argante Mullvad DAITA or NymVPN offer some protection against packet analysis. Tor offers nothing.
TOR introduced packet padding and circuits in 2019 to be more resilient against network analysis.
You can read more here.
In this study we can read how this update has been significant against network analysis.
I understand that since 2021 machine learning became better and new techniques are available now, but I cannot find a reputable source to understand to what extent these techniques are efficient.
Every study I found, is based on a reproduction of TOR, and not on real life data, so it is difficult to calculate their actual cost, both in term of time and money.
Most of the attacks involve at least 1 malicious node (usually 2), and TOR project already took care of lowering the probability of using one in 2013, as already noticed in this analysis.
I think most of the identifications are due to fingerprinting, possibly leaving the browser as the weakest link of the chain (after the user, of course).
This is the only project I found suggesting they can systematically correlate traffic.
This project involve people having both enter and exit nodes receiving the traffic to correlate.
I still fail to understand how much time is needed for this to work.
Also, in here we can read as TOR will give less probability to slower nodes to be part of a path, with the (maybe wanted, maybe not) consequence of preferring nodes that cost more, as more money can buy better hardware.
This means that people like me will never be able to conduct a good study and/or understand how easier will be for govs / big hacker groups to achieve the same goal.
Honestly, I stopped using TOR long time ago, and I now leverage Mullvad only, but I am just trying to rising my privacy, anonymity is not in the equation.
Would be nice to have a better picture in services like TOR, i2p and the like.