Timothy Walsh 0002

dblp:69/3209 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0008-1143-699XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Improved Open-World Fingerprinting Increases Threat to Streaming Video Privacy but Realistic Scenarios Remain Difficult
abstract
Recent work on video stream fingerprinting has begun to explore its effectiveness in large open-world scenarios, in which the vast majority of test samples are from unmonitored videos that are unknown to the model at training time, showing that it is more difficult than earlier small open-world results have suggested. However, the evaluated approach employed deep learning techniques with potential shortcomings for the open-world task. We build on that work to evaluate more advanced techniques drawn from the literature on open set recognition, out-of-distribution detection, and robustness to adversarial examples, hypothesizing that they can improve effectiveness. We find that combinations of techniques can improve effectiveness, cutting the open-world false positive rate by up to 92% at a recall of 0.5. However, precision would likely still be problematic at the full-scale of the largest platforms hosting hundreds of millions or more videos. Additionally, we find that introducing two other dimensions of realism - when training and test sets are streamed from different vantage points, and when monitoring shorter videos or traffic flows - can greatly increase open-world false positives, making the full-scale open-world task even more difficult. Accordingly, we call for more work to focus on larger and more realistic open-world scenarios to continue to gain a better understanding of the effective envelope for fingerprinting.
Timothy Walsh 0002, Armon Barton, Mathias Kölsch
Proc. Priv. Enhancing Technol.1
2025 PredicTor: A Global, Machine Learning Approach to Tor Path Selection
abstract
Tor users derive anonymity in part from the size of the Tor user base, but Tor struggles to attract and support more users due to performance limitations. Previous works have proposed modifications to Tor’s path selection algorithm to enhance both performance and security, but many proposals have unintended consequences due to incorporating information related to client location. We instead propose selecting paths using a global view of the network, independent of client location, and we propose doing so with a machine learning classifier to predict the performance of a given path before building a circuit. We show through a variety of simulated and live experimental settings, across different time periods, that this approach can significantly improve performance compared to Tor’s default path selection algorithm and two previously proposed approaches. In addition to evaluating the security of our approach with traditional metrics, we propose a novel anonymity metric that captures information leakage resulting from location-aware path selection, and we show that our path selection approach leaks no more information than the default path selection algorithm.
Armon Barton, Timothy Walsh 0002, Mohsen Imani, Jiang Ming 0002, Matthew Wright 0001
ACM Trans. Priv. Secur.2
2025 Defending Against Deep Learning-Based Traffic Fingerprinting Attacks With Adversarial Examples
abstract
In an increasingly digital and interconnected world, online anonymity and privacy are paramount issues for Internet users. To address this, tools like The Onion Router (Tor) offer anonymous and private communication by routing traffic through multiple relays with multiple layers of encryption. However, traffic fingerprinting attacks have threatened anonymity and privacy. In response, the community has proposed additional defenses for Tor, but fingerprinting techniques that utilize deep neural networkss (DNNs) have undermined many of these defenses. The latest defenses that are both lightweight and robust against DNNs use adversarial examples, but these defenses require either the full traffic trace beforehand or a database of pre-computed adversarial examples. We propose Prism , a defense against fingerprinting attacks that utilizes adversarial examples with neither prior access to the full traffic trace nor a database. We describe a novel method of adversarial example generation as input is learned over time. Prism injects these adversarial examples into the Tor traffic stream to prevent DNNs from accurately classifying both websites and videos that a user is viewing, even if the DNN is hardened by adversarial training. We also show that the Tor network could implement Prism entirely on relays under certain conditions, extending the defense to users who may run Tor on devices without graphics processing units.
Blake Hayden, Timothy Walsh 0002, Armon Barton
ACM Trans. Priv. Secur.2
2019 Whisper: a unilateral defense against VoIP traffic re-identification attacks
abstract
Encrypted voice-over-IP (VoIP) communication often uses variable bit rate (VBR) codecs to achieve good audio quality while minimizing bandwidth costs. Prior work has shown that encrypted VBR-based VoIP streams are vulnerable to re-identification attacks in which an attacker can infer attributes (e.g., the language being spoken, the identities of the speakers, and key phrases) about the underlying audio by analyzing the distribution of packet sizes. Existing defenses require the participation of both the sender and receiver to secure their VoIP communications.
Tavish Vaidya, Timothy Walsh 0002, Micah Sherr
ACSAC2