Why MAC Randomization and Encrypted DNS Fall Short
MAC randomization and encrypted DNS are the two technical controls designed to stop device tracking. MAC rotation does create a time limit. iOS Wi-Fi defaults rotate every 14 days, but many devices reuse the same MAC while connected to the same network, and 14 days is enough time to accumulate DNS traces. Encrypted DNS closes the local snooping gap but hands your queries to a resolver that can play exactly the same curious role a local attacker would. The problem shifts, not disappears.
Building the Dataset: 985 Million DNS Events
Bitdefender tapped its own DNS resolvers, hashed device identifiers so no MAC address could be traced back, and registered to events from approximately 30,000 devices. Over 35 days the collection produced 985 million DNS events, processed on four computational clusters totaling 480 virtual CPUs and 1.5 TB of RAM. iOS devices dominated US traffic; Android spread across fewer countries, with France and the US leading. Both platforms showed devices generating repetitive request sequences, visible, as the researchers noted, to the naked eye.
Treating DNS Traces as Documents: TF-IDF and Cosine Similarity
Standard categorical encoding approaches (one-hot, label encoding, feature hashing) all broke down at the scale of millions of DNS requests across 30,000 devices. The team reframed DNS traces as NLP documents: each domain name is a word, each device’s request history is a corpus. TF-IDF scores domains by how often they appear per device versus how common they are across all devices. Cosine similarity then compares two traces by direction rather than magnitude, so a device that makes the same requests three times looks identical to one that makes them once.
Tracking Accuracy: 96% in Under Two Hours
The tracking index is self-similarity minus maximum cross-device similarity. Any positive result means the device stands out from the pool. In the similarity matrix visualization (16:19), self-similarity runs 10 times higher than comparisons to other devices. The tracking accuracy chart at 2 hours (19:29) shows accuracy crossing 80% for 250-device pools at the two-hour mark.
“topped out at 96% which is excellent.” — Bela Genge
Scale up to 1,000 devices and accuracy drops, but 24 hours of aggregated traces still pushes it back above 90%.
LSTM Results, Cost Floor, and What Comes Next
LSTM was the machine learning candidate. First trials reached 78% accuracy for 100 devices per OS. After tuning to one layer with 188 cells, the best result matched the statistical method at 96%.
“One LSTM layer with 188 cells will do the job.” — Yan Pedrian
Training 48 models across 2,500 devices consumed 280 GB of RAM on iOS, 190 GB on Android, and 9 days of compute. On commodity cloud that translates to roughly $3,000 per month. Dropping 20% of DNS requests had no measurable accuracy cost. Dropping 80% still left devices detectable.
Notable Quotes
topped out at 96% which is excellent. Bela Genge · ▶ 19:37
One LSTM layer with 188 cells will do the job. Yan Pedrian · ▶ 22:05
around $3,000 a month. Bela Genge · ▶ 23:17
Key Takeaways
- DNS traces from 30,000 devices identified individual smartphones at 96% accuracy using cosine similarity on TF-IDF vectors.
- MAC randomization provides only a 14-day window; 2 hours of DNS data is enough to reach 80% tracking accuracy.
- Replicating this attack costs roughly $3,000 per month on commodity cloud, within reach of well-funded adversaries.