Rate-Distortion Function for Encrypted Traffic Side-Channel Defense

arXiv:2607.17889 · cs.CR · Submitted 2026-07-20 · Read on arXiv

Guangjie Liu, Guang Cheng, Weiwei Liu, Yutong Wang

cs.CR

Submitted: 2026-07-20

License: http://creativecommons.org/licenses/by/4.0/

The gist: Parameter selection for encrypted traffic defense has long relied on empirical tuning, yet the fundamental question -- given a QoS cost budget D, how low can the leakage rate go under sustained

Terminology

Abstract

Parameter selection for encrypted traffic defense has long relied on empirical tuning, yet the fundamental question -- given a QoS cost budget D, how low can the leakage rate go under sustained observation? -- lacks a provable, computable baseline. Taking the semantic label sequence X n as the source, the defended feature sequence Y n as the observation, and Wasserstein-1 distance as the defense cost, we define the side-channel rate-distortion function R sc(D) within the stationary memoryless defense class iid and provide its complete characterization. We prove that R sc(D) is monotone decreasing, convex, and continuous, with exact endpoints; the optimal defense has an exponential-tilting (Boltzmann) structure governed by KKT conditions; and the curve constitutes the exact Pareto frontier within iid. For binary equal-prior tasks, D = 2 W 1(P 0,P 1) via Kantorovich--Rubinstein duality. On real-world website-fingerprinting defenses, the framework locates Front (gap = 0.028,bits), WTF-PAD (0.034,bits), and TrafficSliver (0.124,bits) above the theoretical curve, quantifying their suboptimality gaps.

Sources

Related papers