Structural Decomposability of Encrypted Traffic Side-Channel Leakage
cs.CR, cs.IT, math.IT
Submitted: 2026-07-20
Updated: 2026-07-20
License: http://creativecommons.org/licenses/by/4.0/
The gist: Existing side-channel theories treat leakage as a holistic quantity I(X;Y), without characterizing its internal structure.
Abstract
Existing side-channel theories treat leakage as a holistic quantity I(X;Y), without characterizing its internal structure. This paper studies the structural decomposability of encrypted-traffic side-channel leakage. Via the structural causal model X! to!Y size! to!Y dir! to!Y time and the mutual-information chain rule, total leakage is decomposed into three sequential increments for packet size, direction, and timing. Defenses are formalized as mechanism replacement by a strategy variable D; coupling information C size,dir=I(Y size;Y dir! !X) measures inter-dimensional dependence, and the Markov residual gives a testable condition for a single-dimension defense to sever downstream leakage. Causal efficacy η d quantifies per-unit-cost suppression, and a Fisher-geometric approximation I(X;Y) about 1 over 2 2 Tr(GΣ θ) holds under small perturbations. On the Wang dataset (95 websites), Y dir dominates undefended leakage (0.637,bits), while Tor's fixed 512-byte cells make Y size degenerate; FRONT suppresses the direction term by 63%, yet its Markov residual of 0.021,bits (95% CI [0.016,0.027]) shows it cannot sever timing leakage; η dir=0.97 vs. η time about 0 confirms FRONT's design intent. This yields a computable, structured leakage-accounting method for multi-dimensional joint defense design.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs