Adaptive Traffic Camouflage: Causal and Resource-Aware Defense Against IoT Fingerprinting
A causal IoT traffic-camouflage defense cuts fingerprinting Macro-F1 by up to 43.5% with limited bandwidth cost.
Researchers present Adaptive Traffic Camouflage, a causal controller that estimates IoT traffic-shape leakage without runtime device labels and selects a budget-feasible transform for the next window. Choices include padding, packet splitting, timing changes, composites, or leaving traffic unchanged. On CIC-IoT-2022, IoT Sentinel, and UNSW, the Balanced profile reduced mean Macro-F1 by 13.2-23.3% versus clean traffic, with 4.88-7.47% average bandwidth overhead and at most 0.64 ms added latency. The Privacy profile reached a 28.0-43.5% reduction, but defense-aware training recovered much attacker performance on CIC-IoT-2022 and UNSW.
- Controller picks padding, splitting, timing, or no change per window.
- Balanced profile cuts Macro-F1 13.2-23.3% with under 7.5% bandwidth overhead.
- Privacy profile reduces fingerprinting Macro-F1 by 28.0-43.5%.
- Defense-aware training recovers much attacker accuracy on two datasets.
Full article206 words · extracted from arxiv.org · click to collapse
Encryption hides IoT payloads, but traffic shape can still reveal device identity through packet sizes, timing, direction, and packetization. We present Adaptive Traffic Camouflage, a causal, leakage-aware controller that characterizes traffic-shape leakage without runtime device labels and selects a budget-feasible transformation for the next traffic window from previous-window context. The controller chooses among padding, packet splitting, timing, and composite transformations, or leaves traffic unchanged when camouflage is unnecessary. We evaluate the design on CIC-IoT-2022, IoT Sentinel, and UNSW using classical and sequence-based fingerprinting models under clean-trained, defense-aware, and incremental-exposure settings, with fixed, random, and mean-bandwidth-matched baselines. Under the Balanced profile, camouflage reduces mean Macro-F1 by 13.2-23.3% relative to clean traffic with 4.88-7.47% average bandwidth overhead and at most 0.64 ms added latency. Under the larger Privacy profile, the reduction increases to 28.0-43.5%. Defense-aware training recovers much of the lost attacker performance on CIC-IoT-2022 and UNSW, while IoT Sentinel retains a substantial privacy gap. A non-causal same-window reference provides only modest additional benefit over previous-window control, and metadata-rich attackers remain effective outside the targeted traffic-shape surface. These results show that causal, resource-aware camouflage can reduce IoT traffic-shape fingerprintability under explicit communication constraints, while the persistence of protection depends on how readily the defended distribution can be learned.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.25787