AI 中文总结
研究加密流量防御中给定QoS成本预算下的泄漏率问题,定义边信道率失真函数R^(sc)(D)并完整表征其特性,给出最优防御结构,还通过实际网站指纹识别防御量化了一些方法与理论曲线的差距。
AI 中文摘要
长期以来,加密流量防御的参数选择依赖于经验调整,然而一个基本问题,即在给定QoS成本预算D的情况下,持续观测下泄漏率能有多低,缺乏可证明、可计算的基线。我们将语义标签序列X^n作为源,将防御后的特征序列Y^n作为观测,以Wasserstein-1距离作为防御成本,在平稳无记忆防御类Θ_iid中定义了边信道率失真函数R^(sc)(D)并给出完整表征。我们证明了R^(sc)(D)的单调性、凸性、连续性等特性,还给出了最优防御结构。对于二元等先验任务,通过Kantorovich-Rubinstein对偶性得到D_max = 1/2W_1(P_0,P_1)。在实际网站指纹识别防御中,该框架量化了一些防御方法与理论曲线的差距。
英文摘要
Parameter selection for encrypted traffic defense has long relied on empirical tuning, yet the fundamental question -- \emph{given a QoS cost budget $D$, how low can the leakage rate go under sustained observation?} -- lacks a provable, computable baseline. Taking the semantic label sequence $X^n$ as the source, the defended feature sequence $Y^n$ as the observation, and Wasserstein-1 distance as the defense cost, we define the \emph{side-channel rate-distortion function} $R^{\mathrm{sc}}(D)$ within the stationary memoryless defense class $Θ_{\mathrm{iid}}$ and provide its complete characterization. We prove that $R^{\mathrm{sc}}(D)$ is monotone decreasing, convex, and continuous, with exact endpoints; the optimal defense has an exponential-tilting (Boltzmann) structure governed by KKT conditions; and the curve constitutes the exact Pareto frontier within $Θ_{\mathrm{iid}}$. For binary equal-prior tasks, $D_{\max} = \tfrac{1}{2}W_1(P_0,P_1)$ via Kantorovich--Rubinstein duality. On real-world website-fingerprinting defenses, the framework locates Front ($Δ_{\mathrm{gap}}{=}0.028$\,bits), WTF-PAD ($0.034$\,bits), and TrafficSliver ($0.124$\,bits) above the theoretical curve, quantifying their suboptimality gaps.