合成具有差分隐私形式保证的概率饱和计数器
Synthesizing Probabilistic Saturating Counters with Differentially Private Formal Guarantees
浏览论文内容
中文总结 AI 辅助
本文基于差分隐私对概率饱和计数器开展形式分析,推导最优攻击策略并合成满足目标纯DP保证的增强型PSC参数,验证其在提供形式安全保证的同时保持了有竞争力的预测性能。
中文摘要 AI 辅助
分支预测器可提升现代处理器的指令级并行度,通常用饱和计数器建模。但经典饱和计数器是确定性的,易受侧信道攻击:攻击者可操纵计数器状态,推断受害进程的分支方向。概率饱和计数器(Probabilistic Saturating Counters, PSCs)被提出以通过随机化计数器更新缓解这种信息泄漏,但现有评估主要是经验性的。本文基于差分隐私(Differential Privacy, DP)开展形式分析:将PSCs及对应的Prime+Probe攻击策略建模为概率Moore机,推导最优攻击策略,通过DP量化攻击者的区分能力。该DP保证适用于Prime+Probe观测模型下的PSC原语;针对完整分支预测器在重复或自适应攻击下的端到端安全性是未来重要研究方向。随后,本文为增强型PSC合成满足目标纯DP保证的参数。为评估效用,本文推导了稳态误预测率,并在基准程序上验证理论预测。与确定性及现有概率饱和计数器相比,合成的PSCs提供形式化安全保证,同时保持有竞争力的预测性能。
英文摘要
Branch predictors improve instruction-level parallelism in modern processors and are commonly modeled using saturating counters. However, classical saturating counters are deterministic and thus vulnerable to side-channel attacks: an attacker can manipulate the counter state and infer the branch direction of a victim process. Probabilistic saturating counters (PSCs) have been proposed to mitigate this leakage by randomizing counter updates, but existing evaluations are mainly empirical. In this paper, we give a formal analysis based on differential privacy (DP): we model PSCs and the corresponding Prime+Probe attack strategies as probabilistic Moore machines, derive optimal attack strategies, and quantify the attacker's distinguishing power through DP. Our DP guarantee applies to the PSC primitive under the Prime+Probe observation model; end-to-end security for a full branch predictor under repeated or adaptive attacks is an important direction for future work. We then synthesize parameters for an enhanced PSC that satisfies a target pure DP guarantee. To evaluate utility, we derive the stationary misprediction rate and validate the theoretical predictions on benchmark programs. Compared to deterministic and existing probabilistic saturating counters, the synthesized PSCs provide formal security guarantees while preserving competitive prediction performance.