SpikeCliff effect: empirical analysis of deterministic timing discontinuities in sponge-based XOF functions
Article Sidebar
Issue Vol. 40 (2026)
-
Analysis of the capabilities of predictive artificial intelligence models in corporate risk management
Kacper Ziemski188-192
-
Usability and availability of selected e-commerce services
Marcin Kozicki, Maria Skublewska-Paszkowska193-200
-
Comparison of C++ and Python performance based on selected algorithms
Szymon Bogucki, Kacper Burda201-205
-
Security analysis of selected web applications using vulnerability scanners
Mariusz Choroś, Marta Dziuba-Kozieł206-212
-
Comparison of Java and .NET reflection mechanisms for dynamic module loading: a performance benchmark study
Michał Mazur, Sebastian Maruszak, Marek Miłosz213-217
-
Comparative analysis of network vulnerability detection tools
Mateusz Zdunek218-225
-
Evaluation of mobile applications for personal finance management using the MARS scale
Łukasz Nikiel, Artsiom Patskevich, Marek Miłosz226-231
-
Comparison of the effectiveness of roulette betting strategies using Monte Carlo simulation
Marek Sarnecki232-238
-
Analysis of optimization capabilities of selected database management systems
Paweł Tarkiewicz, Małgorzata Plechawska-Wójcik239-246
-
Comparative analysis of Espresso and Appium frameworks for automated UI testing of Android mobile applications
Jakub Derkacz247-254
-
Comparative analysis of the applicability of artificial intelligence models for code generation
Patryk Warchoł, Małgorzata Plechawska-Wójcik255-262
-
Comparison of the effectiveness of selected tools for detecting texts generated by artificial intelligence
Marcin Brodacki, Małgorzata Plechawska-Wójcik263-269
-
Comparative analysis of selected containerization tools in terms of MCP
Paweł Jan Tłusty, Maciej Pańczyk270-276
-
SpikeCliff effect: empirical analysis of deterministic timing discontinuities in sponge-based XOF functions
Łukasz Wójcik, Stanisław Lota277-282
-
Comparison of AI agents for creating SQL queries
Julia Sierpień, Maria Skublewska-Paszkowska283-288
-
Comparative analysis of the performance of PostgreSQL and Neo4j databases in the context of genealogical queries
Michał Muzyka, Mateusz Niedźwiedź, Marek Miłosz289-296
-
Evaluation of the effectiveness of static and dynamic methods in malware analysis
Dominik Tracz, Daniel Sawicki, Konrad Gromaszek297-303
-
Comparison of classical machine learning methods in the task of obesity level classification
Paweł Biesaga, Paweł Powroźnik304-312
Main Article Content
Authors
Abstract
This paper presents the characterization and systematic documentation of the SpikeCliff effect, a deterministic temporal discontinuity occurring in extendable-output functions (XOF) based on the sponge construction. The phenomenon manifests as regular processing time spikes at input lengths crossing the rate boundary, caused by additional Keccak-f permutation calls. While theoretically predictable from the sponge definition, this effect has not been previously measured, documented, or analyzed in the context of XOF functions. We introduce boundary-aware profiling, a methodology for per-byte timing analysis, and demonstrate that SpikeCliff is fully deterministic, algorithmic in nature, and reproducible across platforms when dynamic frequency scaling is disabled. BLAKE3 serves as a negative control, confirming the specificity of the effect to sponge-based architectures. Practical implications for IoT systems, benchmarking methodology, and side-channel analysis are discussed.
Keywords:
Sustainable Development Goal (SDG)
- Industry, Innovation, Technology and Infrastructure
References
[1] G. Bertoni, J. Daemen, M. Peeters, G. Van Assche, Cryptographic sponge functions, https://keccak.team/files/CSF-0.1.pdf.
[2] Standard for cryptographic hash functions. SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions, FIPS PUB 202, https://doi.org/10.6028/NIST.FIPS.202, [07.07.2026].
[3] Architecture guide for Intel Turbo Boost. Intel Turbo Boost Technology 2.0 Architecture, White Paper, https://builders.intel.com/docs/networkbuilders/intel-turbo-boost-technology-configure-per-core-turbo-overview-technology-guide-1673528561.pdf, [07.07.2026].
[4] Q. Ge, Y. Yarom, D. Cock, G. Heiser, A survey of microarchitectural timing attacks and countermeasures on contemporary hardware, Journal of Cryptographic Engineering 8(1) (2018) 1–27, https://doi.org/10.1007/s13389-016-0141-6.
[5] Specification for SHA-3 derived functions. SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash and ParallelHash, NIST Special Publication 800-185, https://doi.org/10.6028/NIST.SP.800-185, [07.07.2026].
[6] J. O'Connor, J.-P. Aumasson, S. Neves, Z. Wilcox-O'Hearn, BLAKE3: One Function, Fast Everywhere, IACR Cryptology ePrint Archive 2021/1164 (2021), https://eprint.iacr.org/2021/1164.
[7] J. Daemen, G. Van Assche, Differential propagation analysis of Keccak, in: Fast Software Encryption – FSE 2012, LNCS 7549, Springer (2012) 422–441, https://eprint.iacr.org/2012/163.
[8] P. C. Kocher, Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems, in: Advances in Cryptology – CRYPTO 1996, LNCS 1109, Springer (1996) 104–113, https://doi.org/10.1007/3-540-68697-5_9.
[9] D. J. Bernstein, Cache-timing attacks on AES, Technical Report, University of Illinois at Chicago, 2005, https://cr.yp.to/antiforgery/cachetiming-20050414.pdf.
[10] J. L. Hennessy, D. A. Patterson, Computer Architecture: A Quantitative Approach, 6th ed., Morgan Kaufmann, 2019, ISBN 978-0-12-811905-1.
[11] A. Kuznetsov, I. Oleshko, V. Tymchenko, K. Lisitsky, M. Rodinko, A. Kolhatin, Performance analysis of cryptographic hash functions suitable for use in blockchain, International Journal of Computer Network and Information Security 13(2) (2021) 1–15, https://doi.org/10.5815/ijcnis.2021.02.01.
[12] S. Windarta, S. Suryadi, K. Ramli, B. Pranggono, T. S. Gunawan, Lightweight cryptographic hash functions: Design trends, comparative study, and future directions, IEEE Access 10 (2022) 82272–82294, https://doi.org/10.1109/ACCESS.2022.3195572.
[13] I. Mufidah et al., Performance and security analysis of lightweight hash functions in IoT, Jurnal Informatika: Jurnal Pengembangan IT 9(3) (2024), https://arxiv.org/pdf/2508.07840v1.
[14] M. Khan, D. Johansen, H. Dagenborg, A comparative analysis of lightweight hash functions using AVR ATXMega128 and ChipWhisperer, arXiv preprint arXiv:2508.07840 (2025), https://doi.org/10.48550/arXiv.2508.07840.
[15] Ł. Wójcik, SpikeCliff XOF Analysis – Boundary Profiler, GitHub repository (2026), https://github.com/lukaszwojcikdev/spikecliff-xof-analysis/
Article Details
Abstract views: 5

