Paper 2026/1990

Bounded Information: PAC Certification of Multivariate Side-Channel Traces

Kuheli Pratihar, Indian Institute of Technology Kharagpur
Nimish Mishra, Indian Institute of Technology Kharagpur
Debdeep Mukhopadhyay, Indian Institute of Technology Kharagpur
Abstract

Side-channel leakage certification aims to quantify what an attacker can learn about a secret variable from observed leakage. Existing information-theoretic estimators, such as perceived information (PI), hypothetical information (HI), and nonparametric mutual information (MI), aim to quantify distributional leakage, but they become unstable in high-dimensional traces and do not provide a finite-sample certificate of the best attacker. We introduce \emph{Bounded Information} (BI), a probably approximately correct (PAC)-style finite-sample certification method that upper-bounds the exact-recovery success of a fixed attacker scope on unseen traces. The attacker suite certificate, $\mathrm{BI}^{\mathrm{suite}}$, applies a KL-binomial confidence interval with a union bound over a fixed suite that contains every trained attacker, preprocessing choice, and hyperparameter. BI therefore turns standard profiled-attack evaluation into an auditable certificate with an explicit attacker scope and confidence level. We further define $\mathrm{BI}^{\mathrm{loc}}(\varepsilon)$ to bound the recovery success of attackers whose normalized scores differ by at most $\varepsilon$ from those of a model in the suite. Across eight side-channel benchmarks with trace dimensions up to $7{,}000$, BI provides stable certificates without density estimation, and its tightness diagnostics tell an evaluator whether a certified value is a genuine measurement of leakage or a conservative bound that more attack traces would tighten.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
Side-channel analysisLeakage certificationPAC boundsMultivariate leakageDeep learning side-channel attacks
Contact author(s)
its kuheli96 @ gmail com
neelam nimish @ gmail com
debdeep mukhopadhyay @ gmail com
History
2026-09-14: approved
2026-09-12: received
See all versions
Short URL
https://ia.cr/2026/1990
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1990,
      author = {Kuheli Pratihar and Nimish Mishra and Debdeep Mukhopadhyay},
      title = {Bounded Information: {PAC} Certification of Multivariate Side-Channel Traces},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1990},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1990}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.