VLDB 2026 Research / reviewers in the wild / expert
Rob Jansen
dblp:14/7561
· DBLP profile ↗
39ranked-venue papers
22as first author
20since 2021 · last 2026
0000-0002-4406-997XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 36 · 21 first-author · 18 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CELLSHIFT: RTT-Aware Trace Transduction for Real-World Website Fingerprinting
Rob Jansen |
NDSS | 1 |
| 2026 | A Measurement of Genuine Tor Traces for Realistic Website Fingerprinting
Rob Jansen, Ryan Wails, Aaron Johnson 0001 |
PAM | 1 |
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 1 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 2 |
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 2 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 2 |
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 3 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 2 |
| 2026 | Editors' IntroductionabstractEditors' Introduction, Issue 4 of PoPETs Volume 2026 Gunes Acar, Rob Jansen |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | Censorship Evasion with Unidentified Protocol Generation
Ryan Wails, Rob Jansen, Aaron Johnson 0001, Micah Sherr |
USENIX Security Symposium | 2 |
| 2025 | Editors' IntroductionabstractEditors' Introduction, Issue 1 of PETS Volume 2025 Rob Jansen, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Editors' IntroductionabstractEditors' Introduction, Issue 2 of PETS Volume 2025 Rob Jansen, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Editors' IntroductionabstractEditors' Introduction, Issue 3 of PETS Volume 2025 Rob Jansen, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Editors' IntroductionabstractEditors' Introduction, Issue 4 of PETS Volume 2025 Rob Jansen, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Onion-Location Measurements and FingerprintingabstractOnion-Location makes it easy for websites offering onion service access to support automatic discovery in Tor Browser of the random-looking onion address associated with their domain. We provide the first measurement study of how many websites are currently using Onion-Location. We also describe the open-source tools we created to conduct the study. Onion-Location has been criticized elsewhere for its lack of transparency and vulnerability to blocking. Perhaps even more troubling, we show that Onion-Location is vulnerable to very accurate fingerprinting. We present recommended changes to and alternatives to Onion-Location as well as steps towards even more secure onion discovery and association. Paul F. Syverson, Rasmus Dahlberg, Tobias Pulls, Rob Jansen |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | On Precisely Detecting Censorship Circumvention in Real-World Networks
Ryan Wails, George Arnold Sullivan, Micah Sherr, Rob Jansen |
NDSS | 4 |
| 2023 | Data-Explainable Website Fingerprinting with Network SimulationabstractWebsite fingerprinting (WF) attacks allow an adversary to associate a website with the encrypted traffic patterns produced when accessing it, thus threatening to destroy the client-server unlinkability promised by anonymous communication networks. Explainable WF is an open problem in which we need to improve our understanding of (1) the machine learning models used to conduct WF attacks; and (2) the WF datasets used as inputs to those models. This paper focuses on explainable datasets; that is, we develop an alternative to the standard practice of gathering low-quality WF datasets using synthetic browsers in large networks without controlling for natural network variability. In particular, we demonstrate how network simulation can be used to produce explainable WF datasets by leveraging the simulator's high degree of control over network operation. Through a detailed investigation of the effect of network variability on WF performance, we find that: (1) training and testing WF attacks in networks with distinct levels of congestion increases the false-positive rate by as much as 200%; (2) augmenting the WF attacks by training them across several networks with varying degrees of congestion decreases the false-positive rate by as much as 83%; and (3) WF classifiers trained on completely simulated data can achieve greater than 80% accuracy when applied to the real world. Rob Jansen, Ryan Wails |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | Co-opting Linux Processes for High-Performance Network Simulation
Rob Jansen, James Newsome, Ryan Wails |
USENIX ATC | 1 |
| 2022 | Online Website Fingerprinting: Evaluating Website Fingerprinting Attacks on Tor in the Real World
Giovanni Cherubin, Rob Jansen, Carmela Troncoso |
USENIX Security Symposium | 2 |
| 2022 | Learning to Behave: Improving Covert Channel Security with Behavior-Based DesignsabstractCensorship-resistant communication systems generally use real-world cover protocols to establish a covert channel through which uncensored communication can occur. Unfortunately, many previously proposed systems use cover protocols inconsistently with the way humans normally use those protocols, leading to anomalous network traffic patterns that have been shown to be discoverable by real-world censors. In this paper, we argue that censorship-resistant communication systems should follow two behavior-based design properties: (i) behavioral independence: systems should isolate the operation of their covert channels from the operation of their cover protocols, and (ii) behavioral realism: systems should either opportunistically use existing genuine cover protocol instances or run new protocol instances that are modeled after genuine ones. These properties ensure that the behavior of a system’s users will not degrade its security. We demonstrate how to achieve these properties through the design and evaluation of Raven, a censorship-resistant messaging system that uses email cover protocols identically to the way humans use email. Raven uses a generative adversarial network that is trained on genuine email data to control the timing and sizes of the email messages it sends and receives, and these messages are transferred independently of user actions. Our evaluation shows that, compared to the state-of-the-art email-based Mailet system, Raven raises the false-positive rate from 3% to 50% when detecting covert channel usage with 100% recall. Ryan Wails, Andrew Stange, Eliana Troper, Aylin Caliskan, Roger Dingledine, Rob Jansen, Micah Sherr |
Proc. Priv. Enhancing Technol. | 6 |
| 2021 | FlashFlow: A Secure Speed Test for TorabstractThe Tor network uses a measurement system called TorFlow to estimate its relays' forwarding capacity and to balance traffic among them. This system has been shown to be vulnerable to adversarial manipulation, and inaccuracies even in benign circumstances have long been observed. To solve the issues with security and accuracy, we present FlashFlow, a system to measure the capacity of Tor relays. Our analysis shows that FlashFlow limits a malicious relay to obtaining a capacity estimate at most 1.33 times its true capacity. Through realistic Internet experiments, we find that FlashFlow measures relay capacity with$\geq {89\%}$accuracy 95 % of the time. Through simulation, we find that FlashFlow can measure the entire Tor network in less than 5 hours using 3 measurers with 1 Gbit/s of bandwidth each. Performance simulations using FlashFlow for load balancing shows that, compared to TorFlow, network weight error decreases by 86 %, while the median of 50 KiB, 1 MiB, and 5 MiB transfer times decreases by 15 %, 29 %, and 37 %, respectively. Moreover, FlashFlow yields more consistent client performance: the median rate of transfer timeouts decreases by 100 %, while the standard deviation of 50 KiB, 1 MiB, and 5 MiB transfer times decreases by 55%, 61 %, and 41 %, respectively. We also find that the performance improvements increase relative to TorFlow as the total client-traffic load increases, demonstrating that FlashFlow is better suited to supporting network growth. Matthew Traudt, Rob Jansen, Aaron Johnson 0001 |
ICDCS | 2 |
| 2021 | On the Accuracy of Tor Bandwidth Estimation
Rob Jansen, Aaron Johnson 0001 |
PAM | 1 |
| 2021 | Once is Never Enough: Foundations for Sound Statistical Inference in Tor Network Experimentation
Rob Jansen, Justin Tracey, Ian Goldberg 0001 |
USENIX Security Symposium | 1 |
| 2019 | Point Break: A Study of Bandwidth Denial-of-Service Attacks against Tor
Rob Jansen, Tavish Vaidya, Micah Sherr |
USENIX Security Symposium | 1 |
| 2019 | KIST: Kernel-Informed Socket Transport for TorabstractTor’s growing popularity and user diversity has resulted in network performance problems that are not well understood, though performance is understood to be a significant factor in Tor’s security. A large body of work has attempted to solve performance problems without a complete understanding of where congestion occurs in Tor. In this article, we first study congestion in Tor at individual relays as well as along the entire end-to-end Tor path and find that congestion occurs almost exclusively in egress kernel socket buffers. We then analyze Tor’s socket interactions and discover two major contributors to Tor’s congestion: Tor writes sockets sequentially, and Tor writes as much as possible to each socket. To improve Tor’s performance, we design, implement, and test KIST: a new socket management algorithm that uses real-time kernel information to dynamically compute the amount to write to each socket while considering all circuits of all writable sockets when scheduling cells. We find that, in the medians, KIST reduces circuit congestion by more than 30%, reduces network latency by 18%, and increases network throughput by nearly 10%. We also find that client and relay performance with KIST improves as more relays deploy it and as network load and packet loss rates increase. We analyze the security of KIST and find an acceptable performance and security tradeoff, as it does not significantly affect the outcome of well-known latency, throughput, and traffic correlation attacks. KIST has been merged and configured as the default socket scheduling algorithm in Tor version 0.3.2.1-alpha (released September 18, 2017) and became stable in Tor version 0.3.2.9 (released January 9, 2018). While our focus is Tor, our techniques and observations should help analyze and improve overlay and application performance, both for security applications and in general. Rob Jansen, Matthew Traudt, John Geddes, Chris Wacek, Micah Sherr, Paul F. Syverson |
ACM Trans. Priv. Secur. | 1 |
| 2018 | Privacy-Preserving Dynamic Learning of Tor Network TrafficabstractExperimentation tools facilitate exploration of Tor performance and security research problems and allow researchers to safely and privately conduct Tor experiments without risking harm to real Tor users. However, researchers using these tools configure them to generate network traffic based on simplifying assumptions and outdated measurements and without understanding the efficacy of their configuration choices. In this work, we design a novel technique for dynamically learning Tor network traffic models using hidden Markov modeling and privacy-preserving measurement techniques. We conduct a safe but detailed measurement study of Tor using 17 relays (~2% of Tor bandwidth) over the course of 6 months, measuring general statistics and models that can be used to generate a sequence of streams and packets. We show how our measurement results and traffic models can be used to generate traffic flows in private Tor networks and how our models are more realistic than standard and alternative network traffic generation~methods. Rob Jansen, Matthew Traudt, Nicholas Hopper |
CCS | 1 |
| 2018 | Understanding Tor Usage with Privacy-Preserving Measurement
Akshaya Mani, T. Wilson-Brown, Rob Jansen, Aaron Johnson 0001, Micah Sherr |
Internet Measurement Conference | 3 |
| 2018 | Inside Job: Applying Traffic Analysis to Measure Tor from Within
Rob Jansen, Marc Juarez, Rafa Gálvez, Tariq Elahi, Claudia Díaz |
NDSS | 1 |
| 2017 | Avoiding The Man on the Wire: Improving Tor's Security with Trust-Aware Path Selection
Aaron Johnson 0001, Rob Jansen, Aaron D. Jaggard, Joan Feigenbaum, Paul F. Syverson |
NDSS | 2 |
| 2017 | PeerFlow: Secure Load Balancing in TorabstractAbstract We present PeerFlow, a system to securely load balance client traffic in Tor. Security in Tor requires that no adversary handle too much traffic. However, Tor relays are run by volunteers who cannot be trusted to report the relay bandwidths, which Tor clients use for load balancing. We show that existing methods to determine the bandwidths of Tor relays allow an adversary with little bandwidth to attack large amounts of client traffic. These methods include Tor’s current bandwidth-scanning system, TorFlow, and the peer-measurement system EigenSpeed. We present an improved design called PeerFlow that uses a peer-measurement process both to limit an adversary’s ability to increase his measured bandwidth and to improve accuracy. We show our system to be secure, fast, and efficient. We implement PeerFlow in Tor and demonstrate its speed and accuracy in large-scale network simulations. Aaron Johnson 0001, Rob Jansen, Nicholas Hopper, Aaron Segal, Paul F. Syverson |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | Safely Measuring TorabstractTor is a popular network for anonymous communication. The usage and operation of Tor is not well-understood, however, because its privacy goals make common measurement approaches ineffective or risky. We present PrivCount, a system for measuring the Tor network designed with user privacy as a primary goal. PrivCount securely aggregates measurements across Tor relays and over time to produce differentially private outputs. PrivCount improves on prior approaches by enabling flexible exploration of many diverse kinds of Tor measurements while maintaining accuracy and privacy for each. We use PrivCount to perform a measurement study of Tor of sufficient breadth and depth to inform accurate models of Tor users and traffic. Our results indicate that Tor has 710,000 users connected but only 550,000 active at a given time, that Web traffic now constitutes 91% of data bytes on Tor, and that the strictness of relays' connection policies significantly affects the type of application data they forward. Rob Jansen, Aaron Johnson 0001 |
CCS | 1 |
| 2015 | WPES 2015: The 14th Workshop on Privacy in the Electronic SocietyabstractWe present a brief summary of The 14th Workshop on Privacy in the Electronic Society, held on October 12th, 2015, in conjunction with the 22nd ACM Conference on Computer and Communications Security in Denver, Colorado, USA. The goal of this workshop is to discuss the problems of privacy in the global interconnected societies and possible solutions to them. The workshop program includes 11 full papers and 3 short papers out of 32 total submissions. Specific areas that are covered in the program include, but are not limited to: web and social network privacy, mobile and location privacy, communications privacy, and privacy-preserving data analysis. Nicholas Hopper, Rob Jansen |
CCS | 2 |
| 2014 | The Sniper Attack: Anonymously Deanonymizing and Disabling the Tor Network
Rob Jansen, Florian Tschorsch, Aaron Johnson 0001, Björn Scheuermann 0001 |
NDSS | 1 |
| 2014 | Never Been KIST: Tor's Congestion Management Blossoms with Kernel-Informed Socket Transport
Rob Jansen, John Geddes, Chris Wacek, Micah Sherr, Paul F. Syverson |
USENIX Security Symposium | 1 |
| 2013 | Users get routed: traffic correlation on tor by realistic adversariesabstractWe present the first analysis of the popular Tor anonymity network that indicates the security of typical users against reasonably realistic adversaries in the Tor network or in the underlying Internet. Our results show that Tor users are far more susceptible to compromise than indicated by prior work. Specific contributions of the paper include(1)a model of various typical kinds of users,(2)an adversary model that includes Tor network relays, autonomous systems(ASes), Internet exchange points (IXPs), and groups of IXPs drawn from empirical study,(3) metrics that indicate how secure users are over a period of time,(4) the most accurate topological model to date of ASes and IXPs as they relate to Tor usage and network configuration,(5) a novel realistic Tor path simulator (TorPS), and(6)analyses of security making use of all the above. To show that our approach is useful to explore alternatives and not just Tor as currently deployed, we also analyze a published alternative path selection algorithm, Congestion-Aware Tor. We create an empirical model of Tor congestion, identify novel attack vectors, and show that it too is more vulnerable than previously indicated. Aaron Johnson 0001, Chris Wacek, Rob Jansen, Micah Sherr, Paul F. Syverson |
CCS | 3 |
| 2013 | LIRA: Lightweight Incentivized Routing for Anonymity
Rob Jansen, Aaron Johnson 0001, Paul F. Syverson |
NDSS | 1 |
| 2013 | How Low Can You Go: Balancing Performance with Anonymity in Tor
John Geddes, Rob Jansen, Nicholas Hopper |
Privacy Enhancing Technologies | 2 |
| 2012 | Shadow: Running Tor in a Box for Accurate and Efficient Experimentation
Rob Jansen, Nicholas Hopper |
NDSS | 1 |
| 2012 | Throttling Tor Bandwidth Parasites
Rob Jansen, Nicholas Hopper, Paul F. Syverson |
NDSS | 1 |
| 2012 | Throttling Tor Bandwidth Parasites
Rob Jansen, Paul F. Syverson, Nicholas Hopper |
USENIX Security Symposium | 1 |
| 2010 | Recruiting new tor relays with BRAIDSabstractTor, a distributed Internet anonymizing system, relies on volunteers who run dedicated relays. Other than altruism, these volunteers have no incentive to run relays, causing a large disparity between the number of users and available relays. We introduce BRAIDS, a set of practical mechanisms that encourages users to run Tor relays, allowing them to earn credits redeemable for improved performance of both interactive and non-interactive Tor traffic. These performance incentives will allow Tor to support increasing resource demands with almost no loss in anonymity: BRAIDS is robust to well-known attacks. Using a simulation of 20,300 Tor nodes, we show that BRAIDS allows relays to achieve 75% lower latency than non-relays for interactive traffic, and 90% higher bandwidth utilization for non-interactive traffic. Rob Jansen, Nicholas Hopper, Yongdae Kim |
CCS | 1 |
| 2009 | Membership-concealing overlay networksabstractWe introduce the concept of membership-concealing overlay networks (MCONs), which hide the real-world identities of participants. We argue that while membership concealment is orthogonal to anonymity and censorship resistance, pseudonymous communication and censorship resistance become much easier if done over a membership-concealing network. We formalize the concept of membership concealment, discuss a number of attacks against existing systems and present real-world attack results. We then propose three proof-of-concept MCON designs that resist those attacks: one that is more efficient, another that is more robust to membership churn, and a third that balances efficiency and robustness. We show theoretical and simulation results demonstrating the feasibility and performance of our schemes. Eugene Y. Vasserman, Rob Jansen, James Tyra, Nicholas Hopper, Yongdae Kim |
CCS | 2 |