Related Experiment Video
Updated: Aug 14, 2026

Large Scale Energy Efficient Sensor Network Routing Using a Quantum Processor Unit
Published on: September 8, 2023
Game-Theoretic Obfuscation of Wi-Fi MAC-Layer Traffic Against IoT Device Fingerprinting Attacks
Abdulmajeed Alghamdi1,2, Mnassar Alyami3, Inad Alqurashi4
1Department of Computer and Network Engineering, College of Computing, Umm Al-Qura University, Makkah 24382, Saudi Arabia.
None:
Internet-of-Things (IoT) devices in smart homes are vulnerable to passive traffic fingerprinting, where an adversary captures encrypted IEEE 802.11 frames and identifies devices using MAC-layer metadata such as packet sizes and inter-arrival times. Existing defenses based on padding, traffic shaping, or synthetic cover traffic can remain vulnerable because artificial timing signatures are detectable by machine learning classifiers. This paper proposes a game-theoretic framework for evaluating Wi-Fi MAC-layer cover-traffic injection defenses. We introduce donor-based mimicry injection, in which the access point injects a replica of a paired device's authentic traffic into each device's stream. We compare donor mimicry with fixed-rate, exponential, and uniform synthetic baselines across 198 scenario instances (156 unique defender configurations) and eight classifiers using 10-fold cross-validation. Donor mimicry at 100% bandwidth overhead reduces the best attacker's balanced accuracy to 33.5%, whereas synthetic methods at equal overhead reach 93.9%, showing that behavioral realism, rather than injected volume alone, drives effectiveness. Modeling the interaction as a finite two-player zero-sum game yields a mixed-strategy Nash equilibrium with game value 0.247 within the evaluated strategy space; a deployable deterministic defense holds the best pairing-unaware attacker to 25.9% balanced accuracy, near the four-class random baseline of 25%. A pairing-aware robustness analysis shows that an attacker who can orient the donor-induced identity swap recovers near-baseline accuracy, so the four-class protection presumes pairing secrecy and the durable effect is pair-level anonymity. The defense operates at the access point and requires no IoT device modifications.