---
title: Leakage Theory Overview
url: https://www.emergentmind.com/topics/leakage-theory
type: topic
---

# Leakage Theory Overview

In current research, “leakage theory” denotes several formal traditions for analyzing unintended transport or disclosure across an imperfect interface, channel, or mechanism. In rough-contact sealing, it concerns fluid or gas flow through non-contact constrictions governed by lubrication or kinetic theory and multiscale contact mechanics. In quantitative information flow and cryptography, it concerns posterior vulnerability under observation, protocol composition, and adversarial interaction. In quantum information, it concerns dephasing, gentle measurements, and Rényi-type capacities. In machine learning, it concerns contamination of evaluation protocols, shortcut transmission through concept bottlenecks, reconstruction from model updates, and artifacts detectable from prediction vectors alone [2007.13576], [1404.7516], [2403.11433], [2607.01025].

## 1. Interfacial transport in seals and rough contacts

In metallic-seal theory, two nominally flat but microscopically rough bodies are pressed together under nominal contact pressure \(p(x,y)\), while a fluid of viscosity \(\eta\) and pressure difference \(\Delta P\) attempts to flow through the non-contact channels. In the Reynolds approximation, the local volumetric flux per unit width is
\[
J_x(x,y)=-\frac{u^3(x,y)}{12\eta}\frac{\partial p_{\rm fluid}}{\partial x},
\]
with \(u(x,y)\) the local separation. If a single “critical constriction” of height \(u_{\rm c}\) dominates the flow, the leak-rate is approximated by
\[
\dot Q \approx \frac{u_{\rm c}^3}{12\eta}\,\frac{\Delta P}{w/L_y},
\]
where \(w\) is the constriction width and \(L_y\) is the transverse length or circumference feeding parallel channels. A more complete treatment replaces the single junction by an effective conductivity \(\sigma_{\rm eff}(p(x))\) and yields
\[
\Delta P=\dot Q\,\frac{1}{L_y}\int_{-\infty}^{\infty}\frac{dx}{\sigma_{\rm eff}(p(x))}.
\]
For azimuthally symmetric seals with \(p(y)=p_0 e^{-y^2/2}\) and \(s^2=\gamma R h_{\rm rms}\), the leak-rate becomes
\[
\dot Q=\frac{L_y}{2s}\;
\frac{\Delta P}{\displaystyle\int_0^\infty [\sigma_{\rm eff}(p_0 e^{-y^2/2})]^{-1}\,dy}.
\]
These formulas are coupled to Persson contact mechanics through the pressure-separation relation \(p(u)=p_{\rm c}e^{-u/u_0}\), with \(u_0=\gamma h_{\rm rms}\), and through the roughness power spectrum \(C(q)\) [2007.13576].

A central refinement in metallic seals is asperity-scale plasticity. When plastic yield occurs, the original spectrum \(C(q)\) is replaced by a smoothed spectrum
\[
C_{\rm pl}(q)=\Bigl[1-\bigl(\tfrac{A_{\rm pl}(\zeta)}{A^0_{\rm pl}}\bigr)^6\Bigr]C(q),
\]
where \(A^0_{\rm pl}=F_{\rm N}/\sigma_{\rm P}\) and \(\sigma_{\rm P}\approx 3\sigma_{\rm Y}\). Substituting \(C_{\rm pl}(q)\) into the Persson-Bruggeman calculation reduces the computed \(u_{\rm c}\) by roughly a factor of \(2\), and because \(\dot Q\propto u_{\rm c}^3\), the predicted leak-rate is reduced by about \(2^3\approx 8\). In the reported experiment, a hardened steel ball of radius \(R=20\) mm sealed against a conical steel seat with \(\theta=45^\circ\); the ball had \(h_{\rm rms}\approx 0.8\,\mu\)m, the sandblasted seat \(h_{\rm rms}\approx 1.9\,\mu\)m, \(E^*=115\) GPa, and \(\sigma_{\rm P}\approx 3.5\) GPa. Without plasticity, the theory overestimated leakage by almost an order of magnitude; with plastic smoothing, theory and experiment agreed closely over \(\Delta P=1\)–20 bar, including the example \(\dot Q\approx 5\times 10^{-6}\) m\(^3\)/s at \(20\) bar.

## 2. Percolation, Knudsen crossover, and critical closure

A recurrent idea in seal leakage is that the decisive event is percolation of the non-contact region. As magnification \(\zeta\) increases, the real contact area \(A(\zeta)\) decreases until non-contact zones percolate at \(A/A_0\approx 0.42\) for isotropic random roughness. In the effective-medium treatment of elastic contacts, this threshold is encoded by modifying Bruggeman theory: the rigid-contact value \(A^*/A_0=1/2\) is shifted by elasticity to \(A^*/A_0\approx 0.42\pm 0.02\), corresponding at threshold to an effective dimension \(n_{\rm eff}\approx 1.72\). Near sealing, however, the critical behavior is not universal. Numerical work found
\[
Q\sim (\Delta L)^\beta,\qquad \beta=\frac{69}{20}\approx 3.45,
\]
for the default adhesion-free, no-slip model, but also showed that the exponent is governed by the microscopic geometry of the last open constriction rather than by universal percolation statistics [1512.00186], [1308.3449].

For gases, the local transport law must interpolate between diffusive and ballistic regimes. In syringe and suction-cup leakage, the Knudsen number \(\mathrm{Kn}=\lambda/h\) separates the continuum limit \(\lambda\ll h\) from the free-molecular limit \(\lambda\gg h\). In one formulation, the microscopic current is
\[
J(x)=-\sigma(x)\nabla p(x),
\]
with
\[
\sigma(x)=\frac{u^3 p_{\rm avg}}{12k_B T\eta}+\frac{\bar v u^2}{2k_B T}.
\]
In the slit-constriction model, the diffusive conductance scales as \(h^3\), the ballistic conductance as \(h^2\), and a unified leakage equation bridges the two. For a torus-shaped seal of length \(L_x\) and circumference \(L_y=2\pi R\), the macroscopic leak-rate is
\[
Q=\frac{L_y\Delta P}{S(L_x)},\qquad
S(L_x)=\int_0^{L_x} dx\,[1/\sigma_{\rm eff}(p_{\rm cont}(x))].
\]
This framework was validated for a syringe system in which stylus profilometry and AFM supplied \(C(q)\), FEM supplied \(p_0(x)\), and Multiscale Contact Mechanics software supplied the leakage prediction; the paper reports strong sensitivity near \(\theta_c\approx 0.42\), and dry tests agreed with prediction without fitting parameters [2507.09571].

The same physical structure appears in suction cups. There, the unified number-flux law
\[
\dot N=\frac{1}{24}\frac{L_y}{L_x}\frac{p_a^2-p_b^2}{k_BT}\frac{u_c^3}{\eta}
\Bigl[1+\xi \frac{\langle \lambda\rangle}{u_c}\Bigr],\qquad \xi=\frac{32}{\pi},
\]
is combined with Persson theory for \(u_c\), with viscoelastic deformation of the cup, and with time evolution of the trapped volume and internal pressure. Experiments on \(40\) mm soft-PVC cups against sandblasted PMMA matched theory for rms roughness \(\gtrsim 1\,\mu\)m, while smoother surfaces exhibited anomalously long lifetimes attributed to plasticizer diffusion blocking critical constrictions [1906.01459]. In Teflon-coated rubber syringe seals, the gas flow was found to be mainly ballistic, the percolation threshold again occurred near \(A/A_0\approx 0.42\), and plastic flow in Teflon under rib pressures \(\sim 3\)–\(5\) MPa was reported to reduce \(Q\) by factors up to \(\sim 10^3\) [2108.02063].

## 3. Information leakage as channel vulnerability and strategic interaction

In quantitative information flow, a system is modeled as a channel \(C:X\to D(Y)\), with prior \(\pi\in D(X)\) and a vulnerability functional \(V:D(X)\to\mathbb R\). Posterior vulnerability is
\[
\pi\,C=\sum_{y\in Y} p(y)\,V(p(\cdot\mid y)),
\]
and leakage may be written additively as \(L_{\rm add}(C,\pi)=\pi\,C-V(\pi)\) or multiplicatively as \(L_{\rm mul}(C,\pi)=\pi\,C/V(\pi)\). The resulting utility is generally non-linear in the defender’s mixed strategy: under hidden choice, the effective channel is the convex mixture
\[
\oplus_{i\leftarrow \mu} C_i=\sum_i \mu(i) C_i,
\]
and posterior vulnerability is convex in the channel, whereas under visible choice,
\[
(\boxplus_{i\leftarrow \mu} C_i)(x,(y,i))=\mu(i)\,C_i(x)(y),
\]
posterior vulnerability is linear in the mixture [1802.10465], [2012.12060].

This distinction supports a zero-sum game-theoretic theory of leakage. Each attacker-defender action pair \((d,a)\) induces a channel \(C_{d,a}\), and the payoff is \(u(d,a)=V(\pi,C_{d,a})\). Simultaneous visible games have expected payoff \(U(\delta,\alpha)=\sum_{d,a}\delta(d)\alpha(a)u(d,a)\); simultaneous hidden games replace this by
\[
U(\delta,\alpha)=\sum_a \alpha(a)\,V\!\Bigl(\pi,\sum_d \delta(d) C_{d,a}\Bigr).
\]
The literature establishes a hierarchy of equilibrium leakage:
\[
{\rm Game\ VI}\le {\rm Game\ IV}={\rm V}\le {\rm Game\ III}\le {\rm Game\ I}\le {\rm Game\ II}.
\]
In the concrete \(2\times 2\) example with payoff matrix
\[
u=
\begin{pmatrix}
1/2 & 1\\
1 & 2/3
\end{pmatrix},
\]
the equilibrium values are \(1/2\), \(4/7\), \(2/3\), \(4/5\), and \(1\), in that order. These results formalize two basic facts already present in channel algebra: defender randomization can reduce leakage, and exposing the defender’s randomization can only help the attacker.

Dynamic leakage extends the same program to single realized runs. The traditional dynamic quantity,
\[
L^{\rm trad}_g(y;C,\pi)=V_g(\pi(\cdot\mid y))-V_g(\pi),
\]
can be negative. The newer strategy-based definition separates the adversary’s belief \(q\) from the baseline distribution \(p\) against which success is measured. With posterior \(\mu=\pi(\cdot\mid y)\),
\[
L_{{\rm dyn},g}(y;\pi)=V^{\rm st}_g(\mu\Vert \mu)-V^{\rm st}_g(\mu\Vert \pi)
=V_g(\mu)-V^{\rm st}_g(\mu\Vert \pi).
\]
This quantity satisfies non-interference, is non-negative in the single-step setting, obeys a single-step data-processing inequality, and recovers the standard expected-case and max-case static leakages after averaging or maximizing over \(y\) [2510.20922].

## 4. Quantum and cryptographic formulations

A major strand of leakage theory treats leakage as a quantum channel phenomenon. One route starts from a classical leakage model \(L\) in which an adversary may request \(l=\{(\ell_j,p_j)\}_{j=1}^m\) and learn \(\ell_j(W_{\mathcal C}(x,y))\), where \(W_{\mathcal C}(x,y)\) is the vector of wire values. The corresponding quantum phase-noise channel is
\[
\mathcal N(\rho)=\frac{1}{d}\sum_{j=1}^m p_j \sum_{k=0}^{d-1} F_j^k\,\rho\,(F_j^k)^\dagger,
\]
with \(F_j^k|s\rangle=\omega^{k\ell_j(s)}|s\rangle\). If a fault-tolerant quantum implementation \(\widetilde{\mathcal C}\) of \(\mathcal C\) is \(\epsilon\)-reliable under this phase-noise model, then the induced classical protocol is a \(2\sqrt{\epsilon}\)-leakage-resilient compiler against \(L\). The paper further gives an implementation based on the concatenated Steane \([[7,1,3]]\) code and quotes an independent phase-error threshold \(p_{\rm th}\approx 10^{-5}\) [1404.7516].

A second route measures leakage under detection threat. For an ensemble \(\{p_x,\rho^x\}\), a POVM \(F=\{F_y\}\) is \((\alpha,\delta)\)-weakly gentle if, with probability at least \(1-\delta\), the post-measurement disturbance of every state in the family is at most \(\alpha\) in trace distance. The resulting gentle quantum leakage is
\[
\mathcal L_{(\alpha,\delta)}(X\to A)_\rho
=\sup_{F\in G_{(\alpha,\delta)}(S)} I_\infty(X;Y),
\]
where
\[
I_\infty(X;Y)=\log_2\sum_y \max_x \operatorname{Tr}(\rho^x F_y).
\]
This measure satisfies positivity, independence, and unitary invariance. Under global depolarizing noise \(\mathfrak D_p(\rho)=pI/d+(1-p)\rho\), the leakage obeys
\[
\mathcal L_{(\alpha,\delta)}(X\to A)_{\mathfrak D_p(\rho)}
=\log_2\!\bigl[p+(1-p)\,2^{\mathcal L_{(\alpha,\delta)}(X\to A)_\rho}\bigr],
\]
so depolarization monotonically reduces leakage. The same work derives a lower bound via asymmetric approximate cloning and reports that, for BB84 encoding, \(\mathcal L_{0.1,\delta}\gtrsim 0.7608\) bits for any \(\delta\in[0,1]\) [2403.11433].

A third route generalizes \(\alpha\)-leakage to quantum privacy mechanisms. For a cq-state
\[
\rho_{X,Y}=\sum_x P_X(x)\,|x\rangle\langle x|_X\otimes \rho_Y^x,
\]
the maximal expected \(\alpha\)-gain is characterized by a measured conditional Rényi entropy \(H_\alpha^M(X\mid Y)\), and
\[
L_\alpha(X\to Y)=\exp[(\alpha-1)I_\alpha^M(X;Y)].
\]
Maximal \(\alpha\)-leakage is
\[
L_\alpha^{\max}(\mathcal M)=\exp[(\alpha-1)C_\alpha^M(\mathcal M)],
\]
where \(C_\alpha^M\) is the measured Rényi capacity. The framework establishes a data-processing inequality, a composition property, and, for \(n\) i.i.d. uses, the additivity relation
\[
L_\alpha^{\max}(\mathcal M^{\otimes n})=n\,L_\alpha^{\max}(\mathcal M).
\]
In the i.i.d. limit, the regularized quantities coincide with \(\alpha\)-tilted sandwiched Rényi information and sandwiched Rényi capacity [2403.14450].

## 5. Leakage in machine learning pipelines and model artifacts

In machine learning, “data leakage” often denotes contamination of training or evaluation by information unavailable under the intended deployment protocol. A controlled study of RF drone identification formalizes the optimism of segment-level cross-validation when a small number of continuous recordings are split into many short segments. With \(R\) independent recordings per class, segment-level CV can learn the degenerate conditional \(P(y\mid g)\), where \(g\) is the recording index, rather than the intended \(P(y\mid \mathbf x)\). Using Cover’s function-counting theorem, the study shows that exact recording memorization can occur when \(2R\) is less than or approximately equal to \(d\), the feature dimension. In synthetic experiments, naive balanced accuracy rose toward \(1.0\) while honest recording-grouped evaluation declined to chance. On DroneRF, AR-versus-Bebop type identification collapsed from naive macro-F1 \(0.742\) to honest macro-F1 \(0.455\), approximately the two-class chance level \(0.50\); the reported ablation attributed essentially all inflation to segment-level leakage [2607.01025].

A different problem is whether leakage can be detected from predictions and outcomes alone. In the decision-theoretic framework based on the joint law of \((\hat p,y)\), threshold-weighted expected net benefit is
\[
\mathrm{ENB}_\eta
=\frac1n\sum_{i=1}^n \bigl[y_i H(\hat p_i)-(1-y_i)G(\hat p_i)\bigr].
\]
The paper proves an impossibility result: if a leaky procedure is recalibrated and marginally matched to an honest predictor, then no function of \((\hat p,y)\) can distinguish them. Thus broad calibrated leakage is detectable only against an externally supplied ceiling on achievable discrimination. What remains prior-free detectable is a near-deterministic subgroup, visible as a sustained unit-purity head in the top-\(k\) purity curve \(\rho(k)=k^{-1}\sum_{i=1}^k y_{(i)}\). In the UK Biobank incident-delirium example, the empirical detection floor was \(\Delta C\approx 0.007\): at \(+2\) years, \(\Delta C=0.0056\) was not detected, while at \(+3\) years, \(\Delta C=0.0077\)–\(0.008\) produced a detectable breadth of \(1.2\%\); the full leak raised concordance to \(0.9249\) with breadth \(37.5\%\) [2606.11267].

Leakage also appears inside learned representations and distributed training protocols. In concept bottleneck models, unintended leakage is quantified by conditional mutual information,
\[
I(z;y\mid c)=H(y\mid c)-H(y\mid z,c),
\]
where \(z\) is the concept embedding and \(c\) the intended concept set. The empirical estimator trains one classifier for \(p(y\mid c)\) and another for \(p(y\mid z,c)\); among the tested estimators, XGBoost produced the smoothest monotonic trends. In one synthetic configuration \((d=2500,k=50)\), the estimated leakage dropped from approximately \(1.2\) bits at \(b=50\) to approximately \(0.2\) bits at \(b=400\), and in soft-joint CBMs with \(k=100\), leakage fell from approximately \(0.35\) bits at \(\lambda=0.01\) to approximately \(0.15\) bits at \(\lambda=1.0\) [2504.09459]. In federated learning, leakage is tied to invertibility of the mapping from batch data to model update. If the Jacobian \(J=\partial \Delta\theta/\partial X\) satisfies \(\operatorname{rank}(J)<m\), then distinct batches can generate the same update; a sufficient condition for non-identifiability is \(Bp+B>d\). The same work gives an optimization-theoretic upper bound on privacy leakage in terms of batch size, distortion extent, and regret terms [2407.16735].

## 6. Structural themes, impossibility results, and boundary conditions

Across these literatures, leakage is typically governed by a bottleneck observable rather than by the full microscopic state. In seal mechanics this bottleneck is the critical gap \(u_{\rm c}\) or effective conductivity \(\sigma_{\rm eff}\); in QIF it is posterior vulnerability \(V(\pi,C)\); in quantum privacy it is a measured Rényi information or capacity; in benchmark auditing it is the law of \((\hat p,y)\) or the top-\(k\) purity head; and in concept methods it is \(I(z;y\mid c)\). This suggests a common architecture: a high-dimensional mechanism is reduced to a small set of transport, inference, or discrimination coordinates that determine the leakage observable.

Thresholds are equally recurrent. Rough-contact leakage changes character near the non-contact percolation point \(A/A_0\approx 0.42\); RF benchmark leakage changes character near the separability threshold \(2R\approx d\); output-only audits become decisive only when a unit-purity head persists over a non-null fraction of ranked predictions; and gas-seal models become highly sensitive when \(\theta(x)\to \theta_c\). At the same time, several papers state strict limitations on what can be inferred. Near the sealing point, the exponent and closure law depend on the microscopic details of the last constriction, so statistical surface properties alone do not determine how the leak ceases [1512.00186]. In prediction auditing, calibrated broad leakage is output-indistinguishable from an honestly stronger predictor unless an exogenous ceiling \(C_{\max}\) is supplied [2606.11267].

A related impossibility appears in encrypted-traffic analysis, but there it is formulated positively: under mapping non-degeneracy, protocol-layer distinguishability, Lipschitz continuity, observation non-degeneracy, and the propagation condition \(C<\bar\Delta/(2L_\varphi)\), the mutual information \(I(X;Y)\) is strictly positive and admits an explicit lower bound. The corollary states that, in efficiency-prioritized systems, leakage is inevitable when at least one application pair is distinguishable [2602.14055]. A plausible implication is that “zero leakage” is often not a realistic engineering target. In the physical literature it would require suppressing the final constriction; in encrypted traffic it would require heavy padding or delays, semantic homogenization, or elimination of useful observability; and in ML evaluation it would require grouping and acquisition protocols that remove source identity from the train-test boundary.

Taken together, leakage theory is not a single formalism but a family of mathematically explicit programs for locating, quantifying, and sometimes bounding unintended transport or inference. Its mature forms are characterized by multiscale reduction, explicit threshold phenomena, and equally explicit statements of detectability limits.

Source: https://www.emergentmind.com/topics/leakage-theory