Beyond Random-Split Accuracy: Duplicate-Safe and Crypto-Agile Evaluation of Anomaly Detection for Post-Quantum TLS

Post-quantum cryptography changes the size, timing, and algorithmic context of Transport Layer Security (TLS) handshakes, creating a dynamic normal class for anomaly detectors. This study evaluates an assurance framework, rather than proposing a new classifier, on CIC-PQC_OAV v1: 40,010 sessions represented by 32 encrypted-metadata features. An audit finds 185 exact fingerprints shared across the supplied partitions, affecting 1594 sessions, plus one exact conflicting-label group. We compare the fixed split with five-seed, size-matched sample-stratified, exact-disjoint, raw round-3-disjoint, and IQR-normalized round-3-disjoint protocols, each separating fitting, probability calibration, threshold selection, conformal calibration, and testing. The fixed-split LightGBM F1 is 0.9013; controlled five-seed means cluster at 0.8872–0.8898, showing that its gap is not attributable solely to duplicate control. Condition-disjoint tests reveal heterogeneous anomaly transfer and false-positive rates of 0.9998, 0.9897, and 0.6107 for three unseen valid families. Isotonic calibration yields a Brier score of 0.0221±0.0013, while five-seed perturbations confirm sensitivity to timing masking and byte scaling. The results support layered, dataset-bounded evaluation combining fingerprint independence, condition holdouts, calibration, selective review, robustness, and explanation.

Authors

Institutions

Publication Details

Journal
Electronics
Published
2026-09-15
DOI
https://doi.org/10.3390/electronics15184179
Primary Topic
Cryptographic Implementations and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Beyond Random-Split Accuracy: Duplicate-Safe and Crypto-Agile Evaluation of Anomaly Detection for Post-Quantum TLS

Mohammed Abdulaziz Alsubhi
Electronics
Cryptographic Implementations and Security
article

Beyond Random-Split Accuracy: Duplicate-Safe and Crypto-Agile Evaluation of Anomaly Detection for Post-Quantum TLS

Mohammed Abdulaziz Alsubhi
article en

Abstract

Post-quantum cryptography changes the size, timing, and algorithmic context of Transport Layer Security (TLS) handshakes, creating a dynamic normal class for anomaly detectors. This study evaluates an assurance framework, rather than proposing a new classifier, on CIC-PQC_OAV v1: 40,010 sessions represented by 32 encrypted-metadata features. An audit finds 185 exact fingerprints shared across the supplied partitions, affecting 1594 sessions, plus one exact conflicting-label group. We compare the fixed split with five-seed, size-matched sample-stratified, exact-disjoint, raw round-3-disjoint, and IQR-normalized round-3-disjoint protocols, each separating fitting, probability calibration, threshold selection, conformal calibration, and testing. The fixed-split LightGBM F1 is 0.9013; controlled five-seed means cluster at 0.8872–0.8898, showing that its gap is not attributable solely to duplicate control. Condition-disjoint tests reveal heterogeneous anomaly transfer and false-positive rates of 0.9998, 0.9897, and 0.6107 for three unseen valid families. Isotonic calibration yields a Brier score of 0.0221±0.0013, while five-seed perturbations confirm sensitivity to timing masking and byte scaling. The results support layered, dataset-bounded evaluation combining fingerprint independence, condition holdouts, calibration, selective review, robustness, and explanation.

ElectronicsVol. 15(18)
University of Ha'il (SA)
Openalex Percentile: Top 8%
Cryptographic Implementations and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.