偷窥的代价:ML-KEM 电磁迹线上任意有效的泄漏检测
The Price of Peeking: Anytime-Valid Leakage Detection on ML-KEM EM Traces
浏览论文内容
中文总结 AI 辅助
针对侧信道评估中实时监控泄漏测试缺乏误差保证的问题,提出基于投注检验的任意有效检测方法,在ML-KEM电磁迹线上实现随时间可控的误报率,并显著节省评估迹线预算。
中文摘要 AI 辅助
侧信道评估人员通常在采集仍在进行时检查泄漏测试,并根据所见内容延长或停止测试活动。固定视界筛选(如阈值 $|t|>4.5$ 的 Welch $t$-检验)对此类受监控的决策规则不提供任何误差保证。我们研究基于投注检验的任意有效泄漏检测:SKIT 型交换对 e 过程,其误报概率在显式条件对称零假设下随时间均匀控制。在共享冻结见证、行和收益的匹配比较中,在合成流上,首越检测在 80% 检测率下所需的迹线数为固定视界随机化检验的 1.68-2.00 倍;在来自开放 ML-KEM 电磁数据集且使用主 Ridge 见证($\alpha=0.05$)的退化录音上,该倍数为 1.68-2.38 倍。使用相同的主见证和水平,在未退化的参考和 pqm4 录音上,受监控过程提前停止:其中位停止点为 62-72 和 146-316 条评估迹线,即保守的 4096 迹线预算的 2-8%。在记录背景上的精确设计零假设下,对所有 13000-20000 个样本进行重复查看 $|t|>4.5$ 筛选,在 2.7-12.9% 的重复中引发误报,而仅终端筛选的误报率为 0.0-4.7%,样本级 e-Bonferroni 过程则无拒绝;在预设的后续分析中,该过程在 4 个背景中的 4 个中于 840-3288 条迹线后检测到自然标签关联。所有录音均来自同一设备,自然标签结果为描述性;我们陈述了每个声明所需的前提条件。
英文摘要
Side-channel evaluators routinely inspect leakage tests while acquisition is still running, and extend or stop the campaign based on what they see. Fixed-horizon screening such as the Welch $t$-test with threshold $|t|>4.5$ gives no error guarantee for this monitored decision rule. We study anytime-valid leakage detection based on testing by betting: SKIT-type swap-pair e-processes whose false-alarm probability is controlled uniformly over time under an explicit conditional symmetry null. In matched comparisons that share the frozen witness, rows and payoff, first-crossing detection needed 1.68-2.00$\times$ the traces of a fixed-horizon randomization test at 80% detection on synthetic streams, and 1.68-2.38$\times$ on degraded recordings from an open ML-KEM electromagnetic dataset with the primary Ridge witness at $α=0.05$. With the same primary witness and level, on undegraded reference and pqm4 recordings the monitored procedure stopped early: its median stopping point was 62-72 and 146-316 evaluation traces, i.e. 2-8% of a conservative 4096-trace budget. Under exact designed nulls on the recorded backgrounds, repeated-look $|t|>4.5$ screening over all 13000-20000 samples raised a false alarm in 2.7-12.9% of replicates, against 0.0-4.7% for terminal-only screening and no rejection by a sample-wise e-Bonferroni process, which in a prespecified follow-up detected natural-label associations in 4 of 4 backgrounds after 840-3288 traces. All recordings come from one device, and natural-label results are descriptive; we state the assumptions each claim requires.