knowledge.
The progress of automotive technologies has made cybersecurity a crucial focus, leading to various cyber attacks. These attacks primarily target the Controller Area Network (CAN) and specialized Electronic Control Units (ECUs). In order to mitigate these attacks and bolster the security of vehicular systems, numerous defense solutions have been proposed. These solutions aim to detect diverse forms of vehicular attacks. However, the practical implementation of these solutions still presents certain limitations and challenges. In light of these circumstances, this paper undertakes a thorough examination of existing vehicular attacks and defense strategies employed against the CAN and ECUs. The objective is to provide valuable insights and inform the future design of Vehicular Intrusion Detection Systems (VIDS). The findings of our investigation reveal that the examined VIDS primarily concentrate on particular categories of attacks, neglecting the broader spectrum of potential threats. Moreover, we provide a comprehensive overview of the significant challenges encountered in implementing a robust and feasible VIDS. Additionally, we put forth several defense recommendations based on our study findings, aiming to inform and guide the future design of VIDS in the context of vehicular security.
In vehicular ad-hoc networks (VANET), federated learning enables vehicles to collaboratively train a global model for intelligent transportation without sharing their local data. However, due to dynamic network structure and unreliable wireless communication of VANET, various potential risks (e.g., identity privacy leakage, data privacy inference, model integrity compromise, and data manipulation) undermine the trustworthiness of intermediate model parameters necessary for building the global model. While existing cryptography techniques and differential privacy provide provable security paradigms, the practicality of secure federated learning in VANET is hindered in terms of training efficiency and model performance. Therefore, developing a secure and efficient federated learning in VANET remains a challenge. In this work, we propose a privacy-enhanced and efficient authentication protocol for federated learning in VANET, called FedComm. Unlike existing solutions, FedComm addresses the above challenge through user anonymity. First, FedComm enables vehicles to participate in training with unlinkable pseudonyms, ensuring both privacy preservation and efficient collaboration. Second, FedComm incorporates an efficient authentication protocol to guarantee the authenticity and integrity of model parameters originated from anonymous vehicles. Finally, FedComm accurately identifies and completely eliminates malicious vehicles in anonymous communication. Security analysis and verification with ProVerif demonstrate that FedComm enhances privacy and reliability of intermediate model parameters. Experimental results show that FedComm reduces the overhead of proof generation and verification by 67.38% and 67.39%, respectively, compared with the state-of-the-art authentication protocols used in federated learning.
Over the years, network traffic analysis and generation have advanced significantly. From traditional statistical methods, the field has progressed to sophisticated deep learning techniques. This progress has improved the ability to detect complex patterns and security threats, as well as to test and optimize network performance. However, obstacles persist, such as the dependence on labeled data for analysis and the difficulty of generating traffic samples that follow realistic patterns. Pre-trained deep neural networks have emerged as powerful tools to resolve these issues, offering improved performance by learning robust data representations from large unlabeled datasets. Despite their benefits, existing pre-trained models face challenges like token length limitation, which restricts their usefulness in comprehensive traffic analysis and realistic traffic generation. To address these challenges, we introduce TrafficGPT, a deep learning model that can tackle complex challenges related to long flow classification and generation tasks. This model uses generative pre-training with the linear attention mechanism, which allows for a substantially increased capacity of up to 12,032 tokens from the previous limit of only 512 tokens. TrafficGPT demonstrates superior performance in classification tasks, reaching state-of-the-art levels. In generation tasks, it closely resembles real traffic flows, with low JS divergence and an F1 score close to 0.5 (representing a random guess) in discriminating generated data. These advancements hold promise for future applications in both traffic flow classification and generation tasks.
Mobile apps have significantly transformed various aspects of modern life, leading to growing concerns about privacy risks. Despite widespread encrypted communication, app fingerprinting (AF) attacks threaten user privacy substantially. However, existing AF attacks, when targeted at wireless traffic, face four fundamental challenges, namely 1) sample inseparability; 2) app multiplexing; 3) signal attenuation; and 4) open-world recognition. In this paper, we advance a novel AF attack, dubbed, to recognize app user activities over the air in an open-world setting. We introduce two novel models, i.e., sequential XGBoost and hierarchical bag-of-words model, to tackle sample inseparability and enhance robustness against noise packets arising from app multiplexing. We also propose the environment-aware model enhancement to bolster 's robustness in handling packet loss at the sniffer caused by signal attenuation. We conduct extensive experiments to evaluate the proposed attack in a series of challenging scenarios, including 1) open-world setting; 2) simultaneous use of different apps; 3) severe packet loss at the sniffer; and 4) cross-dataset recognition. The experimental results show that can accurately recognize app user activities. It achieves the average F1-score 0.947 for open-world app recognition and the average F1-score 0.959 for in-app user action recognition.
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping's mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and real-world experiments demonstrate that our system can scan up to around 40 times as many IP-device mapping mutations as random/sequential scanning.
Website fingerprinting (WFP) could infer which websites a user is accessing via an encrypted proxy by passively inspecting the traffic characteristics of accessing different websites between the user and the proxy. Designing WFP attacks is crucial for understanding potential vulnerabilities of encrypted proxies, which guides the design of defensive measures against WFP. In this paper, we design a novel WFP attack against (popular) encrypted proxies that relay connections between the user and the proxy individually (e.g., Shadowsocks, V2Ray), and accordingly implement lightweight countermeasures to effectively defend against the attack. The attack features flow-context-aware and is both accurate and immediately deployable, because it fully considers the obstacle (dubbed training-testing asymmetry) that fundamentally limits the practicability of WFP and addresses the obstacle with built-in spatial-temporal flow correlation mechanism. We implement the countermeasure as middleboxes installed on both the client and server sides of encrypted proxies, without altering any existing infrastructures for compatibility. The middleboxes can obfuscate a website's flow regularities across different visits. Large-scale experiments in real-world scenarios demonstrate that the WFP attack can generally achieve a detection rate above 98.8% with a false positive rate below 0.2%. The countermeasure forces the attack's false positive rate to be above 0.2 and true positive rate to be below 0.9 with just five persistent TCP connections while introducing very limited bandwidth overhead (e.g., 0.49%) and almost-zero additional network latency.
Deep neural network (DNN) foundation models are currently exhibiting high prediction accuracy and strong adaptability to broad tasks with remarkably large model scales. They are increasingly becoming the backend support of DNN-driven real-time online services, e.g., Siri and Instagram. Such services require low-latency and cost-efficiency for quality-of-service and commercial competitiveness. When deployed in a cloud environment, these services call for an appropriate selection of cloud configurations (i.e., specific types of VM instances), as well as a considerate device placement plan that places the operations of the model to multiple GPUs via model parallelism for cost-efficiency. Currently, the deployment mainly relies on service providers’ manual efforts, which is not only onerous but also far from satisfactory oftentimes due to the huge joint search space of cloud configurations and device placement plans (for a same service, a poor deployment can incur significantly more costs by tens of times). In this paper, we attempt to efficiently automate the cloud deployment for real-time foundation model inference with minimum costs under the constraint of acceptably low latency. This attempt is enabled by 1) jointly leveraging the Bayesian Optimization and Deep Reinforcement Learning to adaptively unearth the (nearly) optimal cloud configuration and device placement with limited search time, and 2) enhancing the cost-efficiency of the deployment based on the probing-informed block multiplexing mechanism and Tensor Algebra SuperOptimizer. We implement a prototype system based on TensorFlow, conduct extensive experiments on top of Microsoft Azure, and demonstrate the generality and scalability of our solution. Results show that for lightweight DNN models and foundation models, our solution essentially saves inference costs by up to 15% and 47% with 57% and 38% lower search overheads respectively, compared with non-trivial baselines.
The Domain Name System (DNS) is indispensable for almost all Internet services. It has been extensively studied for applications such as anomaly detection. However, the fundamental question of whether a DNS query from a querent (i.e., an IP address) is triggered by humans or issued by software entities remains unclear. Addressing this question enables us to profile the querent’s behavior from a human-software perspective, facilitating the understanding of “who is DNS serving for?”. In this study, we systematically performed querent-centric DNS modeling. Through in-depth measurements of three real-world DNS datasets of diverse origins, we developed an entropy-based method to distinguish between human and non-human queries and proposed a semi-supervised solution towards a community-level view for detecting and estimating software entities in a network. The solution can not only detect unknown software entities but is also NAT-compatible because it can detect and estimate software entities of multiple hosts NATed behind a single querent. An extensive evaluation demonstrates that our approach provides a new functionality for automatically disclosing the distinction between human and non-human domain names as well as a priori-independent and NAT-compatible functionality of discovering nearly 50% of the software entities and estimating their population using DNS queries.