Armon Barton

dblp:189/1752 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-8227-3621ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PadNet: Defending Neural Networks Against Adversarial Examples
abstract
Machine learning (ML) suffers from a persistent and critical flaw: adversarial examples. Many new forms of adversarial example attacks have been invented and many narrow defenses have been proposed. Unfortunately, no defensive approach can withstand current attacks. We hypothesize that ML model robustness can be improved with approaches that delineate the data-point-sparse latent space between data-dense regions of a model’s classification space as a barrier class. We introduce one such defense, PadNet, that builds a barrier class using a combination of training samples that mix multiple classes together. It leverages this barrier class to separate decision boundaries between benign classes with regions of padding. PadNet then implements a gradient regularization strategy that penalizes gradients in the direction of the barrier class, causing the decision boundary to draw tighter around training samples increasing boundary thickness between classes. We evaluate PadNet against a sampling of the most effective state-of-the-art attacks, demonstrating that it offers significant robustness and reliability compared to current defenses. We also test it against adaptive attacks and find that PadNet remains robust against them.
Armon Barton, Matthew Wright 0001, Shaikh Akib Shahriyar, Edgar W. Jatho III, Mohammad Saidur Rahman 0002, Kantha Girish Gangadhara, Jiang Ming 0002
ACM Trans. Priv. Secur.1
2025 Ivory: Adversarial Purification of Obfuscated Faces to Extract Soft-Biometrics using Diffusion Transformers
abstract
The proliferation of online face images has heightened privacy concerns, as adversaries can exploit facial features for nefarious purposes. While adversarial perturbations have been proposed to safeguard these images, their effectiveness remains questionable. This paper introduces IVORY, a novel adversarial purification method leveraging Diffusion Transformerbased Stable Diffusion 3 model to purify perturbed images and improve facial feature extraction. Evaluated across gender recognition, ethnicity recognition and age group classification tasks with CNNs like VGG16, SENet and MobileNetV3 and vision transformers like SwinFace, Ivory consistently restores classifier performance to near-clean levels in white-box settings, outperforming traditional defenses such as Adversarial Training, DiffPure and IMPRESS. For example, it improved gender recognition accuracy from $37.8 \%$ to $96 \%$ under the PGD attack for VGG16 and age group classification accuracy from $\mathbf{2. 1 \%}$ to $\mathbf{5 2. 4 \%}$ under AutoAttack for MobileNetV3. In black-box scenarios, IVORY achieves a $22.8 \%$ average accuracy gain. IVORY also reduces SSIM noise by over $50 \%$ at 1x resolution and up to $80 \%$ at $2 x$ resolution compared to DiffPure. Our analysis further reveals that adversarial perturbations alone do not fully protect against soft-biometric extraction, highlighting the need for comprehensive evaluation frameworks and robust defenses.
Shaikh Akib Shahriyar, Matthew Wright 0001, Armon Barton
FG3
2025 Improved Open-World Fingerprinting Increases Threat to Streaming Video Privacy but Realistic Scenarios Remain Difficult
abstract
Recent work on video stream fingerprinting has begun to explore its effectiveness in large open-world scenarios, in which the vast majority of test samples are from unmonitored videos that are unknown to the model at training time, showing that it is more difficult than earlier small open-world results have suggested. However, the evaluated approach employed deep learning techniques with potential shortcomings for the open-world task. We build on that work to evaluate more advanced techniques drawn from the literature on open set recognition, out-of-distribution detection, and robustness to adversarial examples, hypothesizing that they can improve effectiveness. We find that combinations of techniques can improve effectiveness, cutting the open-world false positive rate by up to 92% at a recall of 0.5. However, precision would likely still be problematic at the full-scale of the largest platforms hosting hundreds of millions or more videos. Additionally, we find that introducing two other dimensions of realism - when training and test sets are streamed from different vantage points, and when monitoring shorter videos or traffic flows - can greatly increase open-world false positives, making the full-scale open-world task even more difficult. Accordingly, we call for more work to focus on larger and more realistic open-world scenarios to continue to gain a better understanding of the effective envelope for fingerprinting.
Timothy Walsh 0002, Armon Barton, Mathias Kölsch
Proc. Priv. Enhancing Technol.2
2025 PredicTor: A Global, Machine Learning Approach to Tor Path Selection
abstract
Tor users derive anonymity in part from the size of the Tor user base, but Tor struggles to attract and support more users due to performance limitations. Previous works have proposed modifications to Tor’s path selection algorithm to enhance both performance and security, but many proposals have unintended consequences due to incorporating information related to client location. We instead propose selecting paths using a global view of the network, independent of client location, and we propose doing so with a machine learning classifier to predict the performance of a given path before building a circuit. We show through a variety of simulated and live experimental settings, across different time periods, that this approach can significantly improve performance compared to Tor’s default path selection algorithm and two previously proposed approaches. In addition to evaluating the security of our approach with traditional metrics, we propose a novel anonymity metric that captures information leakage resulting from location-aware path selection, and we show that our path selection approach leaks no more information than the default path selection algorithm.
Armon Barton, Timothy Walsh 0002, Mohsen Imani, Jiang Ming 0002, Matthew Wright 0001
ACM Trans. Priv. Secur.1
2025 Defending Against Deep Learning-Based Traffic Fingerprinting Attacks With Adversarial Examples
abstract
In an increasingly digital and interconnected world, online anonymity and privacy are paramount issues for Internet users. To address this, tools like The Onion Router (Tor) offer anonymous and private communication by routing traffic through multiple relays with multiple layers of encryption. However, traffic fingerprinting attacks have threatened anonymity and privacy. In response, the community has proposed additional defenses for Tor, but fingerprinting techniques that utilize deep neural networkss (DNNs) have undermined many of these defenses. The latest defenses that are both lightweight and robust against DNNs use adversarial examples, but these defenses require either the full traffic trace beforehand or a database of pre-computed adversarial examples. We propose Prism , a defense against fingerprinting attacks that utilizes adversarial examples with neither prior access to the full traffic trace nor a database. We describe a novel method of adversarial example generation as input is learned over time. Prism injects these adversarial examples into the Tor traffic stream to prevent DNNs from accurately classifying both websites and videos that a user is viewing, even if the DNN is hardened by adversarial training. We also show that the Tor network could implement Prism entirely on relays under certain conditions, extending the defense to users who may run Tor on devices without graphics processing units.
Blake Hayden, Timothy Walsh 0002, Armon Barton
ACM Trans. Priv. Secur.3
2023 Optimizing Naval Movement Using Deep Reinforcement Learning
abstract
In a rapidly evolving maritime warfare landscape, the U.S. Navy and its allies require their crews to quickly identify optimal strategies for vessel engagements to ensure freedom of the seas. This necessity becomes more pronounced given the potential grave consequences of sub-optimal maneuvers, as illustrated by the cases of the USS John McCain and USS Fitzgerald. Recent advancements in Machine Learning (ML) and Artificial Intelligence (AI) offer a promising solution. There have been significant strides in implementing AI to outperform human experts in complex games such as Chess, Poker, and StarCraft that now have the potential to also benefit real-time decision-making and wargaming in the naval domain. This study explores the potential for Reinforcement Learning (RL) techniques to be applied in naval contexts, which could provide valuable decision-support tools to ship captains and their staffs by suggesting optimal movement strategies in complex maritime scenarios. In this study, exemplar naval scenarios were designed and modeled within a combat simulation environment, AI agents (consisting of a mix of rule-based, method-based, and value-based approaches) were designed, and the performances of these agents were evaluated and compared. The aim was to assess the agents' ability to identify optimal movements against a rule-based adversary, while also comparing these performances against human-level play. The insights drawn from this study contribute to ongoing research aimed at developing effective decision aids for ship captains in real-world operations.
Joseph Coble, Armon Barton, Christian J. Darken, Scotty Black
ICMLA2
2018 Towards Predicting Efficient and Anonymous Tor Circuits
Armon Barton, Matthew Wright 0001, Jiang Ming 0002, Mohsen Imani
USENIX Security Symposium1
2018 Guard Sets in Tor using AS Relationships
abstract
Abstract The mechanism for picking guards in Tor suffers from security problems like guard fingerprinting and from performance issues. To address these issues, Hayes and Danezis proposed the use of guard sets, in which the Tor system groups all guards into sets, and each client picks one of these sets and uses its guards. Unfortunately, guard sets frequently need nodes added or they are broken up due to fluctuations in network bandwidth. In this paper, we first show that these breakups create opportunities for malicious guards to join many guard sets by merely tuning the bandwidth they make available to Tor, and this greatly increases the number of clients exposed to malicious guards. To address this problem, we propose a new method for forming guard sets based on Internet location. We construct a hierarchy that keeps clients and guards together more reliably and prevents guards from easily joining arbitrary guard sets. This approach also has the advantage of confining an attacker with access to limited locations on the Internet to a small number of guard sets. We simulate this guard set design using historical Tor data in the presence of both relay-level adversaries and networklevel adversaries, and we find that our approach is good at confining the adversary into few guard sets, thus limiting the impact of attacks.
Mohsen Imani, Armon Barton, Matthew Wright 0001
Proc. Priv. Enhancing Technol.2
2016 DeNASA: Destination-Naive AS-Awareness in Anonymous Communications
abstract
Abstract Prior approaches to AS-aware path selection in Tor do not consider node bandwidth or the other characteristics that Tor uses to ensure load balancing and quality of service. Further, since the AS path from the client’s exit to her destination can only be inferred once the destination is known, the prior approaches may have problems constructing circuits in advance, which is important for Tor performance. In this paper, we propose and evaluate DeNASA, a new approach to AS-aware path selection that is destination-naive, in that it does not need to know the client’s destination to pick paths, and that takes advantage of Tor’s circuit selection algorithm. To this end, we first identify the most probable ASes to be traversed by Tor streams. We call this set of ASes the Suspect AS list and find that it consists of eight highest ranking Tier 1 ASes. Then, we test the accuracy of Qiu and Gao AS-level path inference on identifying the presence of these ASes in the path, and we show that inference accuracy is 90%. We develop an AS-aware algorithm called DeNASA that uses Qiu and Gao inference to avoid Suspect ASes. DeNASA reduces Tor stream vulnerability by 74%. We also show that DeNASA has performance similar to Tor. Due to the destination-naive property, time to first byte (TTFB) is close to Tor’s, and due to leveraging Tor’s bandwidth-weighted relay selection, time to last byte (TTLB) is also similar to Tor’s.
Armon Barton, Matthew Wright 0001
Proc. Priv. Enhancing Technol.1