Game-Theoretic Obfuscation of Wi-Fi MAC-Layer Traffic Against IoT Device Fingerprinting Attacks
Round 1
Reviewer 1 Report
Comments and Suggestions for AuthorsI have the following comments for improvements:
- The manuscript is longer than necessary for the presented contribution. At approximately 45 pages, many sections contain redundant explanations, repeated justifications.
- The manuscript repeatedly emphasizes Nash equilibrium guarantees and optimal defender strategies. However, these guarantees hold only within the finite set of evaluated classifiers and obfuscation configurations.
- The paper acknowledges that the primary cost of the defense is bandwidth overhead, particularly for donor-based injection which operates at approximately 100% overhead. However, the impact of this additional traffic on network performance is not investegated.
- The experimental evaluation is conducted using only four IoT devices within a single residential Wi-Fi environment.
Author Response
Please see the attachment.
Author Response File:
Author Response.pdf
Reviewer 2 Report
Comments and Suggestions for AuthorsThe paper presents an interesting and original idea for defending against IoT device fingerprinting by using donor-based mimicry rather than purely synthetic cover traffic. The key insight that realistic traffic patterns from paired IoT devices can provide stronger obfuscation than artificial dummy traffic is valuable and worth further investigation.
However, I have two major concerns that should be addressed before publication.
First, although the paper evaluates several machine-learning classifiers, the attacker model is still limited because it mainly considers pairing-unaware classifiers. The proposed donor mimicry method appears to create confusion between paired devices. Therefore, a pairing-aware attacker who knows or can infer the donor relationship may be able to reverse or reduce this confusion. The paper should evaluate such an adaptive attacker model or, at minimum, discuss more clearly how robust the proposed defense is when the device pairing is known.
Second, the proposed method depends heavily on the availability of behaviorally similar donor pairs. In realistic smart-home environments, some IoT devices may not have a suitable paired device with similar traffic characteristics. The paper should explain how the defense would operate for devices that cannot be paired effectively, or provide a strategy for donor selection when no natural pair exists.
Overall, the paper has a creative and promising core idea, but the current evaluation does not fully demonstrate robustness against pairing-aware attackers or scalability to devices without suitable donor pairs. I recommend substantial revision to address these issues.
Author Response
Please see the attachment.
Author Response File:
Author Response.pdf
Round 2
Reviewer 1 Report
Comments and Suggestions for Authorsthe authors addressed my concerns.
