English

Rate-Distortion Function for Encrypted Traffic Side-Channel Defense

Cryptography and Security 2026-07-20 v1

Abstract

Parameter selection for encrypted traffic defense has long relied on empirical tuning, yet the fundamental question -- \emph{given a QoS cost budget DD, how low can the leakage rate go under sustained observation?} -- lacks a provable, computable baseline. Taking the semantic label sequence XnX^n as the source, the defended feature sequence YnY^n as the observation, and Wasserstein-1 distance as the defense cost, we define the \emph{side-channel rate-distortion function} Rsc(D)R^{\mathrm{sc}}(D) within the stationary memoryless defense class Θiid\Theta_{\mathrm{iid}} and provide its complete characterization. We prove that Rsc(D)R^{\mathrm{sc}}(D) is monotone decreasing, convex, and continuous, with exact endpoints; the optimal defense has an exponential-tilting (Boltzmann) structure governed by KKT conditions; and the curve constitutes the exact Pareto frontier within Θiid\Theta_{\mathrm{iid}}. For binary equal-prior tasks, Dmax=12W1(P0,P1)D_{\max} = \tfrac{1}{2}W_1(P_0,P_1) via Kantorovich--Rubinstein duality. On real-world website-fingerprinting defenses, the framework locates Front (Δgap=0.028\Delta_{\mathrm{gap}}{=}0.028\,bits), WTF-PAD (0.0340.034\,bits), and TrafficSliver (0.1240.124\,bits) above the theoretical curve, quantifying their suboptimality gaps.

Cite

@article{arxiv.2607.17889,
  title  = {Rate-Distortion Function for Encrypted Traffic Side-Channel Defense},
  author = {Guangjie Liu and Guang Cheng and Weiwei Liu and Yutong Wang},
  journal= {arXiv preprint arXiv:2607.17889},
  year   = {2026}
}