The SPRING lab offers project opportunities for BSc, MSc, and PhD students. We encourage interested students to have a look at the Thesis & Project Guidelines from the MLO lab, where you will gain an understanding about what can be expected of us and what we expect from students.
Last Update: 13th August 2026
Given the short time before the start of the semester, please contact the supervisor(s) of the project you are interested in. You can find their contact information in the project description.
If you encounter any technical issue, please get in touch with Saiid El Hajj Chehade.
Website fingerprinting attacks let a passive eavesdropper infer which page a user visits from encrypted traffic metadata. Yet nearly the whole literature evaluates traffic from browsing the home pages of websites. Real users complete tasks: they search, follow links, backtrack, and open tabs. The project will collect a session-level dataset over Tor and/or Nym and re-evaluate state-of-the-art attacks and defenses under this threat model.
Requirements
Applying to this semester project
This 12 ECTS research project is aimed at one Master student. The student will work with Eric Jollès.
[1] Jollès et al. “Website fingerprinting on Nym: Attacks and Defenses”. PoPETs 2026.[2] Mathews et al. “SoK: A Critical Evaluation of Efficient Website Fingerprinting Defenses”. IEEE S&P 2023.
We recently published an empirical study of website fingerprinting on the Nym mixnet [1].
The goal of this project is to reproduce the Nym WF study inside the emulated network Shadow [2] and determine which conclusions are properties of Nym and which are artifacts of the measurement environment. The student will build a Nym-in-Shadow harness from the artifacts of [1] and [3], model background traffic, topology and page loads (Shadow has no access to the real web), then re-run the attack under the default configuration and the parameter sweeps.
Requirements
Applying to this semester project
This 12 ECTS research project is aimed at one Master student. The student will work with Eric Jollès.
[1] Jollès et al. “Website fingerprinting on Nym: Attacks and Defenses”. PoPETs 2026(2). Artifacts: https://github.com/spring-epfl/WF4NYM-artifacts
[2] Jansen and Hopper. “Shadow: Running Tor in a Box”. NDSS 2012.[3] Schadt et al. “Breaking and (Partially) Fixing Onion Routing with Fragmentation”. PoPETs 2026.
When a user asks an LLM assistant a question, it may also propose visiting web links and provide a preview of them. The prompt therefore produces a second, downstream trace of network activity that the user never sees and does not control.
The research questions are: can a network observer infer something about these queries? Can we recover the initial user prompt from them? The student will build a corpus of questions, run them through one or more assistants under controlled conditions, and record the downstream activity.
Requirements
Applying to this semester project (PDM)
This 12 ECTS research project is aimed at one Master student. The student will work with Eric Jollès.
[1] Weiss et al. “What Was Your Prompt? A Remote Keylogging Attack on AI Assistants”. USENIX Security 2024.[2] Oh, Li, Hopper. “Fingerprinting Keywords in Search Queries over Tor”. PoPETs 2017.