AI surveillance is on the horizon, but Mullvad VPN might have a fix

Mullvad VPN working on a laptop

The original article was amended on May 13, 2024, to include clarifications from Harry Halpin, CEO at NymVPN.

The security gap between our expectations and the harsh digital reality is deepening as AI-powered tools enable internet service providers (ISPs), authorities, and even data brokers to trace back our online activities despite being encrypted. That's why one of the best VPN services on the market, Mullvad VPN, just dropped a new feature to prevent AI-powered snooping.

The provider says its Defense against AI-guided Traffic Analysis (DAITA) is "the first step" in the battle against sophisticated traffic analysis. Fully built on an open-source framework, DAITA's beta version is now available on Mullvad's Windows VPN apps on Windows 10 and 11.

Online surveillance meets AI

Whether you're using a secure VPN, the Tor Network, or any other privacy-focused web browser, encryption alone cannot shield you from increasingly invasive surveillance practices. That's because, every time you access a website, there is an invisible exchange of data packets occurring in the background between your device and the site you're visiting. 

When you use a VPN, this traffic gets encrypted meaning that a third party cannot record the information shared between you and your destination. However, your ISP can still see that some packets are being sent, how big these are, and how often this exchange occurs.

"Even if data is encrypted using a VPN and all packages of information leaving your computers are impossible to read, you will at a minimum level leak the fact that your computer is on, and you are communicating," Jan Jonsson, CEO at Mullvad VPN, told me. "An analysis of [what's known as] metadata can reveal a lot. especially if collected massively over the planet."

Vice already unveiled in 2023 how the FBI has been using a tool to access users' netflow data to fight crime. According to Jonsson, this type of surveillance is now on the rise due to AI tools that can empower your ISP or any other snooper, like a data broker or law enforcement officer, to trace these traffic patterns back to specific websites and users. Pattern recognition is indeed the core strength of AI. All of this, ultimately, makes also VPN users vulnerable to online surveillance.

"We don't need to speculate on the extent to which traffic analysis is being used today. We just observe the development of AI and the development of authoritarian societies. There is also no need to speculate on which role traffic analysis will play in future mass surveillance," said Jonsson. "What we must do is to recognize the threats and opportunities—and work on resistance."

How Mullvad DAITA fights back AI tracking

Mullvad partnered with the Computer Science department at Karlstad University to develop a proactive solution against AI-powered traffic analysis. That's when DAITA was born.

On a simple level, Mullvad's objective is to confuse observers by modifying the appearance of these data packets. As Jonsson put it, "to make analyzing the encrypted traffic and correlating with website traffic damn hard."

DAITA does so by, for instance, making all packets sent over the VPN the same constant size. It also adds some random traffic to make it harder for third parties to distinguish between meaningful activity and background noise. It then modifies the traffic pattern by unpredictably sending cover traffic in both directions between the client and the VPN server.

DAITA is built entirely using an open-source defense network called Maybenot, an academic work Mullvad partly funded. According to Tobias Pulls, a researcher at Karlstad University who took part in the project, putting traffic analysis defenses into practice is long overdue considering how "the area is changing due to the rapid development of AI."

While Mullvad's DAITA is a unique security feature across the VPN market, another provider recently developed an innovative solution for protecting its users against these sophisticated surveillance practices. 

NymVPN employs a tool called Mixnet to reroute data packets via five different VPN servers while shuffling these like a deck of cards along the way. This process, the provider says, ensures that the traffic data gets out completely randomized, scrambling the ability for authorities, hackers, and any other snoopers to identify who sends what packet.

What we must do is to recognize the threats and opportunities—and work on resistance

Jan Jonsson, CEO at Mullvad VPN

"I assume there are many ways of routing traffic between different relays to vary latency and make tracking harder. However, DAITA focuses on an attacker that can see ALL traffic on the net and use AI to analyze it all. Mixnet usually does not protect against this," Jonsson told me.

Harry Halpin, CEO at NymVPN, doesn't agree with Jonsson, though, arguing that mixnets are actually the only technology that can defend against an adversary that can see all the traffic on the network. 

"Of course, no technique is perfect, but mixing is in general more powerful than covering traffic," he told me, adding that besides DAITA's technique not being new, it's also a rather weak defense as "over time traffic analysis can de-anonymize the flows even with adaptive cover traffic."

On his side, Jonsson said that, despite other security software offering similar solutions, DAITA is the only open-source tool developed by university researchers specializing in this issue. To use DAITA, head to your app's Settings and click on VPN settings. You have to turn on the DAITA option under the WireGuard settings tab.

The initial version of DAITA is currently available only on Windows 10 and 11, with the plan to extend the functionality across all operating systems. Not in the Mullvad browser, though, as "it only protects browser traffic and would not be sufficient protection" Jonsson explains, adding that the team seeks to continue to refine and develop the feature according to feedback to ensure that privacy remains the priority.

He said: "We have funded this research for years, and there will be more research and more versions as we learn more. And also adapt to new threats."

Disclaimer

We test and review VPN services in the context of legal recreational uses. For example:

1. Accessing a service from another country (subject to the terms and conditions of that service).

2. Protecting your online security and strengthening your online privacy when abroad.

We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.

Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
VPN
7 VPN predictions to look out for in 2025
Mullvad VPN working on a laptop
VPN firm warns against encryption backdoor in new ad
Outlook Calendar on a Tablet
What we learned from VPNs in 2024
VPN server logo with foggy mountain in the middle
What is obfuscation? Everything you need to know about VPN obfuscation technology
Screenshot of Obscura VPN website
Obscura VPN promises to “set the standard for the next-generation of VPNs”
Abstract illustration of a young woman looking at a smartphone, as large eyes peek through from her hair
Want to hit restart on your online presence? Here's 5 tools you need to stay truly private online
Latest in VPN
AdGuard VPN during TechRadar tests
AdGuard becomes the latest VPN to add post-quantum encryption
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still a stellar option for streaming
NordVPN running on a desktop, mobile devices, Apple TV, a router and a game console
NordVPN reacts to results from its latest security audit
ExpressVPN's new Linux app interface
ExpressVPN releases a major upgrade to its Linux app
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still the best free VPN for streaming
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Google Gemini Calendar
Gemini is coming to Google Calendar, here’s how it will work and how to try it now
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
An image of a Jackbox Games Party Pack
Jackbox games is coming to smart TVs in mid-2025, and I can’t wait to be reunited with one of my favorite party video games