Accounting for Missing Events in Statistical Information Leakage Analysis
Seongmin Lee, Shreyas Minocha, Marcel Böhme
摘要
The leakage of secret information via a public channel is a critical privacy flaw in software systems. The more information is leaked per observation, the less time an attacker needs to learn the secret. Due to the size and complexity of the modern software, and because some empirical facts are not available for a formal analysis of the source code, researchers started investigating statistical methods using program executions as samples. However, current statistical methods require a high sample coverage. Ideally, the sample is large enough to contain every possible combination of secret <tex xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink"></tex> observable value to accurately reflect the joint distribution of (secret, observable). Otherwise, the information leakage is severely underestimated, which is problematic as it can lead to overconfidence in the security of an otherwise vulnerable program. In this paper, we introduce an improved estimator for information leakage and propose to use methods from applied statistics to improve our estimate of the joint distribution when sample coverage is low. The key idea is to reconstruct the joint distribution by casting our problem as a multinomial estimation problem in the absence of samples for all classes. We suggest two approaches and demonstrate the effectiveness of each approach on a set of benchmark subjects. We also propose novel refinement heuristics, which help to adjust the joint distribution and gain better estimation accuracy. Compared to existing statistical methods for information leakage estimation, our method can safely overestimate the mutual information and provide a more accurate estimate from a limited number of program executions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Dependency-aware Residual Risk AnalysisSeongmin Lee, Marcel BöhmeICSE 2026
- How Much is Unseen Depends Chiefly on Information About the SeenSeongmin Lee, Marcel BöhmeICLR 2025
它引用的顶会 Paper10
- Back to the Drawing Board: Revisiting the Design of Optimal Location Privacy-preserving MechanismsSimon Oya, Carmela Troncoso, Fernando Pérez-GonzálezCCS 2017 · 被引用 80 次
- F-BLEAU: Fast Black-Box Leakage EstimationGiovanni Cherubin, Konstantinos Chatzikokolakis, Catuscia PalamidessiS&P 2019 · 被引用 38 次
- Estimating residual risk in greybox fuzzingMarcel Böhme, Danushka Liyanage, Valentin WüstholzFSE 2021 · 被引用 27 次
- Estimating g-Leakage via Machine LearningMarco Romanelli, Konstantinos Chatzikokolakis, Catuscia Palamidessi, Pablo PiantanidaCCS 2020 · 被引用 15 次
- QFuzz: quantitative fuzzing for side channelsYannic Noller, Saeid Tizpaz-NiariISSTA 2021 · 被引用 15 次
相关 Paper
- Reachable Coverage: Estimating Saturation in FuzzingDanushka Liyanage, Marcel Böhme, Chakkrit Tantithamthavorn, Stephan LippICSE 2023 · 被引用 14 次
- Abacus: Precise Side-Channel AnalysisQinkun Bao, Zihao Wang, Xiaoting Li, James R. Larus 等ICSE 2021 · 被引用 19 次
- Obtaining Information Leakage Bounds via Approximate Model CountingSeemanta Saha, Surendra Ghentiyala, Shihua Lu, Lucas Bang 等PLDI 2023 · 被引用 11 次
- Statistical Reachability AnalysisSeongmin Lee, Marcel BöhmeFSE 2023 · 被引用 12 次
- Risk Estimation in Differential Fuzzing via Extreme Value TheoryRafael Baez, Alejandro Olivas, Nathan K. Diamond, Marcelo F. Frias 等ASE 2025
