International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Multivariate Leakage Detection


Aakash Chowdhury
University of Klagenfurt, Klagenfurt, Austria

Elisabeth Oswald
University of Klagenfurt, Klagenfurt, Austria; University of Birmingham, Birmingham, United Kingdom


Keywords: side channels, leakage detection


Abstract

Leakage detection tests are designed to determine if side channel traces are data (or key) dependent. Non-specific leakage detection tests are particularly valuable in the early stages of an evaluation, because they only make minimal assumptions about the leakage and the implementation that is being tested. The most important property of a detection test is its ability to detect true leaks (minimise the rate of false negatives) whilst not alerting incorrectly (minimise the rate of false positives). A detection test is “better” if, for a fixed rate of false positives, it achieves a smaller rate of false negatives. A recent experimental study, which compared a deep learning based approach to classical statistics, suggests that deep learning might be superior over classical statistics for multivariate detection, missing however a thorough exploration of error rates.Classical statistical methods progressed, and in this paper, we explore a generalisation of Pearson correlation, called distance correlation (covariance), which captures nonlinear dependencies (unlike Pearson correlation), for the purpose of non-specific leakage detection. We conduct experiments using several real-world data-sets from software and hardware implementations of commonly used block ciphers (AES, PRESENT, ASCON) with and without countermeasures (hiding and masking). We find that the recently proposed deep learning detection technique does not reliably decrease its false negative rate with more traces. Other multivariate methods fail to detect anything in some of the scenarios. The most robust detection techniques are classical univariate statistics using appropriate multiplicity corrections, and the multivariate distance covariance test. Classical statistical methods require minimal configuration, and therefore, give the evaluator the freedom to not worry about properties of traces and configuring deep net architectures, which makes them a highly attractive option for practical use.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 2

Paper

Artifact

Artifact number
tches/2026/a12

Artifact published
June 02, 2026

Badge
IACR CHES Artifacts Functional

README

ZIP (1025606 Bytes)  

View on Github

License
GPLv3 This work is licensed under the GNU General Public License version 3.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Aakash Chowdhury, Elisabeth Oswald. (2026). Multivariate Leakage Detection. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(2), 296–324. https://doi.org/10.46586/tches.v2026.i2.296-324. Artifact at https://artifacts.iacr.org/tches/2026/a12.