Persistent Cross-Round Carry Leakage in ARX Ciphers: Detection, Prediction, and Topological Classification
David Tom Foss · 2026
We present F8, a cross-round mutual information test that detects a previously unknown class of structural leakage in ARX (Addition-Rotation-XOR) block ciphers. Unlike differential or linear trails, the detected signal does not decay with additional rounds—it is regenerated per round by the carry propagation of modular addition. Applied to 13 cipher families (including controls), F8 yields full-round known-key distinguishers for the entire Speck family (Z > +4,000 at all specified rounds) and for Threefish-256 (Z ≈ +5,900 at all 72 rounds), the basis of the SHA-3 finalist Skein. A closed-form prediction function MI(β) = 0.78 · exp(−1.42β) with R² = 0.999997 determines leakage magnitude from rotation parameters alone, without executing the cipher. A topological classification provides necessary and sufficient conditions: leakage exists if and only if a modular addition output enters the state without prior diffusion. Two distinct mechanisms are identified—β-masking (Speck) and raw carry exposure (Threefish)—and a universal leak-model compiler achieves 9/9 correct predictions. The leakage is strictly encrypt-only (decrypt: Z ≈ 0, ratio > 3,000:1). The SPARX ARX-box in isolation exhibits Z ≈ +5,500 (identical to Speck), proving that the linear inter-round layer is the sole protection mechanism. Control experiments with SIMON 32/64 (AND-rotation, no addition) and a random Feistel cipher both yield Z ≈ 0, isolating modular addition as the necessary condition. Eight cipher families including ChaCha20, AES-128, SPARX, and LEA are confirmed immune at full rounds.