In the Tor network, each client maintains a small set of guard relays that serve as the first hop in all circuits. For hidden services, if an attacker can identify which guard relay your service uses, they significantly narrow the pool of possible server locations. Advanced attackers can then perform traffic analysis on the guard relay to identify your actual IP address.
Guard discovery attacks typically work by creating many circuits to your .onion address and analyzing timing patterns, or by running malicious relays that attempt to become your middle nodes. Once enough circuits are observed, statistical analysis can reveal the guard relay with high confidence.
The Vanguards addon addresses this by adding an additional layer of pinned relays (called vanguards) between your guard and the rendezvous point. It also detects and closes circuits that exhibit suspicious behavior, such as those that might be used for traffic analysis. Since Tor 0.4.7, basic vanguard functionality (vanguards-lite) is built into the Tor daemon, but the full Vanguards addon provides more comprehensive protection.