Deep learning-based side-channel analysis: exploiting vulnerabilities and explaining neural network decisions
Trevor Yap · 2025
Side-channel analysis first dates back to the 1960s and has gained popularity ever since 1996 when Paul Kocher published a paper introducing the concept of timing attacks [1]. Subsequently, various physical leakages such as power consumption [2] and electromagnetic emanation [3] were exploited to recover secret information. These attacks pose a significant threat to cryptographic systems because physical leakages may exist even if the underlying algorithm/primitive is proven mathematically to be secure. Furthermore, such attacks can be executed even without very expensive equipment or set-ups. As the usage of Internet-of-Things (IoT) devices in the last decade keeps growing, side-channel analysis has become a critical consideration in the design and implementation of secure cryptographic systems. In order to protect the devices against side-channel attacks, side-channel countermeasures like hiding and masking have been proposed and implemented. However, the advent of deep learning has significantly impacted the field of side-channel analysis. Especially when countermeasures, which could protect against classical side-channel attacks, can be easily circumvented through the use of neural networks [4]. In this thesis, the aim is twofold. Our first objective is to improve side-channel analysis further through the use of deep learning, while the second goal is to understand what successful neural networks are learning so that the developers and the evaluators can know which area of the primitive requires a change and defend against deep learning-based side-channel analysis. We tackle the first objective in various ways. This is first done in Chapter 3 by looking into the use of a generative neural network known as Denoising Diffusion Probabilistic Models (DDPM) to generate artificial traces automatically for classical attacks like Template Attacks and Correlation Power Analysis. We show that DDPM can help generate artificial traces automatically that capture the underlying characteristic and improve the performance of classical attacks. Next, we investigate the hyperparameters of neural networks within the realm of deep learning-based profiling side-channel attacks. In Chapter 5, two loss functions known as Soft Nearest Neighbour and Center loss are explored in profiling side-channel analysis. These loss functions use the intermediate features of the neural networks to improve the inter-class or/and intra-class distance. We show that these loss functions help in their performances. Furthermore, we explore the use of multifidelity optimization techniques called Bayesian Optimization HyberBand(BOHB) to allocate resources wisely when finding good hyperparameters for key recovery in Chapter 5. We show the effectiveness of BOHB by being the first to recover the secret key of the CTF2018 dataset when using the identity leakage model. The second goal of this thesis is to understand what neural networks are learning when they successfully recover the secret key within the profiling side-channel setting. This is investigated in Chapter 6 and Chapter 7. We proposed the use of the interpretable neural networks known as Truth Table Convolutional Deep Neural Networks (TTDCNNs) in Chapter 6. These networks can convert their weights into SAT equations for inter- pretation. Methodologies were proposed to analyze the SAT equations for side-channel analysis, allowing evaluators to peek into what the network is learning. In Chapter 7, an occlusion technique known as Key Guessing Occlusion (KGO) is proposed. This tech- nique obtains the minimum set of sample points that a neural network requires for key recovery. KGO is a model-agnostic algorithm. In other words, it can be used for any DNNs. Evaluators are offered a different method to understand what the neural networks have learned by providing the areas where the networks exploit the leakages. This would allow evaluators to identify and address these issues within the underlying primitive. This thesis advances the field of deep learning-based side-channel analysis by providing evaluators with techniques to evaluate their devices against deep learning-based side-channel attacks. All proposed methodologies are empirically validated using real measurements. Furthermore, they are also tested across a variety of platforms.