Papers
Topics
Authors
Recent
Search
2000 character limit reached

StickySampling: Streaming Frequency Estimation

Updated 16 November 2025
  • StickySampling is a streaming algorithm that approximates item frequency counts in high-speed data streams with provable one-sided additive error guarantees.
  • It employs a decreasing Bernoulli sampling probability combined with periodic counter decay to achieve logarithmic space complexity relative to the failure probability.
  • The algorithm is applied in security-critical contexts such as DRAM RowHammer mitigation, ensuring efficient detection of hammer rows without false positives.

StickySampling is a streaming algorithm designed to maintain approximate frequency counts for items in a high-speed data stream, providing one-sided additive error guarantees using space that is logarithmic in the failure probability. Originally formulated for data streams by Manku and Motwani, StickySampling achieves strong probabilistic security and performance trade-offs, making it particularly suitable for security-critical systems such as DRAM RowHammer mitigation, where it enables the detection of “hammer” rows with provable guarantees.

1. Problem Statement and Formal Definition

The StickySampling algorithm addresses the problem of tracking item (e.g., memory row) frequencies over a potentially unbounded data stream SS of length NN. For each unique element aa, let real⁡(a)\operatorname{real}(a) denote the true frequency and est⁡(a)\operatorname{est}(a) the estimate reported by the algorithm. The algorithm maintains a data structure CC with the following property:

real⁡(a)−ϵN≤est⁡(a)≤real⁡(a),with probability at least 1−δ\operatorname{real}(a) - \epsilon N \leq \operatorname{est}(a) \leq \operatorname{real}(a),\quad \text{with probability at least } 1-\delta

where ϵ∈(0,1)\epsilon \in (0,1) is the permissible additive error fraction and δ∈(0,1)\delta \in (0,1) is the failure probability on the upper bound. In practice, parameters are tuned so that ϵN\epsilon N is a small fraction of a relevant system threshold (such as RowHammer, RH), and NN0 is the tolerable false-negative rate.

Key parameters:

  • NN1: additive error fraction (e.g., set so NN2 in DRAM applications)
  • NN3: failure probability
  • NN4: support-width constant, controlling counter compression frequency
  • NN5: updates before each compression and halving of sampling probability

StickySampling combines a geometrically decreasing Bernoulli sampling probability with periodical counter decay (“Compress”) to bound the number of stored counters.

2. Algorithm: Annotated Pseudocode

A hardware-friendly version of the StickySampling algorithm maintains accuracy and memory efficiency:

real⁡(a)−ϵN≤est⁡(a)≤real⁡(a),with probability at least 1−δ\operatorname{real}(a) - \epsilon N \leq \operatorname{est}(a) \leq \operatorname{real}(a),\quad \text{with probability at least } 1-\delta0 This structure admits new items with a decreasing probability, ensuring rare items are dropped over time. The Compress step uses geometric decay to cap state and avoids linear growth over the stream.

3. Accuracy and Space Complexity Guarantees

Let NN6 be the total number of processed items. Under the specified parameters:

  • The counter table maintains at most NN7 entries.
  • For any row address NN8:

    • Deterministic lower bound: NN9.
    • Probabilistic upper bound:

    aa0

Space usage is thus

aa1

with each entry recording a row address and its partial count.

4. Security Guarantees for RowHammer Mitigation

For DRAM RowHammer detection, “critical” rows (potential aggressors) are defined as aa2 within a refresh window. To guarantee detection,

  • Set aa3 so that aa4.
  • Any row with aa5 will have aa6 with probability at least aa7, triggering mitigation.
  • No row with aa8 will be falsely reported: no false positives. With this, all rows exceeding the hammer threshold are detected and mitigated with high confidence before causing victim bitflips.

5. Comparison with Reservoir Sampling and Lossy Counting

Algorithm Space Complexity Error Profile
Reservoir Sampling aa9 (real⁡(a)\operatorname{real}(a)0) Probabilistic (detection by sampling)
Lossy Counting real⁡(a)\operatorname{real}(a)1 One-sided, deterministic lower bound
StickySampling real⁡(a)\operatorname{real}(a)2 One-sided additive real⁡(a)\operatorname{real}(a)3 error with failure real⁡(a)\operatorname{real}(a)4

Reservoir Sampling provides uniform sampling but does not yield frequency counts, and is relatively inefficient for high security as real⁡(a)\operatorname{real}(a)5 scales steeply. Lossy Counting provides one-sided error but its counter state grows with real⁡(a)\operatorname{real}(a)6. StickySampling achieves similar error guarantees to Lossy Counting, with superior scaling—its state does not depend on the total stream length real⁡(a)\operatorname{real}(a)7, only on real⁡(a)\operatorname{real}(a)8 and real⁡(a)\operatorname{real}(a)9.

6. Parameter Selection and Practical Deployment in DRAM Controllers

In practical DRAM systems with est⁡(a)\operatorname{est}(a)0 ms, est⁡(a)\operatorname{est}(a)1 ns, and worst-case est⁡(a)\operatorname{est}(a)2 activations per window, set est⁡(a)\operatorname{est}(a)3 (RowHammer threshold). To ensure est⁡(a)\operatorname{est}(a)4, select est⁡(a)\operatorname{est}(a)5. With est⁡(a)\operatorname{est}(a)6, this yields:

  • est⁡(a)\operatorname{est}(a)7
  • est⁡(a)\operatorname{est}(a)8 activations

The resulting counter table holds est⁡(a)\operatorname{est}(a)9 entries. After every CC0 activations, the Compress step is triggered, halving CC1 and doubling the next window. Such resource demands are moderate relative to DRAM controller capabilities and allow designer-controlled trade-offs by tuning CC2 and CC3; lowering CC4 increases tracking fidelity but raises memory usage, while decreasing CC5 reduces false negatives with only logarithmic space cost.

7. Significance and Applicability

StickySampling introduces a novel combination of provable one-sided additive error (CC6) and logarithmic-in-CC7 space, enabled by the geometric decay and window-doubling mechanism. It is the first streaming method to provide these guarantees within the domain of architectural RowHammer defenses, ensuring the detection of all rows surpassing the hammer threshold with tunable confidence while avoiding false positives. The algorithm’s balanced security-performance trade-off surpasses both pure sampling and deterministic bucket-based schemes for this class of memory security problems. Practitioners should select CC8 and CC9 to match system-level false-negative requirements, thereby right-sizing counter table, update window, and sampling probability to ensure resilient mitigation against aggressive RowHammer attacks.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to StickySampling.