Table of Contents
Fetching ...

A new measure for dynamic leakage based on quantitative information flow

Luigi D. C. Soares, Mário S. Alvim, Natasha Fernandes

TL;DR

This work addresses the lack of a principled dynamic leakage measure in QIF by introducing a strategy-based dynamic leakage framework. It distinguishes two states of knowledge—the adversary's belief $q$ and a baseline distribution $p$—and defines leakage as the gain-difference of optimal actions guided by $q$ against the baseline, ensuring non-interference and offering relaxed single-step monotonicity and DPI results. The framework recovers static leakage in expectation/max-case and connects to KL-divergence when using Shannon loss, while providing concrete benefits for evaluating privacy-preserving data releases and leakage-tracker-type systems. It also clarifies when multi-step analyses may violate DPI, outlining the practical implications for system design and privacy guarantees. Overall, the approach unifies dynamic and static leakage analyses under a principled, strategy-centric model that aligns with information-theoretic axioms and supports real-world privacy assessments.

Abstract

Quantitative information flow (QIF) is concerned with assessing the leakage of information in computational systems. In QIF there are two main perspectives for the quantification of leakage. On one hand, the static perspective considers all possible runs of the system in the computation of information flow, and is usually employed when preemptively deciding whether or not to run the system. On the other hand, the dynamic perspective considers only a specific, concrete run of the system that has been realised, while ignoring all other runs. The dynamic perspective is relevant for, e.g., system monitors and trackers, especially when deciding whether to continue or to abort a particular run based on how much leakage has occurred up to a certain point. Although the static perspective of leakage is well-developed in the literature, the dynamic perspective still lacks the same level of theoretical maturity. In this paper we take steps towards bridging this gap with the following key contributions: (i) we provide a novel definition of dynamic leakage that decouples the adversary's belief about the secret value from a baseline distribution on secrets against which the success of the attack is measured; (ii) we demonstrate that our formalisation satisfies relevant information-theoretic axioms, including non-interference and relaxed versions of monotonicity and the data-processing inequality (DPI); (iii) we identify under what kind of analysis strong versions of the axioms of monotonicity and the DPI might not hold, and explain the implications of this (perhaps counter-intuitive) outcome; (iv) we show that our definition of dynamic leakage is compatible with the well-established static perspective; and (v) we exemplify the use of our definition on the formalisation of attacks against privacy-preserving data releases.

A new measure for dynamic leakage based on quantitative information flow

TL;DR

This work addresses the lack of a principled dynamic leakage measure in QIF by introducing a strategy-based dynamic leakage framework. It distinguishes two states of knowledge—the adversary's belief and a baseline distribution —and defines leakage as the gain-difference of optimal actions guided by against the baseline, ensuring non-interference and offering relaxed single-step monotonicity and DPI results. The framework recovers static leakage in expectation/max-case and connects to KL-divergence when using Shannon loss, while providing concrete benefits for evaluating privacy-preserving data releases and leakage-tracker-type systems. It also clarifies when multi-step analyses may violate DPI, outlining the practical implications for system design and privacy guarantees. Overall, the approach unifies dynamic and static leakage analyses under a principled, strategy-centric model that aligns with information-theoretic axioms and supports real-world privacy assessments.

Abstract

Quantitative information flow (QIF) is concerned with assessing the leakage of information in computational systems. In QIF there are two main perspectives for the quantification of leakage. On one hand, the static perspective considers all possible runs of the system in the computation of information flow, and is usually employed when preemptively deciding whether or not to run the system. On the other hand, the dynamic perspective considers only a specific, concrete run of the system that has been realised, while ignoring all other runs. The dynamic perspective is relevant for, e.g., system monitors and trackers, especially when deciding whether to continue or to abort a particular run based on how much leakage has occurred up to a certain point. Although the static perspective of leakage is well-developed in the literature, the dynamic perspective still lacks the same level of theoretical maturity. In this paper we take steps towards bridging this gap with the following key contributions: (i) we provide a novel definition of dynamic leakage that decouples the adversary's belief about the secret value from a baseline distribution on secrets against which the success of the attack is measured; (ii) we demonstrate that our formalisation satisfies relevant information-theoretic axioms, including non-interference and relaxed versions of monotonicity and the data-processing inequality (DPI); (iii) we identify under what kind of analysis strong versions of the axioms of monotonicity and the DPI might not hold, and explain the implications of this (perhaps counter-intuitive) outcome; (iv) we show that our definition of dynamic leakage is compatible with the well-established static perspective; and (v) we exemplify the use of our definition on the formalisation of attacks against privacy-preserving data releases.
Paper Structure (25 sections, 26 theorems, 103 equations, 4 figures)

This paper contains 25 sections, 26 theorems, 103 equations, 4 figures.

Key Result

Lemma 1

For any prior knowledge $\IfNoValueTF{-NoValue-} {\pi} {\pi^{\textnormal{-NoValue-}}}: \mathbb{D}\mathcal{X}$ and channel $\IfNoValueTF{-NoValue-} {\mathrm{C}} {\mathrm{C}^{\textnormal{-NoValue-}}}: \mathcal{X} \to \mathbb{D}\mathcal{Y}$, it follows that both the strategy-based dynamic prior $\ell_{

Figures (4)

  • Figure 1: Pipeline $\IfNoValueTF{-NoValue-} {\mathrm{P}} {\mathrm{P}^{\textnormal{-NoValue-}}}\mathbin{;} \IfNoValueTF{-NoValue-} {\mathrm{S}} {\mathrm{S}^{\textnormal{-NoValue-}}}$ for Example \ref{['ex:motivation:query']}, considering as input the answer no and as final output the answer no. The outgoing black arrows correspond to the case where the mechanism preserved the answer, whereas the outgoing (blue) dashed arrows indicate that the answer was flipped. The probability of an output no when its input is no is $2/3 \cdot 1 + 1/3 \cdot 1/2 = 5/6$.
  • Figure 2: The semantics of analyses related to adversaries $\mathscr{A}^{ \IfNoValueTF{-NoValue-} {\mathrm{P}} {\mathrm{P}^{\textnormal{-NoValue-}}}}$ (upper diagram in each figure) and $\mathscr{A}^{ \IfNoValueTF{-NoValue-} {\mathrm{S}} {\mathrm{S}^{\textnormal{-NoValue-}}}}$ (lower diagram) from Example \ref{['ex:motivation:query']}. In each figure, the vertical dotted line delimits the section of the pipeline that is common to both adversaries. Multiple arrows indicate a "static" input (respectively, output), meaning that the system takes as input (produces as output) a probability distribution over all possible values. A single arrow indicates a concrete, single execution of the system.
  • Figure 3: Attack model against privacy-preserving data releases.
  • Figure 4: The semantics of single- and multi-step analysis with respect to adversaries $\mathscr{A}^{ \IfNoValueTF{-NoValue-} {\mathrm{C}} {\mathrm{C}^{\textnormal{-NoValue-}}}}$ (upper diagram in each figure), who observes an output $y \in \mathcal{Y}$ from system $\IfNoValueTF{-NoValue-} {\mathrm{C}} {\mathrm{C}^{\textnormal{-NoValue-}}}= \IfNoValueTF{-NoValue-} {\mathrm{B}} {\mathrm{B}^{\textnormal{-NoValue-}}}\mathbin{;} \IfNoValueTF{-NoValue-} {\mathrm{R}} {\mathrm{R}^{\textnormal{-NoValue-}}}$, and $\mathscr{A}^{ \IfNoValueTF{-NoValue-} {\mathrm{D}} {\mathrm{D}^{\textnormal{-NoValue-}}}}$ (lower diagram), who observes $z \in \mathcal{Z}$ from system $\IfNoValueTF{-NoValue-} {\mathrm{D}} {\mathrm{D}^{\textnormal{-NoValue-}}}= \IfNoValueTF{-NoValue-} {\mathrm{C}} {\mathrm{C}^{\textnormal{-NoValue-}}}\mathbin{;} \IfNoValueTF{-NoValue-} {\mathrm{S}} {\mathrm{S}^{\textnormal{-NoValue-}}}$.

Theorems & Definitions (53)

  • Definition 1: Cascade QIF-Book:Alvim2020
  • Remark 1
  • Definition 2: Prior measurements
  • Definition 3: Traditional dynamic posterior measurements
  • Definition 4: Traditional dynamic leakage
  • Definition 5: Static posterior measurements
  • Definition 6: Static leakage
  • Definition 7: Refinement
  • Definition 8: Adversarial strategy
  • Remark 2
  • ...and 43 more