Machine-Learning-Based Side-Channel Attack Detection for FPGA SoCs

Lars Bauer, Hassan Nassar, Nadir Zamin Khan, Jürgen Becker, Jörg Henkel · IEEE transactions on circuits and systems for artificial intelligence. · 2024

Embedded systems are threatened by side-channel attacks that allow the extraction of private keys from tampered systems. This particularly applies to FPGA-based SoCs that are widely used due to their attractive features like flexibility, etc. Power analysis (PA) attacks use power fluctuations that occur during cryptographic operations to incrementally reconstruct bits of a private key. Similarly, electromagnetic analysis (EMA) attacks use electromagnetic radiation. Countermeasures against PA and EMA attacks come at noticeable power, performance, and/or area overhead, and thus they should only be enabled when needed. This paper proposes a novel concept that uses machine learning (ML) to detect whether or not a system was tampered for a PA or an EMA attack. The main challenge is to distinguish a system that has been indeed tampered from a system that is untampered but operating under different conditions (e.g., higher ambient temperature) that may make it appear as if the system was tampered (e.g., removed heat sink), especially as we cannot trust off-chip sensors as they are under the control of the potential attacker (e.g., the end-user of the embedded system). Therefore, we can only use trustable information that can be acquired from within the system and we have to implement the entire measurement and classification flow within the FPGA-based SoC. We investigate, train, and deploy a lightweight on-chip ML-based approach along with an on-chip measurement infrastructure that uses load generators and the available on-chip sensors to distinguish tampered systems from untampered ones. For detecting EMA (PA) attacks, we reach a high accuracy, i.e., the number of correctly classified systems relative to all systems, of 0.9880 (0.9090) and a high precision, i.e., the number of systems correctly classified as tampered relative to all systems classified as tampered, of 0.9883 (0.9090). This comes at a reasonable resource overhead of$1$% ($6$%) of the available LUTs and an on-chip classification time of only$122 \textrm{ms}$($40 \textrm{s}$). The entire system including the on-chip measurement infrastructure, the ML-based classification, and the tampering for PA and EMA attacks are implemented and evaluated on FPGA boards.

Read the paper · More papers on PaperTik