The Price of Peeking: Anytime-Valid Leakage Detection on ML-KEM EM Traces
Abstract
Side-channel evaluators routinely inspect leakage tests while acquisition is still running, and extend or stop the campaign based on what they see. Fixed-horizon screening such as the Welch -test with threshold gives no error guarantee for this monitored decision rule. We study anytime-valid leakage detection based on testing by betting: SKIT-type swap-pair e-processes whose false-alarm probability is controlled uniformly over time under an explicit conditional symmetry null. In matched comparisons that share the frozen witness, rows and payoff, first-crossing detection needed 1.68-2.00 the traces of a fixed-horizon randomization test at 80% detection on synthetic streams, and 1.68-2.38 on degraded recordings from an open ML-KEM electromagnetic dataset with the primary Ridge witness at . With the same primary witness and level, on undegraded reference and pqm4 recordings the monitored procedure stopped early: its median stopping point was 62-72 and 146-316 evaluation traces, i.e. 2-8% of a conservative 4096-trace budget. Under exact designed nulls on the recorded backgrounds, repeated-look screening over all 13000-20000 samples raised a false alarm in 2.7-12.9% of replicates, against 0.0-4.7% for terminal-only screening and no rejection by a sample-wise e-Bonferroni process, which in a prespecified follow-up detected natural-label associations in 4 of 4 backgrounds after 840-3288 traces. All recordings come from one device, and natural-label results are descriptive; we state the assumptions each claim requires.
Figures & tables
| Claim | Required condition | Status/scope |
|---|---|---|
| RNG null validity | Independent conditional Bernoulli law, predictable bets | Constructed conditional null |
| Natural fractions | Faithful prespecified execution | Descriptive only |
| Natural nominal error | Conditional swap symmetry and joint sign invariance | Unverified; not claimed |
| Physical association | A1 and operation/capture linkage | Conditional, incomplete |
| Chronological replay | A2: order documents acquisition chronology | Unknown; archive convention |
| Sample-family FWER | Valid component processes, fixed allocation | Designed-null e-Bonferroni |
| Null background | alpha | Fixed final count | Plugin ever count | ONS ever count |
|---|---|---|---|---|
| drift | 0.05 | 16 | 6 | 10 |
| drift | 0.01 | 1 | 1 | 0 |
| ar1 | 0.05 | 26 | 11 | 12 |
| ar1 | 0.01 | 8 | 0 | 1 |
| heavy_tails | 0.05 | 26 | 12 | 21 |
| heavy_tails | 0.01 | 7 | 3 | 3 |
| Scenario | alpha | Fixed | Plug C | Plug T | ONS C | ONS T |
|---|---|---|---|---|---|---|
| linear | 0.05 | 1218 | 2436 | 2896 | 2436 | 2896 |
| linear | 0.01 | 2048 | 3444 | 4096 | 3444 | 4096 |
| nonlinear | 0.05 | 1448 | 2436 | 2896 | 2896 | 2896 |
| nonlinear | 0.01 | 2436 | 3444 | 4096 | 4096 | 4096 |
| second_order | 0.05 | 5792 | 11586 | 13778 | 11586 | 13778 |
| second_order | 0.01 | 9742 | 16384 | –C | 13778 | –C |
| Capture | Chunks | Rows/chunk | Samples | Role |
|---|---|---|---|---|
| ref_fixed | 10 | 10000 | 13000 | RNG null only |
| ref_variable | 10 | 10000 | 13000 | RNG null + natural |
| pqm4_fixed | 20 | 10000 | 20000 | RNG null only |
| pqm4_variable | 20 | 10000 | 20000 | RNG null + natural |
| Capture | Eligible chunks | Segments | Used rows | Leftover rows |
|---|---|---|---|---|
| ref_fixed | 0,1,2,3,4,5,6,7,8,9 | 24 | 98304 | 1696 |
| ref_variable | 2,3,4,5,6,7,8,9 | 19 | 77824 | 2176 |
| pqm4_fixed | 2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19 | 43 | 176128 | 3872 |
| pqm4_variable | 2,3,4,5,6,7,8,9 | 19 | 77824 | 2176 |
| Target | Model | Bettor | alpha | Backgrounds | Flags | Limit | Status |
|---|---|---|---|---|---|---|---|
| ref/a | ridge | plugin | 0.05 | 43 | 0 | 6 | PASS |
| ref/a | ridge | plugin | 0.01 | 43 | 0 | 7 | PASS |
| ref/a | ridge | ons_gain | 0.05 | 43 | 0 | 6 | PASS |
| ref/a | ridge | ons_gain | 0.01 | 43 | 0 | 7 | PASS |
| ref/a | ridge | lr | 0.05 | 43 | 1 | 6 | PASS |
| ref/a | ridge | lr | 0.01 | 43 | 0 | 7 | PASS |
| Target | Added-noise SD multiplier | Fixed | Plug C | Plug T | ONS C | ONS T |
|---|---|---|---|---|---|---|
| pqm4/a | 0 | 256B | 256B | 256B | 256B | 256B |
| pqm4/a | 2.0 | 362 | 608 | 1024 | 608 | 724 |
| pqm4/b | 0 | 256B | 430 | 430 | 512 | 512 |
| pqm4/b | 1.0 | 2048 | 3444 | 4096 | 3444 | 4096 |
| ref/a | 0 | 256B | 256B | 256B | 256B | 256B |
| ref/a | 2.0 | 724 | 1218 | 1448 | 1218 | 1448 |
| Background | Comparator | Rejected | First row | Samples |
|---|---|---|---|---|
| 24 | Welch any-look | yes | 1000 | 87 |
| 24 | Welch terminal | yes | 4096 | 87 |
| 24 | e-Bonferroni ( ) | yes | 3288 | 6 |
| 24 | e-Bonferroni ( ) | yes | 3654 | 5 |
| 25 | Welch any-look | yes | 1000 | 103 |
| 25 | Welch terminal | yes | 4096 | 103 |
| Background ID | Welch any look | Welch terminal | e-Bonf primary | e-Bonf secondary |
| 0 | 33 | 10 | 0 | 0 |
| 1 | 29 | 12 | 0 | 0 |
| 24 | 31 | 12 | 0 | 0 |
| 25 | 29 | 8 | 0 | 0 |
| 43 | 19 | 5 | 0 | 0 |
| 44 | 11 | 4 | 0 | 0 |
Appendix figures & tables4 assets
Supplementary material from the paper’s appendix.
Appendix
| Target | Model | SD | alpha | Fixed | Plug C | Plug T | ONS C | ONS T |
|---|---|---|---|---|---|---|---|---|
| pqm4/a | mlp | 0 | 0.01 | 256B | 256B | 256B | 304 | 304 |
| pqm4/a | mlp | 0 | 0.05 | 256B | 256B | 256B | 256B | 256B |
| pqm4/a | mlp | 2.0 | 0.01 | 1448 | 2436 | 2896 | 2436 | 2896 |
| pqm4/a | mlp | 2.0 | 0.05 | 608 | 2048 | 2436 | 1448 | 2048 |
| pqm4/a | ridge | 0 | 0.01 | 256B | 304 | 304 | 304 | 304 |
| pqm4/a | ridge | 0 | 0.05 | 256B | 256B | 256B | 256B | 256B |
| Target | Model | Bettor | alpha | Backgrounds | Flags | Limit | Status |
|---|---|---|---|---|---|---|---|
| ref/a | ridge | plugin | 0.05 | 43 | 0 | 6 | PASS |
| ref/a | ridge | plugin | 0.01 | 43 | 0 | 7 | PASS |
| ref/a | ridge | ons_gain | 0.05 | 43 | 0 | 6 | PASS |
| ref/a | ridge | ons_gain | 0.01 | 43 | 0 | 7 | PASS |
| ref/a | ridge | lr | 0.05 | 43 | 1 | 6 | PASS |
| ref/a | ridge | lr | 0.01 | 43 | 0 | 7 | PASS |
| Condition | Finite stops | Median row | IQR |
|---|---|---|---|
| pqm4/a/mlp/ONS/0.01 | 19 | 206.0 | 61.0 |
| pqm4/a/mlp/ONS/0.05 | 19 | 150.0 | 36.0 |
| pqm4/a/mlp/plugin/0.01 | 19 | 186.0 | 63.0 |
| pqm4/a/mlp/plugin/0.05 | 19 | 136.0 | 41.0 |
| pqm4/a/ridge/ONS/0.01 | 19 | 238.0 | 73.0 |
| pqm4/a/ridge/ONS/0.05 | 19 | 156.0 | 48.0 |
| Stage | Invocations | CPU seconds | Wall seconds |
|---|---|---|---|
| development | 4 | 21.6 | 12.4 |
| pilot | 384 | 1407.9 | 468.8 |
| freeze | 1 | 3.7 | 1.3 |
| null | 1680 | 6430.5 | 2352.4 |
| gate | 1 | 4.0 | 1.6 |
| natural | 152 | 629.9 | 260.1 |