Ethan Witwer

dblp:326/1283 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0006-8038-5693ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Ephemeral Network-Layer Fingerprinting Defenses
abstract
Fingerprinting attacks on encrypted network traffic may reveal sensitive information about users of anonymous communication systems, such as visited websites or watched videos, linking users' activities to their identities. Defenses come at the cost of bandwidth and delay overheads, impacting the user experience and making wide-scale deployment challenging. There is a rich history of attacks and defenses, with continual improvements in deep learning as a catalyst, making deployment of defenses an ever more pressing matter. This paper introduces a new defense strategy against fingerprinting attacks---ephemeral defenses---where efficient defense search enables the generation of unique per-connection defenses. We demonstrate that ephemeral defenses are multipurpose network-layer defenses against circuit, website, and video fingerprinting attacks, achieving competitive performance compared to related work. Furthermore, we create tunable ephemeral defenses that are not overly specialized to a particular fingerprinting attack, dataset, or network conditions. Ephemeral defenses are practical, demonstrated through integration with WireGuard and deployment at Mullvad VPN for a year, serving thousands of daily users.
Tobias Pulls, Topi Korhonen, Ethan Witwer, Niklas Carlsson
Proc. Priv. Enhancing Technol.3
2026 Dodge: A Client-Side Framework for Application-Layer Video Fingerprinting Defenses
abstract
As reliance on online video continues to increase throughout all facets of society, it is critical to address the security and privacy threat of video fingerprinting, in which a local, passive adversary monitors a victim’s encrypted connection to a video server to infer which videos they are watching. These attacks attain high accuracy in realistic scenarios, while defenses that offer an acceptable trade-off between protection, overhead, and user experience are lacking. In this paper, we motivate application-layer defenses against video fingerprinting and present Dodge, a client-side framework for application-layer video fingerprinting defenses, implemented as a fork of the dash.js video player. Dodge provides the infrastructure and building blocks for defenses as well as a plug-and-play interface, making defense development and use straightforward while still providing maximal control over video flows. As a proof of concept, we use Dodge to implement a mimicry defense and show through live deployments that Dodge and the defense operate seamlessly, with modest overhead and very low user experience impact, while reducing attacker success close to theoretical bounds. Dodge can easily be deployed at scale and in a number of scenarios, with no changes to servers or network components; our analyses also lead to a host of insights that we hope will aid in deployment efforts.
Ethan Witwer, David Hasselquist, Tobias Pulls, Niklas Carlsson
Proc. Priv. Enhancing Technol.1
2025 Predicting Video QoE from Encrypted Traffic: Leveraging Video Fingerprinting and Providing System-Level Insights
Somiya Kapoor, Ethan Witwer, David Hasselquist, Mikael Asplund, Niklas Carlsson
Networking2
2024 Raising the Bar: Improved Fingerprinting Attacks and Defenses for Video Streaming Traffic
abstract
Despite the clear dominance of video streaming traffic on the Internet and the significant ramifications of disclosure of which videos users are streaming, video fingerprinting has received relatively little attention compared to other traffic analysis domains. Existing attacks are tailored to undefended traffic and mostly rely on a few manually crafted features. Meanwhile, potential defenses are ad hoc, often impractical, and typically only mentioned briefly. Drawing from progress made on website fingerprinting, we aim to improve current standards for attacks and defenses for video streaming traffic while highlighting a critical and underexplored issue on today's Internet. We show that directional and timing-based attacks that leverage CNNs are competitive with state-of-the-art video fingerprinting attacks, in many cases with far less training data. We also provide the first extensive study of potential defenses, which considers performance against attacks, overheads, and user QoE; and we present a novel defense design that boasts both broader applicability and greater efficacy than existing proposals.
David Hasselquist, Ethan Witwer, August Carlson, Niklas Johansson, Niklas Carlsson
Proc. Priv. Enhancing Technol.2