发表机构
Nanjing University of Information Science and Technology; Southeast University; Nanjing University of Science and Technology(南京信息工程大学; 东南大学; 南京理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
将侧信道存在定理推广至多类,通过逐类分解和Wasserstein约束证明加密流量侧信道泄漏不可避免,并在95类数据集上验证。
AI 中文摘要
侧信道存在定理证明了在二元、无防御设定下 $I(X;Y)>0$,但该定理仅限于成对论证且忽略了主动防御。我们通过逐类分解 $I(X;Y)=\sum_i\pi_i D_{\mathrm{KL}}(P_{Y|i}\\|P_Y)$ 将其推广到 $k$ 类,其中防御成本由逐类 Wasserstein-1 约束 $\sup_x W_1(Q_x^D,P_x)\le B$ 建模。由此得到三个结果:(1) 所有活跃类上的求和形式互信息下界;(2) 级联临界成本定理及逐类预算推论,在均匀预算界消失处非零;(3) 精度推论 $\mathrm{Acc}^*\ge 2^{I_0}/k>1/k$。在 95 类网站指纹识别数据集上,所有测试防御下测得的互信息具有严格为正的 95% 置信下界。与最强的成对基线——一个覆盖所有 $\binom{k}{2}$ 三角形约束的凸规划,在相同非消失间隙条件下同样为 $\Theta(1)$ 于 $k$——相比,求和形式仅强 $1.45\times$,因此逐类分解的理由是结构性的:只有它能给每个类提供临界成本和级联。FRONT 表观 $122\times$ 的差距主要源于阈值排除而非不等式链:在活跃类上为 $21\times$,与测得的无防御 $15\times$ 相差在 $1.4\times$ 以内。分别测量链的两步,将坍缩到单个 Lipschitz 统计量的下界限制为 $28\times$,而测得的散度步为 $1.5\times$。无防御的 OVR 可区分性预测防御后逐类泄漏的 Spearman $\rho=0.62$–$0.77$,这是认证程序所依赖的迁移。该框架原样适用于 100 类 QUIC/TCP 对。
英文摘要
The Side-Channel Existence Theorem proves $I(X;Y)>0$ in the binary, undefended setting, but is confined to pairwise arguments and ignores active defenses. We extend it to $k$ classes via the per-class decomposition $I(X;Y)=\sum_iπ_i D_{\mathrm{KL}}(P_{Y|i}\|P_Y)$, with defense cost modelled by per-class Wasserstein-1 constraints $\sup_x W_1(Q_x^D,P_x)\le B$. Three results follow: (1) a summation-form MI lower bound over all active classes; (2) a cascade critical cost theorem and a per-class budget corollary, nonzero where the uniform-budget bound vanishes; (3) an accuracy corollary $\mathrm{Acc}^*\ge 2^{I_0}/k>1/k$. On a 95-class website fingerprinting dataset the measured MI has a strictly positive $95\%$ confidence lower bound under every defense tested. Against the strongest pairwise baseline---a convex program over all $\binom{k}{2}$ triangle constraints, also $Θ(1)$ in $k$ under the same non-vanishing-gap conditions---the summation form is only $1.45\times$ stronger, so the case for the per-class decomposition is structural: only it gives each class a critical cost and a cascade. FRONT's apparent $122\times$ gap is inflated mainly by threshold exclusion rather than the inequality chain: on the active classes it is $21\times$, within $1.4\times$ of the $15\times$ measured undefended. Measuring the chain's two steps separately bounds the collapse onto one Lipschitz statistic below by $28\times$, against a divergence step measured at $1.5\times$. Undefended OVR distinguishability predicts post-defense per-class leakage at Spearman $ρ=0.62$--$0.77$, the transfer the certification procedure relies on. The framework carries over unchanged to a 100-class QUIC/TCP pair.