Sourcing content from a .onion service?

I understand that it is possible to use CloudFlare’s Onion Service (link) to protect ToR users from a needless loop to the Internet (from random exit node to CloudFlare) when the destination site is ultimately a CloudFlare subscriber (ToR user -> CloudFlare site), but I’m curious if it is possible to invert this?

Internet user hits CloudFlare and traffic is backhauled across ToR. For sites infrequently visited (out of cache) isn’t there a correlation attack for an adversary monitoring both the front (user -> CDN) and rear (CDN-> origin site) connections?

Allowing backhauling across ToR would ameliorate this to some degree (two layers instead of one).


