Flow correlation attacks threaten Tor’s anonymity by linking both ends of a communication circuit. Yet, existing correlation models rely on artificial datasets, resulting in significant performance degradation when evaluated against the sparse and highly variable nature of live Tor traffic. In this paper, we challenge this unrealistic evaluation by introducing two new datasets: Correlated GTT23, constructed from genuine exit traces, and Correlated CellFlow, comprising ground-truth flow pairs that we directly collected from the live Tor network. To tackle the unique challenges of these datasets, we propose ESPRESSO, a robust flow correlation attack tailored for realistic Tor traffic. ESPRESSO utilizes a density-based window representation via Kernel Density Estimation (KDE) to dynamically adapt to differences in transmission volume across a trace. Our results show that ESPRESSO outperforms state-of-the-art Tor flow correlation attacks, significantly improving detection accuracy across various scenarios, including standard settings and traffic drifted by temporal and network environment shifts. Notably, ESPRESSO achieves an impressive 88% True Positive Rate (TPR) at a False Positive Rate (FPR) of 10^−5, whereas DeepCoFFEA, the state-of-the-art attack, degrades to a near-zero TPR for the same FPR. This robustness holds even under adversarial constraints, including partial trace observations (as few as 500 cells) and limited visibility over the network under large numbers of concurrent connections (base rates as low as 10^−4). These findings indicate that flow correlation remains a severe, imminent threat, establishing both our datasets and ESPRESSO as the new standard benchmarks for evaluating future flow correlation attacks and defenses.
@inproceedings{espresso-ccs2026,
title = {Brewing Under Pressure: More Realistic Tor Flow Correlation Considering Low FPRs},
author = {Jeon, Haeseung and Cho, Yeonseo and Mathews, Nate and Jansen, Rob and Juarez, Marc and Oh, Se Eun},
booktitle = {Conference on Computer and Communication Security},
year = {2026},
doi = {10.1145/3830454.3846708},
}