Understanding the “Airport” Censorship Circumvention Ecosystem in China Rumaisa Habib∗§ , Mingshi Wu∗† , Shiva Shahandeh† , Min Ni† , Eric Wustrow‡ , Zakir Durumeric§
arXiv:2606.18427v1 [cs.CR] 16 Jun 2026
§ Stanford University
† GFW Report
Abstract—In China, a burgeoning underground market sells citizens subscription-based censorship circumvention proxies known as “airports.” We present the first systematic study of this ecosystem, combining user surveys, social media analysis, and active network measurements. We find that airports are by far the most popular off-the-shelf censorship circumvention tool in China, used by over half of our 1,667 survey respondents, who cite their ease of use, performance, and access to geo-restricted services like ChatGPT and Netflix. By scanning the Internet and scraping Telegram announcement channels, we identify 3,431 active airports built on a handful of opensource toolkits. We subscribe to 35 airports and characterize their performance, which often surpasses direct connections through the Great Firewall due to a distinctive multi-hop architecture. However, airports also pose new challenges and security risks: they accept payment through commercial services like Alipay, suffer frequent government takedowns, and are difficult for clients to configure optimally. Many airports also deploy their own distinct censorship policies. Airports are far more widely used than other circumvention tools from the academic literature, but introduce new forms of fragility and control, offering both lessons and opportunities for future circumvention research.
1. Introduction In China, an underground market sells netizens access to commercial network proxies—known as “airports” (机 场, jı̄chǎng)—for bypassing the Great Firewall (GFW). The name likely stems from Shadowsocks, a widely used proxy protocol with a paper-airplane logo [1]: operating a fleet of proxy servers resembles running an airport. The term “airport” also serves as a code word on platforms like WeChat where terms like “proxy” and “VPN” are often filtered. Vendors advertise their airports via well-known announcement channels (e.g., on Telegram), sell metered proxy “subscriptions” through self-service web portals that accept Alipay and WeChat Pay, provide plug-and-play configuration for popular proxy clients like ClashX [2] and Shadowrocket [3], and compete on price, speed, and access to popular georestricted platforms like ChatGPT and Netflix. In this work, we present the first comprehensive study of the airport ecosystem. Despite their popularity, airports ∗ Authors contributed equally.
‡ University of Colorado Boulder
remain largely absent from the academic literature. This is a missed opportunity: airports emerged organically to meet user needs, evolved within a competitive environment, and can inform future system design. Conversely, the research community can help make one of the most widely used circumvention tools more resilient and safe for users. We start by anonymously surveying 1,667 users in China who regularly bypass Internet censorship (§4). Despite many alternatives, we find that airports are the most popular offthe-shelf approach for accessing censored content: 55% of respondents use airports with many citing their balanced ease-of-use for accessing blocked sites, speed, stability, and cost. Through Internet scans for web-based subscription portals and manual analysis of public Telegram channels, we identify 3,431 active airports (§5). We subscribe to 35 airports and characterize their architecture, performance, and service access. Airports are inexpensive (users report spending a median $2.80/month) and are typically offered through tiered, byte-metered plans (§5.2). Despite their low cost, airport proxies provide sufficient bandwidth for streaming video during peak hours, and, in our experiments, often outperformed direct connections to uncensored sites (§6). Airports achieve this impressive performance through a distinctive architecture that decouples ingress and egress endpoints (§6.1) with ingress nodes inside China and egress nodes outside the Great Firewall, reportedly connected by leased International Ethernet Private Lines (IEPLs) [4]– [16]. This approach bypasses GFW-induced congestion [17] and enables destination-based routing to geo-restricted sites. Many airports offer tiered egress nodes priced by access to high-demand services. While convenient, this architecture also introduces new risks: users provide PII to unknown operators, utilize government-monitored payment channels, and trust orchestration software with a history of vulnerabilities (§8.1). In addition, many operators impose their own censorship policies. We measured access to a subset of the Citizen Lab CN test websites [18] and find that over half of the tested domains (198 out of 368) were blocked by at least one airport (§7.2). For instance, 12 out of the 15 airports we tested blocked access to Falun Gong sites, and nine blocked access to overseas news outlets. Our results suggest that airports are now the foremost off-the-shelf method for bypassing the Great Firewall of China to access censored content due to their ease of use, performance, stability, and low cost. This success is driven by an architecture distinct from previously proposed solu-
tions from the research community. Despite their popularity, airports introduce new privacy and security risks and shift censorship control to opaque commercial operators. We hope our analysis enables the next generation of censorship circumvention systems that both better meet the needs of users and protect their security and privacy.
2. Related Work The Great Firewall of China (GFW) is a state-operated Internet censorship and surveillance system. It blocks access to restricted websites through IP blocking [19], TLS SNI filtering [20]–[22], DNS injection [23]–[25], and HTTP inspection [26], [27], and it detects circumvention through passive traffic analysis [28] and active probing [29]. A substantial body of work has analyzed the GFW [21], [30]–[34]. In response, many tools have been designed to evade censorship in China [35]–[46] using proxies [35], [38], [47]–[49], domain fronting [46], or obfuscation [43], [45], [50]. Several free tools operated by volunteers outside China, including Tor [35] and Snowflake [38], enable users to bypass the GFW. Airports stand in contrast to these services: they are underground commercial operations run from within China, with infrastructure both inside and outside the country. Prior work has qualitatively examined censorship circumvention [51]–[53] and user perceptions [51], [54]– [57]. Xue et al. [58] interviewed circumvention users and providers in China and Russia, documenting the operation and challenges of commercial VPN and government-backed circumvention services, and in subsequent work interviewed users and providers to characterize their needs [53]. Our work extends this line of research by examining why users prefer airports and analyzing the architectural and operational practices that let these services meet user demand. Feng et al. [52] studied censorship circumvention in China in the context of online gaming. A separate line of work has audited commercial VPN providers and consumer VPN apps [59]–[62]; we treat airports as a Chinese variant of this commercial-proxy measurement problem, one with distinct architectural and trust-model implications. Little prior work investigates commercial censorship-evasion tools, particularly the Chinese airport ecosystem, which faces a unique threat model and operational challenges. The closest is Chua et al. [63], who characterize the social dynamics of how users select airports on Telegram and how the community polices scammers. Their work is complementary: they study the community vetting of airports, while we analyze their popularity, architecture, performance, and self-censorship.
3. Airport Ecosystem Overview In this section, we provide an overview of the airport ecosystem, informed by our investigation, online forum posts, and informal background conversations with users, operators, and other researchers. Airports are commercial proxy services for bypassing the Great Firewall in China.
Figure 1. Airport Walkthrough—Users start by finding an airport through a third-party platform and creating an account (1–3), purchasing a subscription (4–5), and receiving a ‘subscription link’ (6). The user then provides this link to a proxy client (7), which uses it to download and present the user with a selection of proxy nodes outside China to choose from. Through this software, the user connects to an ingress node in China (8), which connects to an egress node outside of China (9) to access the Internet (10).
In this decentralized ecosystem, several hundred individual operators within China run proxies and sell metered “subscriptions” through online portals; these subscriptions can then be imported into client applications and used to access the Internet freely. We summarize the process in Figure 1 and detail each step below: Airport Discovery. Because airports are run by independent operators, users must first locate and choose an airport from which to buy service. Within China, users typically find airports through: (1) keyword searches via domestic search engines (e.g., Baidu) or—using a traditional VPN—on Google; (2) direct recommendations from peers; or (3) access to foreign platforms like Telegram. For users who have already partially bypassed the GFW, Telegram serves as a central hub where operators pay well-known public channel administrators to promote their airports. Portal Registration. Airports provide web portals, largely built from common open source templates, where users can learn about an airport’s services and purchase a subscription plan. In most cases, users first register an account with a phone number or email, after which they can view service options such as usage limits, service duration, proxy node information, websites they enable access to, and cost. We show example plans from an airport in Figure 2. Subscription Purchase. Users pay for access by purchasing subscription plans that typically cost a few dollars per month, similar to mobile data plans. Airports most commonly accept Alipay or WeChat Pay, though some support cryptocurrencies, PayPal, and credit cards. To evade detection, operators often work with money-laundering services to disguise revenue. For example, one payment page advertises itself as 烟酒商行 (“Liquor & Tobacco Store”). Subscription Links. After payment, the portal provides users with subscription links that are compatible with client proxy software: each is a URL pointing to a Base64-encoded
Figure 2. Example Airport Subscription Plans—Airport portals present subscription tiers with usage quotas, durations, prices, and advertised service capabilities. In this example, the operator lists overseas dedicated lines and access to services commonly blocked in China, including Netflix and ChatGPT.
renewal process is designed to be seamless, often involving one-click payment and automated link regeneration.
4. Why Users Choose Airports
Figure 3. ClashX Proxy Selection UI—Clients let users choose proxy nodes. Nodes with lower RTTs are green, indicating better performance.
To understand the popularity of airports and why users select them, we surveyed over 1,600 Chinese Internet users who regularly employ censorship circumvention tools. We asked which tools they use, how they choose them, how much they pay, and what challenges they face. We find that airports are the most popular off-the-shelf mechanism for bypassing the GFW, used by 55% of respondents. Users report choosing airports over other off-the-shelf tools for their greater stability and speed, and over self-hosting for their lower cost and reduced operational complexity.
4.1. Survey Methodology JSON object that contains the configuration to connect to the airport’s proxy nodes. These links can be imported into widely used proxy clients such as Clash [64], ClashX [2], Shadowrocket [3], sing-box [65], and Surge [66]). Proxy Selection. At launch, the user’s chosen client fetches the subscription link, parses the encoded configuration, and assembles a list of available proxy nodes, which it presents to the user (Figure 3). Most airports provide several dozen nodes. Clients also display proxy metadata such as protocol, egress location, round-trip latency (via simple built-in benchmarks), and suggested usage (e.g., streamingoptimized or low-latency for gaming). Users can manually select a node or allow the client to auto-select based on latency measurements. Several clients support complex routing rules and multi-node aggregation, enabling higher throughput by combining bandwidth from multiple proxies. Monitoring and Renewal. Throughout the life of a subscription, the airport tracks the user’s data consumption and updates the subscription link (configuration file) accordingly; the client software periodically fetches it to display key metrics, including remaining bandwidth, latency, and subscription expiration. When a subscription nears expiration or its quota is exhausted, the user can return to the airport portal to purchase additional bandwidth or renew. This
We surveyed users in China by having a trusted organization within the censorship circumvention community (anonymized for submission) post a Qualtrics-based survey that we developed. Our survey seeks to understand: 1) How users in China bypass the GFW in practice; 2) How users select their circumvention tool; 3) How much users pay for circumvention services; 4) What challenges users face with existing solutions. In this section, we focus on questions (1)–(3) to understand airports’ role and compare them to other circumvention methods. We defer question (4) to §8.1. Our study was approved by the Institutional Review Board (IRB) of the institution that conducted the survey and analyzed the collected data. We detail our ethical considerations in Appendix A. Below, we describe our survey instrument and recruitment. Consent. Before beginning the survey, participants were required to acknowledge a consent form (Appendix D) that outlined the study’s purpose, our safety precautions, an overview of the research team, and contact information for both the team and the overseeing IRB. In particular, participants were informed that the study concerned censorship in China. We did not offer compensation, given the survey’s
brevity (estimated five minutes to complete) and to avoid increasing risk for respondents. Survey Instrument. Our survey (Appendix D) includes six multiple-choice questions and one open-ended question on circumvention tool usage and preferences, as well as associated costs and challenges. We did not collect personally identifying information, and participants could skip any question or select Refuse to answer. For multiple-choice items, participants could select multiple answers and provide a free-form response. Participants could take the survey in Simplified Chinese (default) or in English. The survey was hosted on Qualtrics using a university-specific subdomain of qualtrics.com. A bilingual author translated free-form responses from Chinese into English and the team analyzed the responses; we did not perform back-translation or compute inter-coder reliability for the free-form coding, which we acknowledge as a limitation of the analysis. Recruitment. Because a survey about how users bypass government controls would likely be distrusted if posted by an unknown team, we worked with a reputable party within the Chinese censorship circumvention community to post the survey on Twitter/X, Telegram, and the GitHub-based Net4People BBS in October 2024 [67]. Recruitment posts were written in both Simplified Chinese and English, with corresponding links to the survey in each language. Survey Responses. Our survey ran for three months, from October 4, 2024 to January 10, 2025, yielding 1,667 valid responses out of 2,365 entries. We consider a response valid only if the participant provided explicit consent and reached 100% completion before January 10, 2025. Of these, 1,612 (96.7%) completed the survey in Simplified Chinese and 55 (3.3%) in English. Most respondents reached the survey through links initially posted on Net4People (47.3%) or the official Twitter/X account (41.2%), and a smaller fraction through the official Telegram channel (6.5%). These figures reflect the tagged entry links rather than the actual acquisition channels, as links were redistributed across platforms (e.g., Net4People links were later reshared in several Telegram channels). Limitations and Potential Sources of Bias. Studying censorship circumvention in China is difficult given the topic’s sensitivity. Our survey has three main limitations. First, our recruitment introduces selection bias: because participation required encountering the survey through circumvention-community channels, respondents are likely more technically sophisticated, motivated, and engaged than the average circumventor in China. Our findings thus describe active circumvention users in these communities and do not necessarily generalize to the broader population. However, we do not expect any bias toward airport usage. Second, responses are self-reported and may suffer from recall errors and social desirability or risk-related reporting bias, particularly as respondents may regard circumvention as sensitive; because we cannot independently verify each participant’s location or circumstances, we focus on aggregate trends rather than claims requiring identity verification.
Third, our data is a snapshot from October 2024 to January 2025: individual airports churn frequently, so prevalence figures may have shifted by publication. The structural features we rely on—subscription-based commercial proxies, v2board/sspanel template dominance, and byte-metered pricing—have been documented across the ecosystem for several years and should remain stable over this window. Despite these limitations, our survey offers insight into a hard-to-study population: users who actively circumvent censorship and make recurring choices among off-the-shelf services, self-hosting, and free tools.
4.2. Adoption, Choice Factors, and Spending In this section, we present the popularity of airports and why users choose them over other circumvention tools. Tool Adoption. As shown in Figure 4a, respondents prefer airports over other off-the-shelf solutions: 55% of respondents use airports and 55% use their own self-hosted proxy setup to bypass the GFW, followed by a long tail of other circumvention methods like Cloudflare Warp (15.5%). Selection Priorities. As shown in Figure 4b, respondents choose tools based on stability (64%), speed (41%), and cost (37%). Self-hosting users share these priorities but emphasize stability more (71%). Airport users differ slightly: stability (61%) remains the top concern, but cost (48%) outranks speed (35%). Respondents who use neither airports nor self-hosting prioritize stability (43%), ease of setup (33%), and cost (28%). At a high level, users gravitate toward airports because they balance cost, speed, and stability. Self-hosted setups are faster and more stable but harder to operate (z = 2.6, p = 0.004)1 and more expensive to maintain (z = 6.4, p ≪ 0.05). Relative to other third-party tools, airports are more stable (z = 6.8, p ≪ 0.05), faster (z = 8.1, p ≪ 0.05), and less expensive (z = 5.3, p ≪ 0.05). Costs. Respondents pay $0–8,119/month2 (median $4.30) for their preferred tool (Figure 4c). The wide range stems from a few outliers who run large-scale operations: we inspected all participants who paid over $1,000/month and found that they all self-host, including one who pays several thousand dollars per month to lease a direct fiber link from China to Hong Kong. Respondents who use only airports report paying $0–34/month (median $2.80); some airports offer free plans, explaining the reported $0 costs. By contrast, self-hosting respondents spend a median of $4.60/month. This difference is consistent with cost being the second most common reason for choosing airports. 1. Reported z-scores come from two-proportion z-tests, equivalent to a mean z-test on data encoded as 1 when an answer occurs and 0 otherwise. 2. Participants reported spending in Chinese Yuan (CNY), which we convert to USD at the October 3, 2024 exchange rate (1 USD = 7.02 CNY).
55.0%55.0%
1.0
40%
(a) Circumvention Method Popularity
20%
0.6 0.4
All (n=1422) Airports (n=262) Self setup (n=301)
0.2 Se t ail up ab i Us lity ab ilit Sa y fet y Ot he r No An sw er
0%
sy
0.7% 2.5%
0.8
0.0
0
5
10 15 20 Price ($/month)
Av
7.3% 2.7% 2.5% 1.9%
Airports Self Setup Warp 1.1.1.1 Commercial VPN Tor Geph Friends/ Family Lantern Freegate/ UltraSurf Psiphon Other Don't Know No Answer
0%
8.0%
Ea
11.1% 9.6%
bil it Sp y eed Co st
15.5%15.4%
Sta
20%
60%
CDF
40%
All (n=1667) Airport (n=284) Self setup (n=360) Other (n=258)
(b) Selection Motivation By Method
25
30
(c) Circumvention Cost
Figure 4. Circumvention Preferences—We anonymously surveyed 1,667 users in China to understand how they bypass the GFW. In (b) and (c), we only include respondents who chose a single method. Although safety was not a predefined survey option, 62 participants (3.7%) mention it in free-form responses. Overall, stability is the most common selection factor, while airport-only users place more emphasis on cost than users of self-hosted setups.
Takeaway Airports are the most popular off-the-shelf circumvention option because they strike a unique balance of cost, usability, and stability. While stability is important across all circumvention tools, airport users emphasize cost more than other users; airport-only users report spending a median $2.80/month.
5. Airport Availability and Cost We next investigate airport deployment and behavior, describing how we identify airports, the software powering them, and their high-level architecture.
5.1. Discovering Airports We begin by analyzing public announcement channels on Telegram, which 53% of our survey respondents reported using to find airports. In September 2024, we searched Telegram for the keyword “机场” (“airport”) and manually inspected the highest-ranked channels, identifying seven devoted to airport advertisements with over 5,000 members each (Table 1). Manual analysis of hundreds of airports advertised in these channels surfaced two primary software platforms powering their sign-up portals: v2board and sspanel; informal conversations with members of the censorship circumvention community identified three additional platforms (Table 2). We built fingerprints for each platform from its web resources (e.g., v2Board stores web resources in /theme/v2board/assets/, which we can identify). To find less widely announced airports, we scanned domains from 1,008 CZDS [68] zonefiles, which provide coverage over 84% of the domains and 63% of the TLDs seen in Telegram advertisements. We used ZGrab [69] to make HTTP GET requests against domains on TCP/80 for fingerprinted resources from an academic institution in November 2024. We followed the best practices set by Durumeric et al. [70], [71] when conducting scans. To ensure that we considered only active, working airports, we additionally instrumented Chromium using Playwright and
TABLE 1. P UBLIC A IRPORT P ROMOTION T ELEGRAM C HANNELS —We extract public airport announcements from seven popular airport promotion Telegram channels as of September 20, 2024.
Channel ID
Established Date
Members
Ads
@askahh @freemason6 @jichangtj @cheap_proxy @jichang_list @jctest6666 @wxgqlfx
Dec. 2, 2019 Apr. 22, 2020 May 1, 2020 May 19, 2020 Feb. 24, 2022 Oct. 5, 2022 Nov. 2, 2022
16,670 35,126 82,467 32,210 36,503 7,611 23,935
1,501 618 263 5,379 3,468 497 882
TABLE 2. P OPULAR P ORTAL T EMPLATES —Airport portals typically use one of a handful of open source frameworks: v2board and sspanel account 95% of the airports we find. The last column is not a summation because of overlap in identified airports across methods.
Template
Telegram
Internet Scan
Total
v2board sspanel default vendor xboard aurora bob sspaneldjango zeropanel Other
424 191 38 11 8 7 0 0 0 79
1,896 974 0 0 0 0 6 5 2 –
2,175 1,100 38 11 8 7 6 5 2 79
Total
758
2,883
3,431
filtered out URLs that did not return a successful HTTP 200 status code. We then manually investigated responsive websites and filtered out parked domains.
5.2. Airport Subscription Portals We identified 3,431 publicly accessible airport portals: 758 from Telegram and 2,883 through scans of known domains. This is not an estimate of the full ecosystem size, but a conservative floor for the number of active airports.
Hosting. About a third (27%) of airport portals geolocate to the United States per IPinfo [72] largely due to the popularity of Cloudflare (82% of U.S. airports). The next most popular location is Hong Kong (3%), followed by a long tail of other countries. The top three providers in Hong Kong are Alibaba (28%), DMIT (15%), and Tencent (9%). Limitations. We cannot easily determine whether an individual airport is accessible at multiple domains or if an operator runs multiple airports because of common open source templates. However, we acknowledge that operators are motivated to operate an airport using multiple domains because of potential blocking. Informal background conversations with community members suggest that there are several hundred individual operators in China.
5.3. Byte-Metered Pricing Model Unlike traditional VPNs, which typically charge a flat fee [73]–[75], airports adopt a byte-metered subscription model (e.g., 10 TB per month) similar to mobile data plans. In addition, some airports charge extra for bandwidth that transits specific proxy nodes (e.g., nodes that have access to premium services like ChatGPT). To characterize costs, we manually collected pricing information from 100 randomly sampled airports. As shown in Figure 5, users pay a median $16/TB, with substantial variation: plans range from $0.17/TB to $571/TB. Airports with longer subscription periods tend to be less expensive. Many airports also offer “one-time” tiers that provide a fixed data quota with no expiration; these are often the most expensive, costing a median $29/TB. By contrast, longer-term subscription plans typically impose monthly caps despite charging for the full term: the median annual plan costs $13/TB versus $16/TB for a monthly plan. Monthly plans are the most common subscription duration, offered by 95% of airports; the median monthly plan provides 500 GB for $4.27, and the 25th-percentile plan costs $2.56 for 150 GB. These figures are consistent with our survey, where the median respondent reported spending $2.80/month (§4.2), suggesting that most users select less expensive monthly plans. To validate our measurements, we additionally examined eight popular airports recommended by members of the circumvention community in China. Prices vary widely even within this subset: the most cost-efficient plans range from $0.97/TB to $26.80/TB (Table 7). For context, a fixed 5 GB monthly broadband plan in China costs 0.42% ($4.28) of
103
10 $/TB
5 $/TB
26 $/TB GB
GB
Software. As shown in Table 2, 95% (3,275) of airport portals are powered by v2board and sspanel; the remainder use a variety of other packages, including v2board variants such as xboard. Both projects are widely used open-source platforms, with 4.7K and 9.6K stars on their respective GitHub repositories as of April 2025. This standardization helps the ecosystem scale but also creates correlated risk: bugs, leaks, or misconfigurations in these open source projects can propagate across independent airports.
103
Type
13 $/TB
101
101 100
102 Price (USD)
(a) All Plans
10 1
101 Price (USD)
3 days 1 month 3 months 6 months 1 year 2 years 3 years 5 years one-time
103
(b) Least Expensive Plans
Figure 5. Advertised Subscription Prices—Panel (a) shows price and data quota across all plans. Panel (b) shows the least expensive $/TB plan per airport. Price and data quota are shown on log scales. Red lines indicate the 25th and 75th percentiles. Data quota is the total traffic available over the full duration of the plan. Data cost varies significantly across airports and tiers, and longer plans tend to be more cost-efficient.
gross national income per capita (GNIpc) [76]; in comparison, extrapolating from the most cost-efficient $/TB plans among popular airports, 5 GB through an airport averages 0.002% ($0.02) of GNIpc—roughly 0.5% the per-byte cost of fixed-line broadband.
5.4. Sampling for In-Depth Measurement To more deeply understand their behavior, we purchased subscriptions from a subset of the airports we found: 1) Eight popular airports recommended to us by members of the censorship circumvention community in China; 2) Nine less-popular airports found through our scans but never advertised on Telegram; 3) Nine airports that vary in age, as determined by when they were first advertised on Telegram: 3 old, 3 new, and 3 middle-aged airports; 4) Nine airports of varying price: 3 inexpensive, 3 expensive, and 3 medium priced. In total, we purchased subscriptions from 35 airports (Appendix Table 7). For each, we subscribed to the least expensive plans that offered at least 200 GB ‘unrestricted’ monthly traffic (i.e., plans that did not restrict traffic to specific services like Netflix or Facebook) using Alipay. Our subscriptions were blind to other features that may have been offered (e.g., dedicated IEPL lines or specific egress nodes). The subscriptions we purchased provided access to nodes that supported the Shadowsocks [77] (55.41%), VMess [78] (30.09%), Trojan [79] (12.47%), Hysteria [80] (1.61%), and Vless [81] (0.42%) protocols. We describe our safety precautions when purchasing in Appendix A.
6. Performance We evaluate the performance of 35 representative airports by measuring download throughput, round-trip time (RTT), and time-to-first-byte (TTFB) from three Alibaba Cloud instances in Beijing, Guangzhou, and Shanghai. Cloud instances had 2 cores and 8 GB RAM; none of the vantage instances reached maximum CPU utilization. Below we present measurements from Beijing; Guangzhou and Shanghai results were nearly equivalent.
0
Beijing
Guangzhou
Shanghai
Inexpensive 1 Inexpensive 2 Midprice 1 Midprice 2 Midprice 3 Expensive 1 Expensive 2 Expensive 3 Young 1 Young 2 Young 3 Middle-aged 1 Middle-aged 2 Middle-aged 3 Old 1 Old 2 Scan 1 Scan 2 Scan 3 Scan 4 Scan 5 Scan 6 Scan 7 Scan 8 Scan 9 Popular 1 Popular 2 Popular 3 Popular 4 Popular 5 Popular 6 Popular 7 Popular 8
Median RTT (ms)
500
Beijing
2 0
Guangzhou
Shanghai
Inexpensive 1 Inexpensive 2 Inexpensive 3 Midprice 1 Midprice 2 Midprice 3 Expensive 1 Expensive 2 Expensive 3 Young 1 Young 2 Young 3 Middle-aged 1 Middle-aged 2 Middle-aged 3 Old 1 Old 2 Old 3 Scan 1 Scan 2 Scan 3 Scan 4 Scan 5 Scan 6 Scan 7 Scan 8 Scan 9 Popular 2 Popular 3 Popular 4 Popular 5 Popular 6 Popular 7 Popular 8
Median TTFB (s)
(a) Round-Trip Time (RTT) Between Vantage Points and Ingress Proxy Nodes
(b) Time to First Byte (TTFB) to Download Cloudflare-hosted file Through Airport Node
Inexpensive Midprice Expensive Young Middle-aged Old Scan Popular Baseline
200 100
00 08 16 00 08 16 00 08 16 00 08 16 00 08 16 00 08 16 00 08 16 Apr. 1 Apr. 2 Apr. 3 Apr. 4 Apr. 6 Apr. 7 Apr. 5
0
Throughput (Mbps)
Figure 6. Airport Node Latency—Individual datapoints represent the median time across a 24-hour period for a specific node from an airport in that location. Error bars extend to datapoints within 1.5× the interquartile range. The horizontal lines in (b) indicate the median baseline TTFB across a 24-hour period, measured from the three vantage points. While RTTs are similar, TTFB varies across categories: inexpensive, middle-aged, and unpopular airports tend to be slower.
Figure 7. Average Download Throughput—Hour is given in Chinese Standard Time (UTC+8). Red lines indicate day boundaries. Throughput was averaged over all airports in their categories. Baseline indicates connections directly from the client to the server without using any proxies; both baseline and proxied flows terminate at Cloudflare PoPs. Using an airport proxy generally provides throughput comparable to or higher than the direct baseline for the destinations we test, plausibly reflecting that airport egress paths avoid the Great Bottleneck of China [17], though we do not measure the underlying transit paths. In addition, even during the busiest hours, almost all airports offer over 5 Mbps of throughput, which is sufficient for streaming high-definition video. We see a similar pattern in Shanghai and Guangzhou, and omit the figures for brevity.
Latency. We begin by analyzing latency because client software highlights latency to users to assist with node selection: low-latency nodes are most likely to be used. We characterize latency using two metrics: (1) round-trip time (RTT) to airports’ ingress nodes (displayed to the client) and (2) time to first byte (TTFB) fetching a static 1KB file from Cloudflare (representative of experience). We conducted our measurements over a 24-hour period on March 29–30, 2025. Most airports consistently provided multiple nodes with low latency between the client and ingress server, save for one inexpensive airport (Inexpensive 2) and one scanned airport (Scan 4), which were particularly unstable (Figure 6a).
Most airport–location pairs (e.g., Midprice–Shanghai) (80%) had at least one node with a median RTT under 30 ms; five airport-location pairs (5%) had at least one node with a median RTT of over 500 ms. The nodes with the lowest ingress RTT do not always have the best TTFB, which is more indicative of quality of experience: 20 of 32 airports (63%)3 had differing fastest nodes depending on metric. When considering TTFB (Figure 6b), inexpensive airports do not have significantly higher latency than expensive ones (0.94s vs. 0.90s). Purchasing 3. There were 32 airports for which we were able to get results for both our RTT and TTFB experiments.
a more expensive service does not necessarily provide a better experience. Middle-aged airports are slower than both young (t = 3.8, p ≪ 0.05) and old (t = 2.3, p = 0.04) airports. Scanned/unpopular airports also provide a statistically slower experience than popular airports (t = 2.2, p = 0.04), but not by much. We report these tests as exploratory comparisons across small cohorts; effect sizes and per-cohort sample sizes should be considered alongside the reported p-values. Airports do not substantially increase latency relative to direct connections. To test this, we conduct a baseline experiment by measuring the TTFB when downloading a 1 KB file from the same vantage points but without an airport (indicated by the horizontal lines in Figure 6b). The airports’ average TTFB is comparable to that of the baseline (0.9s vs. 0.8s). This difference in means is statistically significant under a t-test (t = 3.28, p = 0.0011), but is small in absolute terms. Together, these measurements indicate that airports generally provide usable node-level latency. Throughput. We next measure download throughput, which captures whether airports can support high-bandwidth use cases like video streaming. Because bandwidth is metered by airports, we test only three proxy nodes per airport 4 . We specifically download data through three random nodes with RTT under 100 ms from clients in Beijing, Guangzhou, and Shanghai since user interfaces like Clash and Surge promote nodes with <100 ms latency as being “green”, encouraging users to choose them. If fewer than three nodes meet this criterion, we select the three nodes with the lowest latency. Between April 1–7, 2025, we downloaded a 50 MB file from Cloudflare every hour through our selected airports. We additionally measured a baseline comparison in which we directly downloaded the file without any airport. As shown in Figure 7, airport throughput is typically more than twice as fast as direct connections (median 131.60 Mbps vs. 64.24 Mbps) and exceeds the direct baseline in 72% of observations. Throughput also remains consistent throughout the day: the median airport throughput in the lowest-throughput hour is still 71.65 Mbps (vs. 7.32 Mbps direct connection baseline). Most of the airports are consistently usable: 30 of 35 airports have median throughput above the 5 Mbps speed that Netflix recommends for full-HD streaming from 18:00–23:00 CST, when throughput is typically the lowest [82]. While the median case is impressive, 15% of observations were below 1 Mbps. These near-zero measurements are concentrated in a small number of airports (two middle-aged airports, one mid-priced airport, and one discovered through Internet scans), rather than being evenly distributed across the ecosystem. The maximum throughput we observed was 297.90 Mbps for an ‘Old’ airport at noon CST. There are significant differences across sampling categories. Popular airports have double the median throughput 4. The breakdown of the protocols understood by these selected nodes are as follows: Shadowsocks (59.05%), VMess (20.95%), Trojan (18.10%) and Hysteria (1.90%)
(208.66 Mbps) of other airports (104.32 Mbps). Intuitively this is consistent: airports are popular because they provide a better experience. Price also correlates with performance: inexpensive airports have substantially lower median throughput (45.82 Mbps) than both mid-priced (197.29 Mbps) and expensive (176.96 Mbps) airports. Lastly, expensive airports have the lowest variation, suggesting the most consistent performance. Limitations. Our performance measurements have several limitations. First, because we measure throughput only on nodes with RTT under 100 ms, our results likely reflect the more performant nodes that users tend to select rather than the full set of nodes in each airport. Second, our RTT and TTFB measurements span 24 hours and may miss day-ofweek variation, while our throughput measurements span one week and may miss weekly or seasonal effects. Finally, we measure from three vantage points in China against a single external provider (Cloudflare); results from other parts of China or providers could differ.
6.1. Decoupled Ingress and Egress Airports have better throughput than direct connections to foreign websites likely due to their network architecture. Across the 35 airports we investigated, most ingress nodes geolocate to mainland China while most egress nodes were labeled as foreign. Ingress IPs are explicitly disclosed to users, but egress addresses are not. To recover egress IPs, we set up a custom IP-echoing HTTP server outside China and sent an HTTP GET request through each proxy node (§7.2). We then geolocated the collected ingress and egress IPs using an IP2Location [83] snapshot from April 8, 2025. As shown in Tables 3 and 4, 92% of ingress nodes geolocate to mainland China. Egress traffic, by contrast, nearly always exits outside mainland China—most commonly in Hong Kong, the United States, Japan, Taiwan, and Singapore. As subscribers, we observe ingress and egress nodes but not intermediate hops or the transport between them. Operators and community documentation report using dedicated cross-border links such as International Ethernet Private Lines (IEPLs) to bypass the GFW (Figure 2) [4]– [16]. While we cannot empirically confirm this architecture, it is consistent with the performance gains we observe, since IEPLs avoid GFW-induced congestion [17]. Regardless of transport, architecturally separating ingress and egress nodes has several implications: 1) Airports can use widely-supported protocols such as Shadowsocks and VMess for client access, while evolving ingress-to-egress transport over the GFW; 2) Operators can replace egress IPs when they are blocked without requiring client reconfiguration; 3) By concentrating cross-border transit into a managed segment, operators can invest in premium links where they matter most; 4) Foreign egress nodes can be specialized for accessing services with geo-location or IP-reputation restrictions.
TABLE 3. I NGRESS AND E GRESS P ROXY N ODE L OCATIONS —Ingress nodes are concentrated in mainland China (13 countries total), whereas egress nodes are distributed across other countries (76 countries).
Ingress
Egress
Egress contd.
CN 1,769 (91.9%) TW 36 (1.9%) SG 35 (1.8%) US 29 (1.5%) AU 15 (0.8%) DE 12 (0.6%) HK 8 (0.4%) JP 4 (0.2%) CZ 2 (0.1%) VN 1 (0.1%)
HK 239 (12.6%) US 190 (10.0%) JP 130 (6.9%) TW 125 (6.6%) SG 96 (5.1%) GB 34 (1.8%) KR 33 (1.7%) DE 20 (1.1%) TR 19 (1.0%) AU 15 (0.8%)
RU FR CA VN AE IN NL AR MY IT
13 (0.7%) 13 (0.7%) 12 (0.6%) 11 (0.6%) 11 (0.6%) 10 (0.5%) 9 (0.5%) 9 (0.5%) 8 (0.4%) 7 (0.4%)
TABLE 4. G EOLOCATION OF INGRESS NODES —Ingress nodes are concentrated in mainland China, dominated by Guangdong and Beijing.
Location
Location contd.
China, Guangdong 636 China, Beijing 551 China, Shanghai 172 China, Hubei 133 China, Jiangsu 93 China, Gansu 80 Singapore, Singapore 35 China, Hainan 30 Taiwan, Taipei 29 USA, California 27 China, Anhui 26
China, Fujian 21 China, Hunan 16 Australia, Queensland 15 Germany, Nordrhein-Westfalen 11 China, Hong Kong 8 China, Shandong 5 Japan, Tokyo 4 China, Tianjin 3 China, Sichuan 3 Taiwan, Taoyuan 2 Czech Republic, Praha 2
Clients have also evolved to exploit this architecture in ways traditional VPNs do not. Client applications (e.g., Clash, Surge) and server software (e.g., Xray, V2Ray) support destination-based routing, sending traffic to different egress nodes depending on the destination. In practice, common airport clients let users import rule sets, assign proxy groups to specific destinations, and route domestic traffic directly while sending selected foreign or blocked traffic through airport nodes. This traffic splitting reduces quota consumption and improves performance on domestic services for users, while lowering server load and bandwidth use for operators. Takeaway Most tested airports sustain usable cross-border throughput even during peak hours, often matching or exceeding direct connections. Their multi-hop architecture and destination-aware traffic splitting help explain this performance by separating domestic ingress from foreign egress and relaying cross-border traffic only as needed.
7. Access Restrictions Beyond performance, users also need to consider what sites airports enable accessing. We evaluate service access for airports and uncover airport-specific censorship policies.
TABLE 5. P ROVIDERS ’ ACCESS TO O NLINE S ERVICES —Airports generally enable access to more geo-restricted services than other circumvention tools. Green checks indicate full access; red crosses indicate blocking or partial availability. Amazon Prime Video (APV), ChatGPT (CGPT), Claude (Cld), Dazn (Dzn), Disney+ (D+), Google Gemini (GGem), Netflix (Nfx), Reddit (Rdt), TVBAnywhere+ (TVB), and YouTube Premium (YT). Tool Airport Airport 6 Airport 7 Airport 9 Airport 10 Airport 20 Airport 8 Airport 11 Airport 23 Airport 1 Airport 3 Airport 16 Airport 36 Airport 37 Airport 25 Airport 26 Non-Airport NthLink [85] Lantern [45] MullvadVPN [86] Psiphon [43] Orbot [87] NordVPN [74] ProtonVPN [75] ExpressVPN [73]
Dzn D+ Nfx YT APV TVB CGPT GGem Cld Rdt ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✗ ✗ ✗ ✗ ✗ ✓ ✓
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✗ ✗ ✗ ✗ ✗ ✗ ✓ ✓
✓ ✓ ✓ ✓ ✓ ✓ ✗ ✗ ✗ ✗ ✗ ✗ ✗ ✗ ✗
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✗
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✗ ✓
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✗ ✗
✗ ✗ ✗
✗ ✗ ✗
✗ ✗ ✗
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ Blocked by the GFW Blocked by the GFW Blocked by the GFW Blocked by the GFW Blocked by the GFW
✓ ✓ ✓ ✓ ✓ ✗ ✓ ✓ ✓ ✓ ✓ ✗ ✗ ✗ ✗
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✗ ✗
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✗ ✗ ✗ ✓ ✓
✗ ✓ ✗
✓ ✓ ✓
✓ ✗ ✗
7.1. Bypass Server-Side Blocking First, we evaluate the extent to which airports can access high-value services, and compare airports against other wellknown circumvention tools. Methodology. From a Beijing VPS, we tested access to popular services using the open-source tool RegionRestrictionCheck [84], which fetches well-known sites and inspects the response for indicators of availability. We included services from the tool’s multinational category and excluded tests that reported only the service’s region of operation or conditions unrelated to availability (e.g., login or CAPTCHA requirements). We counted a service as available only when fully accessible, not when partially restricted (e.g., with content blocked upon VPN detection). We evaluated service accessibility for 15 of the 35 airports we subscribed to that remained operational as of August 25, 2025. To contextualize these results, we also evaluated eight well-known tools using their official Android clients, enabling all available circumvention-related options (e.g., “Shadowsocks Obfuscation”) when available. Our goal is to measure service availability as a user would experience it through standard circumvention tools, not to isolate the effect of any single design choice, such as egress node selection or subscription tier. Results. Of the eight non-airport tools tested, only three functioned in China. Among working tools, airports were able to access more services on average than non-airports (Table 5). Across the three working non-airport tools, 56.7%
7.2. Self-Censorship Despite enabling users to access geoblocked sites and commonly censored content, some users report that airports block access to certain websites (§8.1). In addition, some airports explicitly expose audit logs that record requests that violate their access policies (Figure 8). In this section, we measure the extent to which airports censor content and what motivations may explain this behavior.
# domains censored
of services were accessible, compared to 77.3% for airports (on average). The difference is clearest for geo-restricted streaming services. All three working non-airport tools were blocked by Dazn, Disney+, and Netflix, while airports reached Dazn in ten of 15 cases, Disney+ in nine, and Netflix in six. Netflix was also commonly advertised by airport providers (Figure 2), suggesting that access to commercial media services is an explicit part of the value airports sell, even though Netflix remains the most restricted service in our test. In contrast, Amazon Prime Video was reachable through all tested airports and working non-airport tools. Beyond streaming services, AI tools showed mixed results. Ten of 15 airports and one of the three working nonairport tools could access Google Gemini. Two airports were unable to reach ChatGPT, while all working non-airport tools were able to reach it.
141
128 135 120 108 105 90 75 63 66 60 46 38 45 20 22 30 14 15 0 0 1 4 5 0 20 37 23 8 1 3 9 6 11 36 26 25 10 7 16 Airport ID
Figure 9. Self-Censored Sites Per Airport—We tested 368 sites that were likely to be censored across 15 airports. Only two airports did not self-censor any site. Over half (198 of 368) of sites were censored by at least one airport. TABLE 6. T OP C ENSORED S ITES —We categorized 368 blocked domains. “Domain Sum” is the number of domains blocked across all airports, while “Domain Union” is the number of unique blocked domains. “Min,” “Med,” and “Max” report the minimum, median, and maximum blocked domains in that category among airports that blocked at least one domain in the category. “Airport Union” reports the number of airports that blocked at least one domain in the category.
Category
Domain
Airport
Sum Union Min Med Max Falun Gong News & Media Chinese website Other Trading Police Circumvention Tech Activism Finance
307 120 84 31 24 20 15 14 8 4
57 41 42 12 6 4 5 8 8 4
1 1 1 1 6 4 5 1 1 1
19 9 7 9 6 4 5 2 2 2
56 39 31 10 6 4 5 3 5 3
Union 12 9 8 5 4 5 3 7 3 2
that disclose blocked sites [88], [89]. We narrowed this set to 368 domains that returned HTTP 200 over both HTTP and HTTPS from an uncensored U.S. network. We then attempted to connect to each domain over HTTP and HTTPS through one randomly selected egress node per airport, from a client in Beijing (not all airports accept connections from outside China). We marked a domain as censored by an airport if both the proxied HTTP and HTTPS requests failed, since airports may filter on the HTTP Host header, the TLS SNI, or both. We excluded failures attributable to other causes (e.g., TLS misconfiguration), isolating cases consistent with deliberate blocking. Figure 8. Example Airport Violation Log—Each row corresponds to a specific rule violation, recording the timestamp, proxy node, and rule that was triggered. When expanded, the log provides additional details, including a description, the filtering patterns, and the matching method.
Methodology. We tested access to known censored domains through 15 airports—a subset of those from §6 that remained accessible as of August 23, 2025. (Individual airports are oftentimes ephemeral.) We began with 1,357 domains drawn from the Citizen Lab CN test list [18] and from the audit rules and Terms of Service published by airports
Results. Only two airports did not block any tested domain; 10 of the 15 airports censored at least ten domains (Figure 9). Of the 368 domains tested, 198 were censored by at least one airport. Using publicly available audit-rule categorizations [89], we manually classified these 198 selfcensored domains into 16 categories (Table 6); we describe the most prominent below. Together, these findings confirm that the user reports in §8.1 reflect a broader pattern: selfcensorship is a systematic practice across airports. Falun Gong. Falun Gong-related websites were most commonly blocked: 12 airports blocked at least one domain, with
307 domain–airport blocks. Examples include minghui.org (the movement’s official site), epochtimes.com (a Falun Gong-affiliated Western media outlet and known misinformation site [90]), and wujieliulan.com (Ultrasurf [49], a circumvention tool developed by Falun Gong practitioners). News Media. Nine airports blocked access to news outlets. Seven airports blocked mingjingnews.com (Mingjing News), five blocked chinadigitaltimes.net (China Digital Times), four blocked rfa.org (Radio Free Asia) and voachinese.com (Voice of America), and one blocked nytimes.com. Domestic Chinese Websites. Eight airports blocked access to popular Chinese websites and apps. Notably, five airports blocked the platform- and government-adjacent reporting portals 110.qq.com and 12321.cn, which solicit reports of online “harmful” or illegal content. Beyond these, the most frequently censored domains include security vendors (360.cn, kingsoft.com), online banking (cmbchina.com), media (news.cctv.com), and social platforms (m.weibo.cn, xiaohongshu.com, douyin.com). Airports likely block access to these domestic sites because they could expose airports’ egress IP addresses to companies and the government. Circumvention Services. Three airports blocked torproject.org (the Tor Project website), which prevents downloading Tor binaries. This could be because Tor provides a free competitive offering. Inconsistent Enforcement Across Nodes. In one instance, we find that self-censorship is not applied consistently across all nodes for a given airport. We performed a targeted probe using one of the most censored domains (epochtimes.com). For each of the 15 airports, we tested accessibility across three randomly selected nodes. Our results showed that at least one airport (ID 6) enforced their policy inconsistently, permitting access on at least one tested node while other nodes blocked the domain, indicating a potential misconfiguration in this airport’s blocklists. Self-censorship Motivation. Self-censorship may appear self-defeating since airports are bought to bypass censorship. We suspect that this is partly due to operator ideology. In one such incident, an airport operator was heavily criticized for suspending users who visited websites that the operator deemed ‘unpatriotic’ [91], [92]. The operator quotes a personal anecdote with Falun Gong as a reason for disabling access to sites that promote it. Another reason for blocking access to certain websites could be risk mitigation. While operating an airport is illegal in China, blocking the most objectionable content may lower the profile of operators, allowing them to evade targeting. Takeaway Airports improve access to geo-restricted and censored services, but most tested airports also impose their own self-censorship, replacing state-imposed blocking with operator-imposed filtering. Our findings complicate the notion of “free access": bypassing a censor does not guarantee a fully uncensored path.
8. Ecosystem Challenges Airports are popular because they make it easy to circumvent the GFW and access popular Internet services at a low cost. But this convenience also introduces fragility: users depend on opaque operators, third-party clients, and payment channels tied to individuals’ identities. In this section, we examine challenges to and concerns about the airport ecosystem.
8.1. User-Perceived Challenges We draw on our survey responses to understand the challenges airport users face; 806 participants used the free-form response field to describe challenges and inconveniences (Figure 10). Across all circumvention methods, users most commonly faced challenges with instability (180), configuration difficulty (163), and poor availability (150). For airport users, instability (16%) was the most common challenge, followed by availability issues (14%) whereas configuration was the largest challenge (20%) for self-hosting respondents. Respondents who use neither airports nor selfhosting reported fewer configuration issues (4%) but more stability issues (22%) than both airport users (z = 1.86, p = 0.03) and self-hosting users (z = 3.03, p ≪ 0.05), and reported speed problems more often (16%) than airport users (z = 2.1, p = 0.02). Setup. Users primarily found airports through Internet search (62%), Telegram (53%), and friends/family (25%). However, users note technical challenges even before they begin using an airport: 17 respondents noted the catch-22 that finding an airport service requires circumventing the GFW: 想购买服务需翻墙,翻墙前需购买服务 (“Buying a service requires circumvention, which creates a paradox.”). Additionally, as airports often do not support auto-renewal, users are left without access once their subscription expires. This necessitates backup subscriptions, or fastidious manual renewals. Several respondents indicated the financial overhead of keeping backups in case their current subscription ceased to operate. A respondent notes: 运营不稳定:服务商的机器常面临被攻击、 违规清退、ip被墙等问题,所以会同时购买 多 个 机 场 的 套 餐 以 备 不 时 之 需 (“Operators’ machines often face attacks, abuse reports, and IP blocking issues, forcing users to maintain multiple subscriptions as backups.”) There are also technical challenges in configuring client proxy software. Participants noted that configuration is tedious, requires significant technical expertise, and has insufficient documentation or maintenance. This makes it difficult to share their tools with others. One respondent noted: 不容易帮助朋友设置 去年安卓手机客户端失效 了, igniter停止了开发. (“Difficult to help friends set up; last year, Android clients stopped working, and Igniter stopped development.") Several respondents note the difficulty of configuring trafficsplitting rules to ensure that only blocked traffic goes
Percentage
20
All Airports Self setup Other
10
Challenge
Explanation
Stability Configuration Availability
Unreliable or frequently disconnected service Difficulty setting up or configuring tools/software Inability to access the desired content, potentially because proxies or services are down, or because providers block specific websites Slow connections, high latency, or low bandwidth Fear of surveillance and/or legal consequences
Speed Safety
Stability Configuration Availability Speed Safety Payment Shared IP Issues Features/Usage Operator Mistrust Protocol Support/Updates Bootstrapping Maintenance Incompatibility
Payment Concerns
0
Challenges
Shared IP Issues Operator Mistrust Limited Features/Usage Protocol Support Bootstrapping Maintenance Incompatibility
Risks from using payment methods such as Alipay or WeChat, or concerns about service price Proxy IPs flagged by websites, leading to blocking or anti-bot mechanisms such as CAPTCHAs Suspicion that airport operators log user traffic, cooperate with the government, or may disappear Missing features, such as auto-renewal or a friendly GUI, or usage limits such as device or traffic caps Lack of support or updates for new protocols Difficulty acquiring or updating circumvention tools access requires bypassing the GFW Lack of development support or maintenance Tools are unsupported on some operating systems, devices, or software configurations
Figure 10. Reported Challenges—We report the challenges most commonly faced by users in our survey.
through the airport nodes instead of all network traffic. Additionally, users note that they need to be careful during configuration to avoid DNS leaks. Operator Trust. Because airports are largely run by anonymous operators, 55 respondents (8%) expressed mistrust, including concern over potential data leaks (机场常 常在未告知用户的情况下记录用户的网络日志 “Airport services often face data leaks; operators sometimes record network logs without informing users.”). This fear may stem from airports that have previously been compromised and had user data stolen [93]–[96]. Some feared that the operator will cease to provide them their services, whether through takedowns or by choice (担心供应商跑路, “Concern over providers abruptly shutting down.”). Participants also feared that airport providers cooperate with the Chinese government. One respondent reports: 机场大多与中国政府有关系,安全性不太好 (“Most airports have ties to Chinese authorities, reducing security.”) Beyond general mistrust of airport operators, 47 users feared that they or the operators would be caught by the authorities for bypassing the GFW. Airport users also expressed discontent with airport operators’ political statements and noted that ideological differences can deter potential airport users who may prefer services that align with their own values. One user expressed: 此外,有一个机场运营者的意识形态偏向“爱 国 爱 党”, 用 大 陆 五 星 旗 来 标 识 台 湾 节 点 , 我提出异议,希望至少去掉五星红旗,但 没有被采纳。我怀疑他随时都会跑路。过 去几年,台湾节点用五星旗的机场基本上都 跑了。 (“one airport operator was ideologically “pro-CCP”, marking Taiwan nodes with China’s five-star red flag. I raised an objection, requesting
at least the removal of the flag, but it wasn’t accepted. I suspect they might go out of business at any time. Over the years, airports marking Taiwan nodes with the five-star flag have typically run away.”) Censorship and Access. Ten respondents commented on the restrictive self-censorship that some airports employ (described in §7.2). For example, a user states: 我 使 用 的Trojan机 场 订 阅 会 对 敏 感 网 站 (如.gov域名/境外新闻网站/时政论坛)进行封 锁。 (“My Trojan airport subscription blocks sensitive websites like .gov domains, overseas news platforms, and political discussion forums.”) Additionally, airport proxy nodes often serve multiple users behind a single IP address. As a result, 35 respondents report issues with websites classifying them as bots and either blocking access or imposing CAPTCHAs. Moreover, the content delivered to these users is localized to the proxy location, rather than the user’s, leading to a poorer quality of experience. For example, a user reports: 日 本 线 路 下 用Google 容 易 出 现 日 文 结 果 。 (“Using Japanese routes often leads to Japaneselanguage search results on Google.”) Payment. Respondents note financial risks associated with airports, which mostly use Alipay or WeChat. Users fear that airport providers may store their financial information, and express concern over the privacy of the payment methods. While foreign payment methods are safer, users note that they are inconvenient. Airports often offer discounts if users purchase annual subscriptions. But users express that these longer subscriptions elevate risk if there is a takedown or scam. One respondent mentions: 服务商容易跑路,年付风险大但优惠大,月付 季付相对麻烦没有优惠但风险小。 (“Operators
often shut down suddenly. Annual payments carry risks but offer discounts; shorter-term payments are safer but less convenient.”) Some airport users (44) are also concerned about the cost of their subscription. A user mentions: 年费相较于收入较 高 (“Annual fees are relatively high compared to income.”). This concern is further compounded by the fact that some users (10) also feel that data plans are insufficient.
8.2. Other Challenges Beyond the concerns expressed by surveyed users, our investigation also uncovers several systemic weaknesses: Vulnerability Impact. Airports have seen multiple dataleak incidents, including disclosures affecting users of v2board-based portals [93]–[96]. Because 95% of the airports we identify run v2board or sspanel (Table 2), faulty code in a shared template can create vulnerabilities in hundreds of otherwise independent airports. The same template standardization that lowers the barrier of entry to operate an airport also makes it a correlated-risk surface. Vulnerability Disclosure Channel. Because airport operators are fully anonymous, there is no established channel for disclosing vulnerabilities, nor an easy way for users to learn whether their operator has applied a fix. The closest replacement to a systematic vulnerability disclosure platform are informal, operator-run Telegram channels and announcements on individual airport portals. Takeaway Airport users commonly report instability and availability problems, showing that commercialized circumvention improves usability but still leaves users dependent on fragile services and opaque operators. Future tools should borrow airports’ usability model, but pair it with stronger transparency, failover, and trust mechanisms.
9. Discussion and Conclusion In this work, we systematically analyzed the airport proxy ecosystem in China, showing that airports have become a leading off-the-shelf censorship circumvention option due to their usability, performance, low cost, and ability to access geo-restricted services. At the same time, we uncover self-censorship and other challenges faced by users and operators. In this section, we draw lessons from airports’ success and discuss recommendations for the censorship circumvention community. Decentralization Enables Resilience. Airports are not technically sophisticated nor are they hidden. As a result, they are regularly blocked and taken down by authorities [97]–[102]. Yet, despite the fact that individual airports are relatively fragile and ephemeral, the ecosystem appears resilient because of the large number of independent operators and proxy nodes available at any given time. That
resilience is not a product of protocol design. Rather, it comes from a handful of open-source toolkits that make it easy and accessible to run an airport. As a result, hundreds of people inside China are willing to run airports. Circumvention as a Service. Our results suggest that one of the foremost use cases for airports is accessing popular geoblocked and/or GFW-blocked services like Netflix and ChatGPT on a daily basis rather than viewing overtly politically sensitive content. Beyond ease of use and performance, this may explain why users are willing to pay for airports even though free circumvention tools exist. It may be that access to more explicitly censored political content is a sideeffect rather than the primary goal of airports. Nonetheless, through their focus on mainstream users and websites, airports may also have unintentionally become one of the easiest ways to access other types of censored content. New Security and Privacy Risks. While there is a clear willingness to pay for access and payments enable the airport ecosystem to be self-sustaining, commonly used payment processors like Alipay and WeChat create clear risks to users, who can be easily identified. This creates a new challenge for future systems: how to accept payment in an easily accessible manner that simultaneously provides user security in an ecosystem where cryptocurrencies and other payment methods are banned. Change of Censorship Control. Airports bypass the GFW, but many do not provide unrestricted Internet access. We find that most tested airports block access to certain websites, including Falun Gong-related sites, overseas news media, and other circumvention resources (§7.2). This behavior may reflect operator risk management, but it may also reflect user demand. Some users may primarily want stable access to foreign entertainment and AI tools, and may tolerate operator-imposed filtering as long as the services they are interested in continue to work. Prior work on censorship attitudes similarly suggest that not all users conceptualize circumvention as completely unrestricted political access [103], [104], shedding light on why self-censorship is a trade-off they are willing to accept. Recommendations. The airport ecosystem suggests two priorities for the circumvention community. First, build for operators, not only users: the ecosystem’s resilience flows from toolkits that let people inside China stand up and secure their own services, so hardening and distributing that software—minimal-data account systems, safer defaults, a vulnerability-disclosure path for the shared templates that 95% of airports depend on—may do more than building and running yet another platform from outside the censored region. Closing that gap may matter more than any throughput gain. Second, evaluate circumvention by what users actually receive: bypassing the state censor guarantees neither service availability (§7.1) nor an uncensored path (§7.2), so both belong alongside reachability and performance in how we measure success.
References [1]
“Shadowsocks github,” https://github.com/shadowsocks, GitHub, 2026.
[2]
ClashX contributors, “Clashx,” https://en.clashx.org/, 2025.
[3]
Shadow Launch Technology Limited, “Shadowrocket,” https://apps. apple.com/us/app/shadowrocket/id932747118, 2025.
[4]
China Mobile International. 国际专线(iplc). [Online]. Available: https://isolutions.cmi.chinamobile.com/sc/product/connectivity/iplc
[5]
China Telecom Americas, “IEPL (international ethernet private line) product brochure,” China Telecom Americas, Tech. Rep., 2018. [Online]. Available: https://www.ctamericas.com/wp-content/ uploads/2018/10/IEPL.pdf
[6]
China Telecom (Asia Pacific). (2024, Jan.) IEPL & IPLC: Exploring reliable data connectivity solutions. [Online]. Available: https://www.chinatelecom-ctap.com/blog-and-whitepaper/iepliplc-exploring-reliable-data-connectivity-solutions
[7]
Kxs. (2023, Jul.) 硬核翻墙系列8:内网线路. Blog post describing internal network circuits and comparing IEPL and IPLC. [Online]. Available: https://hardcoreq.com/8.%20%E5%86%85% E7%BD%91%E7%BA%BF%E8%B7%AF/
[19]
P. Winter and S. Lindskog, “How the Great Firewall of China is blocking Tor,” in USENIX Free and Open Communications on the Internet, 2012.
[20]
Z. Chai, A. Ghafari, and A. Houmansadr, “On the importance of encrypted-SNI (ESNI) to censorship circumvention,” in USENIX Free and Open Communications on the Internet, 2019.
[21]
N. P. Hoang, J. Dalek, M. Crete-Nishihata, N. Christin, V. Yegneswaran, M. Polychronakis, and N. Feamster, “GFWeb: Measuring the Great Firewall’s Web censorship at scale,” in USENIX Security Symposium, 2024.
[22]
A. Zohaib, Q. Zao, J. Sippe, A. Alaraj, A. Houmansadr, Z. Durumeric, and E. Wustrow, “Exposing and circumventing SNI-based QUIC censorship of the Great Firewall of China,” in USENIX Security Symposium, 2025.
[23]
N. P. Hoang, A. A. Niaki, J. Dalek, J. Knockel, P. Lin, B. Marczak, M. Crete-Nishihata, P. Gill, and M. Polychronakis, “How great is the Great Firewall? Measuring China’s DNS censorship,” in USENIX Security Symposium, 2021.
[24]
P. Pearce, B. Jones, F. Li, R. Ensafi, N. Feamster, N. Weaver, and V. Paxson, “Global measurement of DNS manipulation,” in USENIX Security Symposium.
[25]
A. Bhaskar and P. Pearce, “Many roads lead to Rome: How packet headers influence DNS censorship measurement,” in USENIX Security Symposium, 2022.
[26]
R. Rambert, Z. Weinberg, D. Barradas, and N. Christin, “Chinese wall or Swiss cheese? keyword filtering in the Great Firewall of China,” in ACM Web Conference, 2021.
[27]
J. Knockel, L. Ruan, and M. Crete-Nishihata, “Measuring decentralization of Chinese keyword censorship via mobile games,” in USENIX Free and Open Communications on the Internet, 2017.
[8]
Runtushare. 2025 稳 定 可 靠 的iepl专 线 机 场 推 荐. Available: https://runtushare.net/5352/
[9]
梯子博客. (2021, Aug.) iepl、iplc详细介绍及区别. [Online]. Available: https://tizi.blog/204.html
[10]
China Unicom Americas. IEPL. [Online]. Available: https: //unicomus.com/iepl/
[11]
xiaoji. (2023) What is a dedicated line and why do we use IPLC and IEPL dedicated lines? [Online]. Available: https://jdssl.top/index.php/2023/08/08/iplc/
[28]
Kxs. (2025) Hardcore wall-crossing series 8: Intranet line. Hardcore Wall-Crossing Series blog post. [Online]. Available: https://hardcoreq.com/8.%20%E5%86%85%E7%BD% 91%E7%BA%BF%E8%B7%AF/
M. Wu, J. Sippe, D. Sivakumar, J. Burg, P. Anderson, X. Wang, K. Bock, A. Houmansadr, D. Levin, and E. Wustrow, “How the Great Firewall of China detects and blocks fully encrypted traffic,” in USENIX Security Symposium, 2023.
[29]
Alice, Bob, Carol, J. Beznazwy, and A. Houmansadr, “How China detects and blocks Shadowsocks,” in ACM Internet Measurement Conference, 2020.
[30]
E. Tsai, R. S. Raman, A. Prakash, and R. Ensafi, “Modeling and detecting Internet censorship events,” in Network and Distributed System Security, 2024.
[31]
A. Filastò and J. Appelbaum, “OONI: Open observatory of network interference,” in USENIX Free and Open Communications on the Internet, 2012.
[32]
R. S. Raman, L.-H. Merino, K. Bock, M. Fayed, D. Levin, N. Sullivan, and L. Valenta, “Global, passive detection of connection tampering,” in SIGCOMM. ACM, 2023.
[33]
R. S. Raman, P. Shenoy, K. Kohls, and R. Ensafi, “Censored Planet: An Internet-wide, longitudinal censorship observatory,” in Computer and Communications Security. ACM, 2020. [Online]. Available: https://www.ramakrishnansr.com/assets/censoredplanet.pdf
[34]
A. A. Niaki, S. Cho, Z. Weinberg, N. P. Hoang, A. Razaghpanah, N. Christin, and P. Gill, “ICLab: A global, longitudinal internet censorship measurement platform,” in IEEE Symposium on Security & Privacy, 2020.
[35]
R. Dingledine and N. Mathewson, “Design of a blockingresistant anonymity system,” The Tor Project, Tech. Rep., 2006. [Online]. Available: https://svn.torproject.org/svn/projects/designpaper/blocking.pdf
[36]
M. Pu, A. Wang, A. Chang, K. Quan, and Y. W. Zhou, “Exploring Amazon simple queue service (SQS) for censorship circumvention,” in USENIX Free and Open Communications on the Internet, 2024.
[37]
S. Zillien, T. Schmidbauer, M. Kubek, J. Keller, and S. Wendzel, “Look what’s there! utilizing the Internet’s existing data for censorship circumvention with OPPRESSION,” in ACM Asia CCS, 2024.
[12]
[Online].
[13]
bclerdx, “你的 IEPL 专线机场的电信入口即将被拔线,电信 线路得加钱 (The China Telecom Entry Point of Your IEPL Dedicated-Line Airport Is About to Be Disconnected; Telecom Lines Will Cost Extra),” V2EX, 2026. [Online]. Available: https://www.v2ex.com/t/1199638
[14]
NodeSeek user, “【深港IEPL】入口BGP,出口国际优化线路, 更有各国IPLC线路,欢迎围观!([Shenzhen–Hong Kong IEPL] BGP Ingress, Internationally Optimized Egress Routes, Plus IPLC Routes to Many Countries–Come Take a Look!),” NodeSeek, 2024. [Online]. Available: https://www.nodeseek.com/post-293071-1
[15]
ermaozi, “如何判断一个机场使用的线路类型(如IPLC/IEPL专 线、CN2、BGP中转等)(How to Determine the Line Type Used by a Proxy “Airport” (Such as IPLC/IEPL Dedicated Lines, CN2, BGP Relay, etc.)),” Ermao Blog, Jan. 2025. [Online]. Available: https://www.ermao.net/article/r50bpg9j/
[16]
OpenNetCN/freego contributors, “Chinese title: Clash 机场线 路类型详解:直连 / 中转 / 专线(IPLC / IEPL)区别与 选择指南 (Clash Airport Line Types Explained: Differences Between Direct Connection, Relay, and Dedicated Lines (IPLC / IEPL), and a Selection Guide),” GitHub repository file, Jun. 2026. [Online]. Available: https://github.com/OpenNetCN/freego/ blob/main/route.md
[17]
P. Zhu, K. Man, Z. Wang, Z. Qian, R. Ensafi, J. A. Halderman, and H. Duan, “Characterizing transnational internet performance and the great bottleneck of China,” ACM Measurement and Analysis of Computing Systems, 2020.
[18]
Citizen Lab, “China (cn) test list (cn.csv).” [Online]. Available: https://github.com/citizenlab/test-lists/blob/master/lists/cn.csv
[38]
C. Bocovich, A. Breault, D. Fifield, Serene, and X. Wang, “Snowflake, a censorship circumvention system using temporary WebRTC proxies,” in USENIX Security Symposium, 2024.
[60]
R. Ramesh, L. Evdokimov, D. Xue, and R. Ensafi, “Vpnalyzer: systematic investigation of the vpn ecosystem,” in Network and Distributed System Security, 2022.
[39]
D. Fifield, N. Hardison, J. Ellithorpe, E. Stark, R. Dingledine, P. Porras, and D. Boneh, “Evading censorship with browser-based proxies,” in Privacy Enhancing Technologies Symposium, 2012.
[61]
R. Ramesh, A. Vyas, and R. Ensafi, “"all of them claim to be the best": Multi-perspective study of VPN users and VPN providers,” in USENIX Security Symposium, 2023.
[40]
E. Chi, G. Wang, J. A. Halderman, E. Wustrow, and J. Wampler, “Just add WATER: WebAssembly-based circumvention transports,” in Free and Open Communications on the Internet, 2024.
[62]
B. Mixon-Baca, J. Knockel, and J. R. Crandall, “Hidden links: Analyzing secret families of VPN apps,” in Free and Open Communications on the Internet, 2025.
[41]
K. Bock, G. Hughey, X. Qiang, and D. Levin, “Geneva: Evolving censorship evasion strategies,” in ACM Computer and Communications Security, 2019.
[63]
Y. T. Chua and B. Collier, “Fighting the “blackheart airports”: internal policing in the chinese censorship circumvention ecosystem,” in APWG Symposium on Electronic Crime Research (eCrime), 2019.
[42]
D. Fifield, C. Lan, R. Hynes, P. Wegmann, and V. Paxson, “Blocking-resistant communication through domain fronting,” Privacy Enhancing Technologies, 2015.
[64]
clash-verge-rev contributors, “Clash,” verge-rev/clash-verge-rev, 2025.
[65]
[43]
P. developers. Psiphon3. [Online]. Available: https://psiphon.ca/
S. contributors, “sing-box: The universal proxy platform,” https:// github.com/SagerNet/sing-box, 2025.
[44]
E. Wustrow, S. Wolchok, I. Goldberg, and J. A. Halderman, “Telex: Anticensorship in the network infrastructure,” in USENIX Security Symposium, 2011.
[66]
Surge Networks Inc., “Surge,” https://nssurge.com/, 2025.
[67]
G. Report, “Survey recruitment post (X),” https://x.com/gfw_report/ status/1842070047503876109, October 2024.
[68]
Internet Corporation for Assigned Names and Numbers (ICANN), “Centralized zone data service (czds),” https://czds.icann.org, 2025.
[69]
ZMap Project, “Zgrab2: Application layer scanner,” https://github. com/zmap/zgrab2/, 2017.
[45]
Lantern. [Online]. Available: https://github.com/getlantern
[46]
D. Fifield and T. T. Project, “Meek: A pluggable transport for censorship circumvention,” accessed: 2024-12-31. [Online]. Available: https://git.torproject.org/pluggable-transports/meek.git
https://github.com/clash-
[47]
Shadowsocks developers, “Shadowsocks whitepaper,” Jun. 2019. [Online]. Available: https://github.com/shadowsocks/shadowsocksorg/blob/master/whitepaper/whitepaper.md
[70]
Z. Durumeric, E. Wustrow, and J. A. Halderman, “ZMap: Fast internet-wide scanning and its security applications,” in 22nd USENIX Security Symposium, 2013.
[48]
D. I. T. Inc., “Freegate: Anti-censorship software for secure and fast internet access,” 2002, accessed: 2024-12-31. [Online]. Available: https://www.dit-inc.us/freegate.html
[71]
Z. Durumeric, D. Adrian, P. Stephens, E. Wustrow, and J. A. Halderman, “Ten years of zmap,” in ACM Internet Measurement Conference, 2024.
[49]
U. I. Corp., “Ultrasurf: Internet freedom, privacy, and security,” 2002, accessed: 2024-12-31. [Online]. Available: https://ultrasurf.us/
[72]
IPinfo, “IPinfo: IP Address Data API and Services,” https://ipinfo. io/, 2025, accessed: 2025-08-25.
[50]
Y. Angel et al., “Obfs4 specification.” [Online]. Available: https://gitlab.com/yawning/obfs4/blob/master/doc/obfs4-spec.txt
[73]
ExpressVPN, “Expressvpn,” https://www.expressvpn.com/, 2025.
[74]
NordVPN, “Nordvpn,” https://nordvpn.com/, 2025.
[75]
Proton AG, “Proton vpn,” https://protonvpn.com/, 2025.
[76]
International Telecommunication Union, “ICT Prices,” https: //www.itu.int/en/ITU-D/Statistics/Pages/ICTprices/default.aspx, accessed: 2025-04-13.
[77]
Shadowsocks shadowsocks.
[78]
V. developers, “Vmess.” [Online]. Available: https://www.v2fly.org/ en_US/developer/protocols/vmess.html
[79]
trojan developers. trojan. [Online]. Available: https://github.com/ trojan-gfw/trojan
[51]
[52]
[53]
Y. Kou, Y. Kow, and X. Gui, “Resisting the censorship infrastructure in china,” ser. Annual Hawaii International Conference on System Sciences, 2017. Y. Feng, R. Zhai, R. Sion, and B. Carbunar, “A study of China’s censorship and its evasion through the lens of online gaming,” in USENIX Security Symposium. USENIX, 2023. [Online]. Available: https://www.usenix.org/system/files/usenixsecurity23-feng.pdf D. Xue, A. Ablove, R. Ramesh, G. K. Danciu, and R. Ensafi, “Bridging barriers: A survey of challenges and priorities in the censorship circumvention landscape,” in USENIX Security Symposium, 2024.
Developers,
“Shadowsocks,”
https://github.com/
[54]
D. Wang and G. Mark, “Internet censorship in china: Examining user awareness and attitudes,” ACM Trans. Comput.-Hum. Interact., 2015.
[80]
[55]
S. Guo and C. Feng, “Understanding support for internet censorship in china: An elaboration of the theory of reasoned action,” Journal of Chinese Political Science, vol. 17, 03 2011.
apernet, “Hysteria: A powerful, lightning-fast, and censorshipresistant proxy,” https://github.com/apernet/hysteria, 2026, gitHub repository; accessed 2026-06-06.
[81]
[56]
Y. Kou, B. Semaan, and B. Nardi, “A confucian look at internet censorship in china,” in Human-Computer Interaction, ser. Lecture Notes in Computer Science, 2017.
XTLS Project, “VLESS: Xtls vision seed,” https://xtls.github.io/en/ config/inbounds/vless.html, 2026, documentation; accessed 202606-06.
[82]
[57]
F. Shen and L. Tsui, “Public opinion toward internet freedom in asia: A survey of internet users from 11 jurisdictions,” SSRN Electronic Journal, 05 2016.
Netflix, “Netflix-recommended internet speeds,” https://help.netflix. com/en/node/306, accessed: 2026-06-01.
[83]
“IP2Location LITE IP address geolocation database.” [Online]. Available: https://www.ip2location.com/database/ip2location
[84]
lmc999, “Regionrestrictioncheck,” aug 23 2025. [Online]. Available: https://github.com/lmc999/RegionRestrictionCheck/tree/ 51f32cb36be4c5aa4f3f32f6ec62f8645bdffba0
[85]
nthLink, “nthlink,” https://www.nthlink.com/, 2025.
[86]
Mullvad VPN AB, “Mullvad vpn,” https://mullvad.net/en.
[58]
D. Xue, M. Kallitsis, A. Houmansadr, and R. Ensafi, “Fingerprinting obfuscated proxy traffic with encapsulated TLS handshakes,” in USENIX Security Symposium, 2024.
[59]
M. T. Khan, J. DeBlasio, G. M. Voelker, A. C. Snoeren, C. Kanich, and N. Vallina-Rodriguez, “An empirical analysis of the commercial vpn ecosystem,” in ACM Internet Measurement Conference, 2018.
[87]
The Guardian Project, “Orbot (tor for mobile),” https://orbot.app/en/, 2025.
[88]
jichangtuijian, “Common airport audit rules,” 2024. [Online]. Available: https://jichangtuijian.com/%E6%9C%BA%E5%9C% BA%E5%B8%B8%E8%A7%81%E5%AE%A1%E8%AE%A1% E8%A7%84%E5%88%99.html
[89]
DuyaoSS, “部分机场的tos或审计规则,” 03 2018. [Online]. Available: https://www.duyaoss.com/archives/2706/
[90]
A. Y. Qin, F. Xiao, and L. Dai, “Tell china’s conspiracy well: Networks and narratives of anti-ccp youtube conspiracy theorists,” Convergence: The International Journal of Research into New Media Technologies, 2025, first published online November 5, 2025. [Online]. Available: https://doi.org/10.1177/13548565251392612
[91]
F. Info. Dimension pocket’ proxy service: a ‘little pink’ patriotic provider that audited users’ circumvention activity, leading to the owner’s quit. fanqiang.info. [Online]. Available: https://fanqiang.info/archives/ai-guo-ji-chang-guan-bi-le.html
[104] S. Guo and G. Feng, “Understanding support for internet censorship in china: An elaboration of the theory of reasoned action,” Journal of Chinese Political Science, 2012. [105] 瓶奶油. (2023, Oct.) 最新V2Board 面板搭建机场教程,超详 细!从零开始搭机场|机场搭建优化方案,一个视频看完机场搭 建过程,看完你也可以轻松搭建,体验当机场主的感觉#一瓶 奶油. [Online]. Available: https://www.youtube.com/watch?v=SllnUPSaeI [106] 瓶奶油. (2025, Mar.) 【全网首发】一键搭建sspanel uim机场 面板教程,2025最新机场面板搭建,一键脚本搭建,最简单的 搭建方案,SSpanel uim面板功能更加完善,设置、节点对接更 加简单#一瓶奶油. [Online]. Available: https://www.youtube.com/ watch?v=YLPb9oT_cUQ [107] GitHub, “v2board,” https://github.com/v2board/v2board, accessed: 2025-08-27. [108] GitHub, “sspanel,” https://github.com/Anankke/SSPanel-UIM, accessed: 2025-08-27. [109] Dongguan First People’s Court of Guangdong Province, “广 东 省 东 莞 市 第 一 人 民 法 院 (2017) 粤1971刑 初250号 刑 事 判 决 书 (Criminal Judgment No. (2017) Yue 1971 Xingchu 250 of the First People’s Court of Dongguan City, Guangdong Province),” Mar. 2017. [Online]. Available: https://zh.wikisource.org/wiki/%E5%B9%BF%E4%B8%9C% E7%9C%81%E4%B8%9C%E8%8E%9E%E5%B8%82%E7% AC%AC%E4%B8%80%E4%BA%BA%E6%B0%91%E6%B3% 95%E9%99%A2%EF%BC%882017%EF%BC%89%E7%B2% A41971%E5%88%91%E5%88%9D250%E5%8F%B7%E5%88% 91%E4%BA%8B%E5%88%A4%E5%86%B3%E4%B9%A6
[92]
Recommendations for patriotic airport services. Telegram. Telegram channel @aiguojichang. [Online]. Available: https: //t.me/s/aiguojichang
[93]
S. Yatu. (2022) Panel tool v2board was hacked, and the ladder was under pressure. [Online]. Available: https://www.cnblogs.com/ arrdres/p/16986407.html
[94]
planet cx330, “v2board-data,” GitHub repository, 2025, repository on GitHub; exposes V2Board “airport” panel data leak (data from four sites disclosed). [Online]. Available: https://github.com/ oldyibin/v2board-Data
[95]
BandWh.com. (2022, Dec.) Airport panel v2board exposed security vulnerability. [Online]. Available: https://www.bandwh.com/news/ 87.html
Appendix A. Ethical Considerations
[96]
Lomi Wei Xiong. (2023, Jan.) Panel tool v2board was hacked, and the ladder was under pressure. Tencent Cloud Developer Community. [Online]. Available: https://cloud.tencent.com/developer/article/2204631
[97]
M. C. P. Procuratorate, “男子私自搭建VPN服务器非法获利50余 万元被判刑 (Man Sentenced for Illegally Profiting More Than 500,000 Yuan by Privately Setting Up VPN Servers),” Dec. 2017. [Online]. Available: https://www.mc.ls-jcy.gov.cn/mcx/show23642.html
This work documents a censorship circumvention ecosystem both operated and used by people who may face legal or personal risk for bypassing government controls. We considered the potential risks and benefits to individual airport operators and users, destination services, survey participants, the research team, and the airport ecosystem at large presented by conducting and publishing this research.
[98]
The Dui Hua Foundation, “Fortifying the Great Firewall: The Criminalization of VPNs, Part II,” Dui Hua Human Rights Journal, 2019. [Online]. Available: https://duihua.org/fortifying-the-greatfirewall-the-criminalization-of-vpns-part-ii/
[99]
B. Ye. (2024, Mar.) Seizing the lack of illegal awareness to defend innocence – wu moumou, charged with providing programs and tools for invading and illegally controlling computer information systems, was dismissed. Zhihu Column. [Online]. Available: https://zhuanlan.zhihu.com/p/685778246
[100] L. Zhou. (2024, Oct.) Dr. zhou libo was acquitted of a shanghai circumvention software case at the public security stage. [Online]. Available: https://www.houqilawyer.com/ successstory3518/info.aspx?itemid=2425 [101] L. Zhou and Y. Wang. (2022, Jan.) The case of mr. nong, who was defended by lawyers zhou libo and wang yong, involving the use of “wall-climbing software”, was released on bail during the trial phase. [Online]. Available: https: //www.houqilawyer.com/LatestResults/info.aspx?itemid=1952 [102] L. Tan, “China: Fears of a Further Crackdown on Netizens Illegally Accessing Foreign Sites,” Bitter Winter, Apr. 2026, accessed: 202606-06. [Online]. Available: https://bitterwinter.org/china-fears-of-afurther-crackdown-on-netizens-illegally-accessing-foreign-sites/ [103] T. Z. Yang, “Participatory censorship in authoritarian regimes,” Comparative Political Studies, 2024, advance online publication.
Decision to Publish. While airports have received little attention in the academic literature, they are not secret. Operators post public videos on YouTube describing how to run an airport (e.g., [105], [106]), portal software is publicly available on Github (e.g., [107], [108]), and public Telegram channels routinely advertise them. Even operational details, such as airports’ use of IEPL dedicated lines, are discussed openly in public forums and websites [13]–[16]. Airports are regularly shut down, and airport operators have been targeted by the Chinese government (e.g., [97]–[102], [109]), indicating that their existence is well known. Publishing this study could marginally help adversaries understand the ecosystem, but Chinese authorities likely know far more than we have been able to glean from public materials and remote measurements. On the other hand, there is considerable opportunity for the academic research community to improve the airport ecosystem and build the next generation of circumvention tools that better protect users. Given this tradeoff, we argue that it is most beneficial to users to publish our investigation. In the remainder of the section, we discuss specific tradeoffs and how we limit risk to specific individuals and airports.
Survey Participants. Our survey asked participants to describe experiences with tools that may be legally sensitive. To reduce risk, we conducted the survey anonymously using a U.S.-based platform, did not collect personally identifying information, allowed participants to skip any question, and did not provide compensation that might pressure participation or would have required additional tracking. The survey and consent materials were reviewed and approved by the Institutional Review Board at the institution where the survey was conducted and analyzed. We do not release raw survey responses; the paper includes only aggregated results and short anonymized excerpts. Airport Services. Our active measurements used subscriptions we purchased through normal customer channels and stayed within provider-enforced bandwidth limits. To reduce the risk of disrupting service, throughput tests downloaded 50 MB objects and were limited to a small purchased sample of airports. Our measurements may still have imposed some load on airport infrastructure, but the traffic volume was designed to resemble ordinary paid use. To prevent increased risk to any specific airport, we anonymized the specific airports we used and we are not publishing the fingerprints we developed for identifying airports. Censorship Measurements. Testing access to sensitive destinations can create risk if requests are issued from uninvolved hosts or exposed to local network monitors. However, airports are specifically designed to enable access to censored content, and, as we show, block access to content they deem too risky. We conducted experiments from infrastructure registered under the name of a non-Chinese researcher who was aware of the associated risk. Public Telegram Channels. Table 1 identifies seven public Telegram promotion channels by handle. We weighed the reproducibility benefit against the risk of creating a durable pointer for adversaries. We include the handles because these channels are public, have more than 5,000 members each, are trivially discoverable through Telegram search using the keyword “机场,”. We do not identify individual operators or moderators, and we withhold the discovered airport portal list and scanning fingerprints. Researcher Safety. Purchasing subscriptions through payment channels such as Alipay carries risk because transactions are tied to an individual’s identity, which could create legal or personal risk for researchers or collaborators with ties to China. When paid subscriptions were necessary, we used credentials belonging to a person who neither resides in nor is a citizen of China. Additionally, we created an email address used solely for this study to reduce the identifying information exposed to airport operators.
Appendix B. Artifact Availability We will provide anonymized artifacts for review to the extent legally and ethically possible. The shared artifacts
include sanitized analysis code, aggregate measurement outputs, and documentation sufficient to evaluate the methodology. We withhold raw survey responses, Telegram histories, the list of airport portals, purchased subscription credentials, and fingerprinting code that would enable bulk discovery of airport infrastructure. These exclusions protect the studied ecosystem. The current anonymized artifact package is available at: https://anonymous.4open.science/r/airportecosystem-artifacts-616A
Appendix C. Generative AI Usage Generative AI was used for editorial purposes in this manuscript, and all outputs were inspected by the authors to ensure accuracy and originality.
Appendix D. Survey Details Participants had the option of viewing the survey in Simplified Chinese (default) or English. The following consent form and questions are presented as they appeared in the English version of the survey. Consent Form DESCRIPTION: You are invited to participate in a research study on how people circumvent China’s Internet censorship system. We are a team of anti-censorship researchers from Stanford University, the University of Colorado Boulder, and GFW Report. Our goal is to better understand and improve the circumvention ecosystem. If you use VPNs, proxies, and/or any other censorship circumvention tools to get around the Great Firewall (GFW), we would greatly appreciate your help by filling out a short anonymous survey. The survey will ask about your experiences and methods for bypassing censorship. Please note that the survey is completely anonymous, and no personally identifiable information will be collected. The data collected will be used to enhance our understanding and will contribute to developing more effective circumvention tools. Our study has been reviewed and approved by the Stanford University Institutional Review Board (IRB). TIME INVOLVEMENT: Your participation will take approximately 5 minutes. PAYMENTS: You will not receive payment for your participation. RISKS AND BENEFITS: There is no foreseeable risk in this study. Study data will be stored securely, in compliance with Stanford University standards, minimizing the risk of confidentiality breach. The benefits which may reasonably be expected to result from this study are a better understanding and improvement of the circumvention ecosystem. We cannot and do not guarantee or promise that you will receive any benefits from this study. PARTICIPANT’S RIGHTS: If you have read this form and have decided to participate in this project, please understand
your participation is voluntary and you have the right to withdraw your consent or discontinue participation at any time without penalty or loss of benefits to which you are otherwise entitled. The alternative is not to participate. You have the right to refuse to answer particular questions. The results of this research study may be presented at scientific or professional meetings or published in scientific journals. Your individual privacy will be maintained in all published and written data resulting from the study. Questions 1. How do you get censorship circumvention services these days? • Purchase Commercial VPN (ExpressVPN, Astrill VPN, NordVPN, SurfsharkVPN, ProtonVPN, 老王VPN, etc.) • Purchase “Airport” subscriptions • I set up circumvention services myself • My friend or family shared with me • Psiphon3 • Lantern • Tor • Geph • Cloudflare Warp 1.1.1.1 • FreeGate/UltraSurf • I don’t know • Other (specify) • Refuse to answer 2. How much do you approximately pay to circumvent each month (in RMB)? (Enter -1 if you refuse to answer) 3. Where did you hear about the “airports” you’ve used? 5 • From family or friend • Telegram Groups • WeChat Group • Internet Search • I do not remember • Other (specify) • Refuse to answer 4. Why do you choose to use the current circumvention tools? • This is one of those available to me • This is one of those I know how to use • It is relatively cheaper • It is relatively faster • It is relatively more stable • It is relatively easier to configure • Other (specify) • Refuse to answer 5. How long does your proxy typically work uninterrupted in the last two years (before you have to purchase/install/configure a new one)? • Up to 1 hour • Less than 1 day • Less than 1 week • Less than 1 month • Less than 3 months 5. This question only appeared if the respondent had chosen ‘Purchase “Airport” subscriptions’ in Question 1.
Less than 6 months Less than 9 months • Less than 1 year • More than 1 year • I don’t know • Other (specify) • Refuse to answer 6. What protocols do you use to bypass censorship? • I don’t know • Shadowsocks • ShadowsocksR • Hysteria2 • Naiveproxy • Trojan • VMess • VLESS • Wireguard • TUIC • Juicity • SSH • Snell • Brook • Socks5 • HTTP • Others (please specify) • Refuse to answer 7. What are the challenges or incovenience you face with your current censorship circumvention setup? (Enter -1 if you refuse to answer) • •
Appendix E. Measured Airports Table 7 details the characteristics of the airports in our dataset, where an age marked ‘N/A’ signifies that the airport was not found in the Telegram channels we analyzed. TABLE 7. A IRPORTS IN OUR DATASET AND THEIR CHARACTERISTICS —Some airports with their age marked ‘N/A’ may have been present on Telegram with a different TLD (e.g., example.com and example.xyz), but for consistency, we consider different domains to be different airports, even if they potentially have the same backend. Airport
$/TB Date
Airport
$/TB Date
Inexpensive 1 Inexpensive 2 Inexpensive 3 Midprice 1 Midprice 2 Midprice 3 Expensive 1 Expensive 2 Expensive 3 Scan 1 Scan 2 Scan 3 Scan 4 Scan 5 Scan 6 Scan 7 Scan 8 Scan 9
0.45 0.44 0.17 10.3 9.92 10.7 27.35 12.11 28.44 7.29 1.09 23.83 11.64 14.1 12.15 7.29 1.12 5.83
Young 1 Young 2 Young 3 Middle-aged 1 Middle-aged 2 Middle-aged 3 Old 1 Old 2 Old 3 Popular 1 Popular 2 Popular 3 Popular 4 Popular 5 Popular 6 Popular 7 Popular 8
15.8 21.01 11.4 36.47 21.01 10.95 14.59 12.15 21.88 26.8 21.15 15.75 16.48 5.11 0.97 7.24 12.16
2022-03-06 N/A N/A N/A N/A N/A 2022-02-28 N/A 2023-01-30 N/A N/A N/A N/A N/A N/A N/A N/A N/A
2024-12-24 2024-09-24 2024-09-22 2022-04-05 2022-04-06 2022-03-31 2020-04-10 2019-12-18 2020-04-12 2023-10-24 2022-02-24 N/A 2024-01-10 N/A 2022-02-25 N/A 2022-02-25