NSDI 26 - Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation @UsenixOrg
NSDI 26 - Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation  @UsenixOrg
Uploaded June 2026 | Updated September 2026, 3 weeks ago
Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation

Guorui Xie and Qing Li, Pengcheng Laboratory; Zhenning Shi, Tsinghua Shenzhen International Graduate School; Gianni Antichi, Politecnico di Milano; Yijia Zhu, Xidian University; Kejun Li and Changxing Weng, Pengcheng Laboratory; Sebastiano Miano, Politecnico di Milano; Yong Jiang, Tsinghua Shenzhen International Graduate School and Pengcheng Laboratory; Mingwei Xu, Tsinghua University

Traffic analysis attacks can exploit side channels in encrypted traffic (e.g., packet sizes) to infer user activities. Existing defenses provide weak protection, impose excessive bandwidth overhead, or require hard-to-deploy coordination. We present Securitas, a novel network traffic obfuscation framework that protects from side-channel attacks using a learning-guided mix of packet fragmentation and insertion. We implemented Securitas on a number of different data planes: Tofino switch, AMD/Xilinx FPGA, eBPF, and BMv2. Experiments show that Securitas reduces attack accuracy by up to 95.89%, while consuming 42.69× less bandwidth than prior defenses. Real-world Internet tests confirm minimal performance impact, e.g., adding 0.15s to the web page load.

View the full NSDI '26 program at usenix.org/conference/nsdi26/technical-sessions
NSDI 26 - Defending against Traffic Analysis Attacks with Flexible In-Network ObfuscationUSENIX Security 24 - HYPERPILL: Fuzzing for Hypervisor-bugs by Leveraging the Hardware...NSDI 26 - QCON: Seamless QoE-Aware 5G Streaming via Multi-ConnectivityPEPR 26 - Architecting Scalable Data Lineage Graph for Privacy Compliance and Agentic AnalysisFAST 26 - RosenBridge: A Framework for Enabling Express I/O Paths Across the Virtualization...NSDI 26 - PD3: Prefetching Data with DPUs for Disaggregated MemoryNSDI 26 - SPLIDT: Partitioned Decision Trees for Scalable Stateful Inference at Line RateNSDI 26 - A Composable Emulation Framework for Whitebox SwitchesNSDI 26 - MORP4: A Dynamic Network TelescopeFAST 26 - DRBoost: Boosting Degraded Read Performance in MSR-Coded Storage ClustersPEPR 26 - Responding to Regulations Confidently and EfficientlyNSDI 26 - FlexLLM: Token-Level Co-Serving of LLM Inference and Finetuning with SLO Guarantees
USENIX |

NSDI '26 - Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER