Rate-Distortion Function for Encrypted Traffic Side-Channel Defense

📅 2026-07-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses a critical gap in existing encrypted traffic defenses: the absence of a computable and provable lower bound on information leakage under quality-of-service cost constraints. Modeling semantic label sequences as a source and post-defense feature sequences as observations, the study introduces and fully characterizes, for the first time within the class of i.i.d. defenses, a side-channel rate–distortion function where defense cost is measured by the Wasserstein-1 distance. Leveraging information theory, optimal transport, and convex optimization, the authors reveal that optimal defenses exhibit an exponential tilting structure and form a Pareto frontier, and they derive the maximum distortion for binary symmetric-prior tasks. Experiments demonstrate that state-of-the-art schemes—Front, WTF-PAD, and TrafficSliver—exhibit information leakage gaps of 0.028, 0.034, and 0.124 bits, respectively, from the theoretical optimum.
📝 Abstract
Parameter selection for encrypted traffic defense has long relied on empirical tuning, yet the fundamental question -- \emph{given a QoS cost budget $D$, how low can the leakage rate go under sustained observation?} -- lacks a provable, computable baseline. Taking the semantic label sequence $X^n$ as the source, the defended feature sequence $Y^n$ as the observation, and Wasserstein-1 distance as the defense cost, we define the \emph{side-channel rate-distortion function} $R^{\mathrm{sc}}(D)$ within the stationary memoryless defense class $Θ_{\mathrm{iid}}$ and provide its complete characterization. We prove that $R^{\mathrm{sc}}(D)$ is monotone decreasing, convex, and continuous, with exact endpoints; the optimal defense has an exponential-tilting (Boltzmann) structure governed by KKT conditions; and the curve constitutes the exact Pareto frontier within $Θ_{\mathrm{iid}}$. For binary equal-prior tasks, $D_{\max} = \tfrac{1}{2}W_1(P_0,P_1)$ via Kantorovich--Rubinstein duality. On real-world website-fingerprinting defenses, the framework locates Front ($Δ_{\mathrm{gap}}{=}0.028$\,bits), WTF-PAD ($0.034$\,bits), and TrafficSliver ($0.124$\,bits) above the theoretical curve, quantifying their suboptimality gaps.
Problem

Research questions and friction points this paper is trying to address.

side-channel defense
rate-distortion function
encrypted traffic
information leakage
Wasserstein distance
Innovation

Methods, ideas, or system contributions that make the work stand out.

side-channel rate-distortion
encrypted traffic defense
Wasserstein-1 distance
Pareto frontier
exponential tilting
🔎 Similar Papers
No similar papers found.