Synthesizing Probabilistic Saturating Counters with Differentially Private Formal Guarantees
This work addresses the vulnerability of conventional deterministic saturating counters to side-channel attacks, wherein adversaries can infer branch directions through Prime+Probe observations. For the first time, the paper models probabilistic saturating counters as probabilistic Moore machines and formally analyzes their security within a differential privacy framework. By leveraging steady-state analysis of Markov chains and parameter synthesis, the authors derive optimal attack strategies and automatically synthesize counter parameters that satisfy pure differential privacy guarantees. The proposed approach provides provable privacy protection while maintaining branch prediction accuracy comparable to existing schemes, with theoretical misprediction rates validated on benchmark programs.