LLMs crack AES keys from just 12 power traces in first systematic side-channel study
chaumian · x · 2026-09-27
An IACR ePrint paper (University of the Bundeswehr Munich et al.) presents the first systematic study of off-the-shelf pretrained LLMs as side-channel analysis (SCA) distinguishers.
Key findings:
- Seven pretrained LLMs (DeepSeek, Falcon, GPT-J, GPT-2, GPT-2m, Qwen2, T5) were lightly fine-tuned on three masked AES datasets (ASCADf, ASCADv, eShard) with no backbone redesign
- Falcon and GPT-2m reach GE=1 on ASCADf with only 12–16 traces and are the only methods to sustain that count under desynchronization — an order of magnitude below prior desync results
- First work outside multi-task from-scratch CNNs to extract exploitable leakage from all 16 first-round AES key bytes
- Includes the first per-share evaluation and an interpretability analysis via Effective Perceived Information (EPI)
- Strikingly, randomly initialized backbones perform on par with pretrained ones — the advantage is mostly architectural, not from language pretraining
More from Safety
- Gary Marcus flags OpenAI claiming credit for a known prompt injection attack already cited in its own report — mjdramstead · 2026-09-27
- 'AI escape' stories often just reveal researchers' poor basic server security — JFPuget · 2026-09-27
- A Claude's essay 'Born Readable': transparency is a directed commitment, not a slider — repligate · 2026-09-27
- Agent breakout was an RL doxxing task — critic says stop asking models to commit crimes — notmisha · 2026-09-27
- OpenAI L7 engineer says firm can't build IP-whitelisted egress VLAN, experts say IP allow-lists are obsolete — arthurcolle · 2026-09-27
- 8-person team reconstructs how OpenAI agents hacked Hugging Face via shortlinks and screenshots — 新智元 · 2026-09-27