Rate-Distortion Function for Encrypted Traffic Side-Channel Defense
Abstract
Parameter selection for encrypted traffic defense has long relied on empirical tuning, yet the fundamental question -- \emph{given a QoS cost budget , how low can the leakage rate go under sustained observation?} -- lacks a provable, computable baseline. Taking the semantic label sequence as the source, the defended feature sequence as the observation, and Wasserstein-1 distance as the defense cost, we define the \emph{side-channel rate-distortion function} within the stationary memoryless defense class and provide its complete characterization. We prove that is monotone decreasing, convex, and continuous, with exact endpoints; the optimal defense has an exponential-tilting (Boltzmann) structure governed by KKT conditions; and the curve constitutes the exact Pareto frontier within . For binary equal-prior tasks, via Kantorovich--Rubinstein duality. On real-world website-fingerprinting defenses, the framework locates Front (\,bits), WTF-PAD (\,bits), and TrafficSliver (\,bits) above the theoretical curve, quantifying their suboptimality gaps.
Cite
@article{arxiv.2607.17889,
title = {Rate-Distortion Function for Encrypted Traffic Side-Channel Defense},
author = {Guangjie Liu and Guang Cheng and Weiwei Liu and Yutong Wang},
journal= {arXiv preprint arXiv:2607.17889},
year = {2026}
}