---
title: Secrecy Successful Computation Probability (SSCP)
url: https://www.emergentmind.com/topics/secrecy-successful-computation-probability-sscp
type: topic
---

# Secrecy Successful Computation Probability (SSCP)

Secrecy Successful Computation Probability (SSCP) is a probability-based secrecy metric for whether a protected computation, reconstruction, or offloading task succeeds while secrecy constraints are simultaneously satisfied. In the literature surveyed here, the acronym is used explicitly for a UAV-assisted NOMA-MEC system, where SSCP is defined as the joint probability that deadline-constrained offloading succeeds and secrecy-rate requirements are met for both selected users [2507.08352]. Closely related objects appear without the acronym in earlier information-theoretic work as asymptotically vanishing computation error with vanishing leakage, secure computability thresholds, adversarial decoding-success probabilities, successful-guess exponents, and secrecy-event probabilities such as positive secrecy capacity or non-outage [1603.07227], [1007.2945], [2201.03948], [1203.2456], [1507.02342], [0805.3605], [1506.08606], [1803.00631].

## 1. Conceptual scope and definitional variants

SSCP is not introduced as a single universal formalism across these papers. Instead, the literature contains several mathematically adjacent notions that all couple a notion of success with a secrecy condition. Taken together, these results suggest that SSCP is best understood as a family of secrecy-aware success metrics rather than a single fixed definition.

| Research line | Core success object | Representative papers |
|---|---|---|
| End-to-end secure offloading | Joint probability of deadline satisfaction and secrecy-rate satisfaction | [2507.08352] |
| Secure function computation | Vanishing computation error plus vanishing leakage | [1603.07227], [1007.2945], [2201.03948] |
| Adversarial recovery success | Probability of message decoding, guessing, or reconstruction within distortion | [1203.2456], [1507.02342], [0805.3605] |
| Secrecy-only event probability | Positive secrecy capacity or secrecy non-outage | [1506.08606], [1803.00631] |

The most explicit event-level SSCP definition occurs in the UAV-assisted NOMA-MEC setting, where the metric is already a single probability over communication, secrecy, energy, and latency constraints [2507.08352]. By contrast, the secure computation papers formulate asymptotic reliability and secrecy constraints separately, typically as \(P_e^{(n)} \to 0\) together with a leakage condition such as \(L^{(n)} \to 0\), from which an SSCP-style interpretation is inferred rather than named [1603.07227], [1007.2945], [2201.03948].

A second major branch of the literature measures secrecy through the adversary’s own success probability. In this line, the relevant object is not the legitimate receiver’s success under secrecy, but the eavesdropper’s success in decoding, guessing, or reconstructing a protected target. The resulting metric is operationally close to an SSCP complement: if Eve’s success probability vanishes, secrecy is strong in the recovery sense, even if this does not automatically imply semantic secrecy [1203.2456], [1507.02342], [0805.3605].

## 2. Event structure and mathematical form

The clearest direct SSCP definition is
\[
\mathcal{S}_{s^*}^j=\Pr \left\{ t_{F}^{*\,off}\le {T}_{th},t_{N}^{*\,off}\le {T}_{th}, 
C_{F}^{*\,S}\ge {R}_{F}^{*},C_{N}^{*\,S}\ge {R}_{N}^{*} \right\},
\]
with \(j\in\{1,2\}\) indexing imperfect SIC and perfect SIC, respectively [2507.08352]. This is a joint event over both selected NOMA users. It is not merely a secrecy outage metric and not merely a computation-success metric; it requires simultaneous success of latency-constrained offloading and secrecy-constrained transmission.

Because the offloading time is
\[
t_{\vartheta }^{*\,off}=\frac{\mathcal{C}_{\vartheta }^{*\,off}}{C_{\vartheta }^{*\,U}},
\qquad
R_{\vartheta}^{*}=\frac{\mathcal{C}_{\vartheta}^{*\,off}}{T_{th}},
\]
the timing condition \(t_{\vartheta}^{*\,off}\le T_{th}\) is equivalent to \(C_{\vartheta}^{*\,U}\ge R_\vartheta^*\). The secrecy part is imposed through the per-user secrecy capacity constraint \(C_{\vartheta}^{*\,S}\ge R_\vartheta^*\). In this form, SSCP is already an end-to-end probability of secure and timely task completion rather than a post hoc secrecy qualifier [2507.08352].

In asymptotic secure computation, the event structure is usually split into reliability and leakage. For the binary modulo-2 adder multiple-access wiretap channel, the average probability of computation error is
\[
P_e^{(n)} \coloneqq \Pr\bigl(\psi(Y^n)\neq U^k\bigr),
\]
and an SSCP-style success probability is naturally
\[
P_{\mathrm{succ}}^{(n)}=\Pr\bigl(\psi(Y^n)=U^k\bigr)=1-P_e^{(n)}.
\]
Achievability requires
\[
\lim_{n\to\infty} P_e^{(n)} = 0
\quad\text{and}\quad
\lim_{n\to\infty} L^{(n)} = 0,
\]
so the induced SSCP interpretation is \(P_{\mathrm{succ}}^{(n)}\to 1\) with vanishing source leakage [1603.07227].

A more general two-terminal function-computation framework imposes, in the lossless case,
\[
\Pr\Big[f^n(\widetilde{X}_1^n,\widetilde{X}_2^n,Y^n) \neq \widehat{f^n}\Big] \le \delta,
\]
together with secrecy leakage
\[
\frac{1}{n} I(\widetilde{X}_1^n,\widetilde{X}_2^n,Y^n;W_1,W_2\mid Z^n) \le R_{\text{s}}+\delta,
\]
and privacy leakages to the decoder and to Eve. In the lossy case, exact recovery is replaced by
\[
\mathbb{E}\Big[d(f^n(\widetilde{X}_1^n,\widetilde{X}_2^n,Y^n),\widehat{f^n})\Big]\le D+\delta.
\]
This furnishes an SSCP foundation in which success is exact or distorted function computation under simultaneous secrecy, privacy, and communication constraints [2201.03948].

## 3. Asymptotic secure computation and feasibility thresholds

In secure function computation, SSCP is often implicit in an asymptotic feasibility theorem. For the binary modulo-2 adder multiple-access wiretap channel, the decisive matched case is
\[
U=S_1\oplus \cdots \oplus S_M,
\]
with the source-function independence condition
\[
P_{S_mU}=P_{S_m}P_U,\qquad \forall m=1,\dots,M.
\]
Under these assumptions, the secrecy computation-capacity equals the ordinary computation capacity:
\[
C_{\mathsf{sc}}=C_{\mathsf{c}}=\frac{1-H(p)}{H(U)}.
\]
This means secrecy imposes no rate penalty in the matched setting, no additional randomness is needed at the encoders, and no advantage of the legitimate receiver over the eavesdropper is required; the result is explicitly independent of the eavesdropper crossover parameter \(q\) [1603.07227].

The same paper gives a particularly strong SSCP-style statement. For any rate
\[
R<\frac{1-H(p)}{H(U)},
\]
there exists a code sequence such that \(P_{\mathrm{succ}}^{(n)}\to 1\) and \(L^{(n)}\to 0\). In the achievability proof, the leakage is in fact shown to be identically zero,
\[
L^{(n)}\equiv 0,
\]
under the main theorem’s assumptions. In the noiseless matched case \(p=q=0\), uncoded transmission yields \(P_e^{(n)}\equiv 0\) and \(L^{(n)}\equiv 0\), so successful secure computation is exact in every block [1603.07227].

A broader threshold characterization appears in multiterminal secure computation over public communication. Let \(G=g(X_\mathcal{M})\) and let \(\mathcal A\) be the set of terminals that must compute the function. The fundamental condition is
\[
H(G) < C(\mathcal A; Z_\mathcal M)
\]
for achievability, with converse
\[
H(G)\le C(\mathcal A; Z_\mathcal M).
\]
Here \(C(\mathcal A; Z_\mathcal M)\) is an aided secret-key capacity associated with the secure computation problem. This produces an asymptotic 0/1 law: below the threshold, one can make computation error and leakage both vanish; above it, asymptotic secure computation is impossible [1007.2945].

The privacy-, secrecy-, distortion-, and storage-constrained extension replaces a single feasibility threshold by inner and outer rate regions. The lossless and lossy regions recover earlier results for special cases, including invertible and partially invertible functions and degraded measurement channels. A key limitation is explicit: because the secrecy and privacy rate terms in the outer bounds are generally strictly positive, strong secrecy or strong privacy constraints cannot be satisfied in general. In SSCP terms, this means that high legitimate computation success may coexist with nonzero unavoidable normalized leakage [2201.03948].

## 4. Adversarial success probability and exponent formulations

A distinct but closely related tradition defines secrecy through the eavesdropper’s own success probability. In the Gaussian wiretap channel, one proposal replaces equivocation by block decoding error:
\[
P_e^n(B)\to 0,\qquad P_e^n(E)\to 1.
\]
For Bob’s and Eve’s capacities
\[
C_1 = 0.5 \log \left(1+\frac{P}{\sigma_1^2}\right),
\qquad
C_2 = 0.5 \log \left(1+\frac{P}{\sigma_2^2}\right),
\]
the central statement is that all rates \(0<R<C_1\) are achievable such that Bob decodes reliably and Eve’s MAP decoding error tends to one. In the transparent regime \(C_2<R<C_1\), Eve operates above her channel capacity, and her probability of successful message recovery,
\[
P_c^n(E)=1-P_e^n(E),
\]
vanishes asymptotically. This is directly usable as a message-decoding SSCP complement, but the paper also emphasizes that high decoding error does not imply semantic secrecy or secrecy for arbitrary functions of the message [1203.2456].

A more exact SSCP-like object appears in secrecy measured by the probability of successful reconstruction within distortion. In the no-key model, the secrecy exponent is
\[
E(P,D,D_e)
=
\lim_{n \rightarrow \infty} \max_{\{f_n\}} \min_{\{g_n\}}
-\frac{1}{n}\log
\Pr\!\left(d_e\Big(X^n,g_n(f_n(X^n))\Big)\le D_e\right),
\]
and the paper proves the single-letter characterization
\[
E(P,D,D_e)=\min_Q D(Q\|P)+R(Q,D,D_e).
\]
In the Shannon cipher setting with key rate \(r\), public communication rate \(R\), and legitimate excess-distortion reliability exponent \(\alpha\), the optimal exponent is
\[
E(P,\overrightarrow{D},\overrightarrow{R},\alpha)
=
\min \left\{ E_0(P,D_e),\,
r+\min_{Q:D(Q\|P)\le \alpha} D(Q\|P)+R(Q,R,D,D_e)\right\}.
\]
Here the quantity being exponentiated is exactly the adversary’s successful reconstruction probability within distortion, making this one of the clearest asymptotic foundations for reconstruction-based SSCP [1507.02342].

A third operational formulation is the wiretapper success exponent under a bounded guessing budget. If Eve may make \(\lambda^{(n)}\) guesses to a sequential yes/no verifier, with guessing rate
\[
R_\lambda := \limsup_{n\to\infty}\frac{1}{n}\log \lambda^{(n)},
\]
and success probability \(s_e^{(n)}\), then the secrecy metric is
\[
S_e := \liminf_{n\to\infty} -\frac{1}{n}\log s_e^{(n)}.
\]
This yields an attack-budget interpretation of SSCP: the protected system is secure when the adversary’s success probability within the allowed budget decays exponentially. In the strongly achievable region, a key condition is
\[
R_\lambda < I(\tilde X \wedge Y\mid U)-I(\tilde X \wedge Z\mid U),
\]
which identifies the maximum adversarial guess-budget exponent supportable by the legitimate information advantage [0805.3605].

## 5. System-level SSCP in UAV-assisted NOMA-MEC with WPT

The most explicit modern use of SSCP is in a UAV-assisted uplink NOMA-MEC IoT system in which the UAV has two roles: aerial power station during WPT and MEC server during offloading and computation. The network contains a far cluster \((F_k)\), a near cluster \((N_q)\), and a passive eavesdropper \(E\). During each frame, the UAV first transfers RF energy, then the best user from each cluster offloads part of its task via uplink NOMA, and the UAV computes the offloaded bits [2507.08352].

Each device has workload length \(l\) bits and offloads fraction \(\sigma_\vartheta\),
\[
\mathcal{C}_{\vartheta}^{off}={\sigma }_{\vartheta}l,\qquad 0<\sigma_\vartheta<1.
\]
The protocol has four phases: WPT, secrecy offloading, computation, and negligible downlink return. The WPT duration is
\[
t^{wpt}=\eta T,\qquad 0<\eta<1,
\]
the computation time is
\[
t^{com}=\frac{\left( \mathcal{C}_{q}^{*\,off}+\mathcal{C}_{j}^{*\,off} \right)\varpi}{f_{MEC}},
\]
and the latency threshold is
\[
T_{th}=(1-\eta)T-t^{com}.
\]
The transmit power of each selected edge device is determined by harvested energy, so energy transfer, uplink rate, and secrecy are coupled rather than separable [2507.08352].

The useful and wiretap capacities are
\[
C_{\vartheta }^{*\,U}=\left[ (1-\eta )T-{t}^{com} \right]W\log _2\left( 1+\gamma _{\vartheta }^{*\,U} \right),
\]
\[
C_{\vartheta }^{*\,E}=\left[ (1-\eta )T-{t}^{com} \right]W\log _2\left( 1+\gamma _{\vartheta }^{*\,E} \right),
\]
and the secrecy capacity is
\[
C_{\vartheta }^{*\,S}=\left\lceil C_{\vartheta }^{*\,U}-C_{\vartheta }^{*\,E} \right\rceil^+ .
\]
The exact SSCP then requires both selected users to satisfy offloading-time and secrecy-rate inequalities simultaneously [2507.08352].

The channel model combines probabilistic LoS/NLoS path loss, Nakagami-\(m\) fading, and imperfect CSI, with best-user selection in each cluster based on the maximum estimated UAV-link channel gain. The paper derives separate closed-form formulations for imperfect SIC and perfect SIC. The final results are expressed through finite summations obtained using Gaussian-Chebyshev quadrature. The numerical study reports that SSCP increases with UAV transmit SNR \(\gamma_U\), improves with larger candidate-set sizes \(K,Q\), is highest under pCSI-pSIC, and is non-monotonic in both UAV altitude \(h_U\) and energy-harvesting ratio \(\eta\), yielding an optimal altitude \(h_U^*\), an optimal EH ratio \(\eta^*\), and an optimal horizontal UAV position \((x_U^*,y_U^*)\) [2507.08352].

This formulation is notable because it elevates SSCP from an asymptotic logical conjunction into a concrete wireless-systems performance metric. It unifies wireless powering feasibility, NOMA decoding feasibility, secrecy against a passive eavesdropper, deadline-constrained offloading, and joint two-user task completion in a single probability [2507.08352].

## 6. Relation to secrecy-outage metrics, misconceptions, and limitations

Several papers provide secrecy-event probabilities that are natural components of SSCP but are not themselves full computation metrics. In \(\kappa\)-\(\mu\) fading wiretap channels, the probability of strictly positive secrecy capacity is
\[
P_0=\Pr(C_S>0)=\Pr(\gamma_M>\gamma_E),
\]
and the secrecy outage probability is
\[
P_{out}(R_S)=\Pr(C_S\le R_S).
\]
These are secrecy-success probabilities in a transmission sense, and they can serve as building blocks if “successful computation” is identified with secure decodability. They do not, however, include computation, latency, or task-completion semantics by themselves [1506.08606].

A similar communication-layer building block appears in cooperative threshold decode-and-forward relaying. A relay participates only if
\[
\gamma_{sk}>\gamma_{th},
\]
and the overall secrecy outage decomposes over decoding sets \(\mathbb S\):
\[
P_o(R_s)=\sum_{\mathbb S}\mathbb{P}[\mathbb S]\,P_o^{\mathbb S}(R_s).
\]
The corresponding secure-success probability is \(1-P_o(R_s)\), or equivalently the decoding-set mixture of \(1-P_o^{\mathbb S}(R_s)\). This is not an SSCP definition, but it provides a reusable structure for secrecy-aware success analysis in layered systems [1803.00631].

Several recurring misconceptions are explicitly corrected in the literature. First, high eavesdropper decoding error is not the same as semantic secrecy: message-decoding failure may coexist with nontrivial information leakage or successful computation of some function of the message [1203.2456]. Second, secrecy of raw sources does not imply secrecy of the computed function: in the noiseless matched modulo-2 setting,
\[
Z^k = U^k,
\]
so the eavesdropper learns the function exactly while still learning nothing about each individual source under \(S_m \perp U\) [1603.07227]. Third, secrecy-only event probabilities such as \(P_0=\Pr(\gamma_M>\gamma_E)\) capture a channel advantage event, not end-to-end secure computation [1506.08606].

The principal limitation across the older information-theoretic papers is asymptotic scope. Secure computability theorems give existence and converse thresholds, but they do not provide finite-blocklength SSCP formulas, outage exponents for general function computation, or one-shot joint probability expressions in the style of modern wireless performance analysis [1007.2945], [2201.03948], [1603.07227]. Conversely, the explicit wireless SSCP formulation in UAV-assisted NOMA-MEC is event-level and closed-form, but it is specialized to a concrete architecture with WPT, NOMA, MEC offloading, Nakagami-\(m\) fading, and a passive eavesdropper [2507.08352].

Taken together, these lines of work indicate a coherent taxonomy. At one extreme, SSCP is an exact end-to-end event probability over latency and secrecy constraints. At the other, it is the asymptotic conjunction of reliable computation and vanishing or bounded leakage, or the complement of an adversary’s successful recovery probability. The common mathematical core is the same: a system succeeds only when correctness and secrecy are both satisfied, but the precise object whose probability is measured depends on whether the model centers legitimate computation, eavesdropper recovery, or instantaneous channel advantage.

Source: https://www.emergentmind.com/topics/secrecy-successful-computation-probability-sscp