Search papers, labs, and topics across Lattice.
This paper establishes a side-channel rate-distortion function \( R^{\mathrm{sc}}(D) \) for encrypted traffic defense, addressing the critical question of minimizing leakage rates under a given quality of service (QoS) cost budget. By employing Wasserstein-1 distance as the defense cost and characterizing the function's properties, the authors demonstrate that the optimal defense strategy follows an exponential-tilting structure, revealing the exact Pareto frontier for stationary memoryless defenses. The findings highlight the suboptimality of existing real-world defenses, quantifying their performance gaps relative to the theoretical limits established by the new framework.
Existing defenses for encrypted traffic can be up to 0.124 bits away from optimal performance, revealing significant room for improvement in side-channel security.
Parameter selection for encrypted traffic defense has long relied on empirical tuning, yet the fundamental question -- \emph{given a QoS cost budget $D$, how low can the leakage rate go under sustained observation?} -- lacks a provable, computable baseline. Taking the semantic label sequence $X^n$ as the source, the defended feature sequence $Y^n$ as the observation, and Wasserstein-1 distance as the defense cost, we define the \emph{side-channel rate-distortion function} $R^{\mathrm{sc}}(D)$ within the stationary memoryless defense class $\Theta_{\mathrm{iid}}$ and provide its complete characterization. We prove that $R^{\mathrm{sc}}(D)$ is monotone decreasing, convex, and continuous, with exact endpoints; the optimal defense has an exponential-tilting (Boltzmann) structure governed by KKT conditions; and the curve constitutes the exact Pareto frontier within $\Theta_{\mathrm{iid}}$. For binary equal-prior tasks, $D_{\max} = \tfrac{1}{2}W_1(P_0,P_1)$ via Kantorovich--Rubinstein duality. On real-world website-fingerprinting defenses, the framework locates Front ($\Delta_{\mathrm{gap}}{=}0.028$\,bits), WTF-PAD ($0.034$\,bits), and TrafficSliver ($0.124$\,bits) above the theoretical curve, quantifying their suboptimality gaps.