A hardened app brackets a sensitive code region with two timestamps (e.g. a monotonic clock read via System.nanoTime() / mach_absolute_time) and measures the elapsed time to execute N instructions between them:
Δt = t(checkpoint B) − t(checkpoint A)
Under normal execution each instruction costs roughly a fixed CPU time ti, so Δtclean ≈ N·ti plus small scheduler jitter. The app calibrates a baseline over several clean runs and derives a statistical threshold:
µ, σ = mean, stdev of clean Δt samples
Threshold = µ + k·σ
A debugger attached via ptrace (Android) or a jailbreak-tier hook (iOS) intercepts the process to single-step or insert breakpoints, adding a per-instruction trap-and-resume overhead ttrap:
Δtdebugged ≈ N·(ti + ttrap)
Because ttrap is orders of magnitude larger than a normal instruction, Δtdebugged blows past µ + k·σ and the check flags tampering — this is the same timing side-channel behind real anti-debug primitives (ptrace(PTRACE_TRACEME) self-attach races, rdtsc-delta checks, syscall-latency probes). Raising k trades detection sensitivity for a lower false-positive rate on slow or throttled devices; too low a k trips on ordinary jitter, too high a k lets a patient attacker single-step under the threshold.
This 2D sibling reproduces the exact same statistical model as the 3D original — same Box-Muller jitter, same mean+kσ threshold, same false-positive bookkeeping — checked line-for-line against it (a standalone script re-running both formulas side by side found no discrepancy, so no fix was needed here). What it adds is a live histogram of the 24-sample clean baseline underneath the track: you can watch the threshold line sit at µ+kσ on the actual sample distribution, and see exactly how far a debugged run's Δt lands past it, instead of only reading the numbers off.
- Instructions per check — length of the guarded code region; longer regions accumulate more trap overhead when debugged, but also more natural jitter.
- Single-step trap overhead — µs added per instruction while a debugger is attached and stepping.
- Detection sensitivity k·σ — how many standard deviations above the clean baseline mean before the check fires.
- Attach Debugger — toggles the attack; the instruction stream turns red and the timing gate reacts on the next run.
- Baseline histogram — the bottom strip bins the 24 clean-calibration samples; the dashed line is the mean+kσ threshold and the solid marker is the last measured Δt.
Drag inside the track to pan, scroll to zoom — useful for lining up a close view of either checkpoint gate.