Head-to-head · measured daily

Every PQC pair, measured.

7 head-to-head comparisons across ML-KEM, ML-DSA, and SLH-DSA. Each opens a side-by-side detail view with latency, percentiles, and key sizes — measured daily on the same hardware.

Run date
2026-08-22
Commit
Host
Xeon Platinum 8259CL @ 2.50GHz
Instance
t3.medium
liboqs
0.15.0
CPU steal
6.9%
The board

Every algorithm, one metric at a time.

Pick the metric and operation you actually care about. The axis is yours to set — a log axis is offered by default only where a linear one would hide the small bars.

LatticeHash-basedMean latency · µs · keygen · log axis
ML-KEM-512
Lattice · level 1
13.8 µs
ML-KEM-768
Lattice · level 3
21.1 µs
ML-KEM-1024
Lattice · level 5
25.8 µs
ML-DSA-44
Lattice · level 2
37.4 µs
ML-DSA-87
Lattice · level 5
87.8 µs
ML-DSA-65
Lattice · level 3
92.0 µs
2.74 ms
183.93 ms

Key encapsulation mechanisms

3 ML-KEM pairs measured daily across NIST security levels.

ML-KEM across security levels

Same lattice scheme, different NIST categories. The cost of higher security.

Digital signatures

4 signature pairs across ML-DSA and SLH-DSA — lattice-based and hash-based schemes side by side.

ML-DSA across security levels

Same lattice scheme, different NIST categories. Higher security means bigger keys and slower signing.

SLH-DSA: fast vs small

The defining SLH-DSA tradeoff — fast signatures with larger signature sizes, or small signatures with much slower signing.

Hybrid vs classical

What turning it on costs inside a real handshake.

Amplification factor is server bytes returned per client byte sent — not published elsewhere for these suites.

Hybrid vs classical.

Real TLS and SSH handshake suites — hybrid post-quantum key exchange next to the classical baseline everyone already runs. Amplification factor (server bytes returned per byte the client sends) is a first-to-publish number here: not measured elsewhere for these suites.

TLSX25519MLKEM768
7.0% faster vs classical
median latency266.1 µs
key-exchange payload bytes2.28 KB
amplification factor0.92×
client → server1.19 KB → 1.09 KB
commit 7e3d474
TLSSecP256r1MLKEM768
24.9% faster vs classical
median latency215.0 µs
key-exchange payload bytes2.35 KB
amplification factor0.92×
client → server1.22 KB → 1.13 KB
commit 7e3d474
TLSMLKEM768
78.5% faster vs classical
median latency61.4 µs
key-exchange payload bytes2.22 KB
amplification factor0.92×
client → server1.16 KB → 1.06 KB
commit 7e3d474
TLSX25519classical
classical baseline
median latency286.1 µs
key-exchange payload bytes64 B
amplification factor1.00×
client → server32 B → 32 B
commit 7e3d474
SSHmlkem768x25519-sha256
107.9% slower vs classical
median latency335.9 µs
key-exchange payload bytes2.28 KB
amplification factor0.92×
client → server1.19 KB → 1.09 KB
commit 7e3d474
SSHcurve25519-sha256classical
classical baseline
median latency161.6 µs
key-exchange payload bytes64 B
amplification factor1.00×
client → server32 B → 32 B
commit 7e3d474
Hash-based signatures (LMS/XMSS)queued — no measurements yet

MechanismNotEnabledError: LMS_SHA256_H10_W8 Shown here rather than left silently absent — see /q-shield/protocols once measurements land.

Detail view

Side by side.

Pick any two PQC algorithms and an operation. Numbers come from the latest daily run, same hardware, same iteration count.

Algorithm A
Algorithm B
Operation
ML-DSA-65· NIST L3·SignaturevsSLH-DSA-SHAKE-128s· NIST L1·Signature

Different families AND different NIST levels. Useful for raw performance intuition, but adjust mentally for the security delta.

Headline · keygen mean

ML-DSA-65 is 2.0k× faster than SLH-DSA-SHAKE-128s on keygen.

Latency profile

keygen mean / p95 / p99 (µs)

Log scale — values span >100×
ML-DSA-65SLH-DSA-SHAKE-128s

Full statistics

MetricML-DSA-65SLH-DSA-SHAKE-128s
Mean92.0 µs183.93 ms
Median90.2 µs175.05 ms
p95120.4 µs215.80 ms
p99137.8 µs321.15 ms
Stdev12.8 µs43.24 ms
Ops / sec10,8705.4
Public key1.91 KB32 B
Signature3.23 KB7.67 KB