Cross-Round Carry Leak in ARX Ciphers: The F8 Distinguisher

Authors

  • David Tom Foss Author

Abstract

We present the F8 distinguisher, a novel cross-round mutual information test that detects persistent carry-leak in ARX ciphers. Modular addition outputs entering the cipher state without prior self-rotation create detectable leakage. Full-round detection on all Speck variants and Threefish-256. Decay model MI = 0.78 exp(-1.42 beta), R-squared 0.999997. Topological rule predicts all 13 tested ciphers correctly.

References

Downloads

Published

2026-03-04