Interpreting Emergent Features in Deep Learning-based Side-channel Analysis
Sengim Karayalcin, Marina Krcek, Stjepan Picek
Abstract
Side-channel analysis (SCA) poses a real-world threat by exploiting unintentional physical signals to extract secret information from secure devices. Evaluation labs also use the same techniques to certify device security. In recent years, deep learning has emerged as a prominent method for SCA, achieving state-ofthe-art attack performance at the cost of interpretability. Understanding how neural networks extract secrets is crucial for security evaluators aiming to defend against such attacks, as only by understanding the attack can one propose better countermeasures. In this work, we apply mechanistic interpretability to neural networks trained for SCA, revealing how models exploit what leakage in side-channel traces. We focus on sudden jumps in performance to reverse engineer learned representations, ultimately recovering secret masks and moving the evaluation process from blackbox to white-box. Our results show that mechanistic interpretability can scale to realistic SCA settings, even when relevant inputs are sparse, model accuracies are low, and side-channel protections prevent standard input interventions. extract input features, i.e., individual shares s i related to device internal randomness, from model activations, providing a path to move from black-box to white-box evaluations. The overall analysis process is illustrated in Figure 1.
To summarize, our main contributions are:
• We explore the feasibility of applying MI in a challenging real-world setting where input interventions to features are not possible due to SCA countermeasures.
• By investigating the changes in model outputs during sudden jumps in model performance, we find how networks combine leakage in DLSCA.
• We directly retrieve the internal secret share values by applying activation patches 3 to intermediate layer activations across several targets.
• We provide more detailed insights into the specific physical leakage that neural networks exploit for widely used (DL)SCA benchmark datasets. Notably, we do this without assuming a priori mask knowledge [54,35] or requiring custom architectures [52,53].
• We find identical structures emerging during sudden generalizations for models trained on side-channel traces captured on different implementations and in different SCA domains (electromagnetic vs. power), providing further evidence for the weak universality hypothesis [7].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 455f7180-9920-4559-af6c-25f0895bb077Cited by top-tier papers1
Ask how each one uses itBuilds on15
- Towards Automated Circuit Discovery for Mechanistic InterpretabilityArthur Conmy, Augustine N. Mavor-Parker, Aengus Lynch, Stefan Heimersheim et al.NeurIPS 2023 · 861 citations
- Causal Abstractions of Neural NetworksAtticus Geiger, Hanson Lu, Thomas Icard, Christopher PottsNeurIPS 2021 · 516 citations
- The Clock and the Pizza: Two Stories in Mechanistic Explanation of Neural NetworksZiqian Zhong, Ziming Liu, Max Tegmark, Jacob AndreasNeurIPS 2023 · 181 citations
- The Quantization Model of Neural ScalingEric J. Michaud, Ziming Liu, Uzay Girit, Max TegmarkNeurIPS 2023 · 179 citations
- A Toy Model of Universality: Reverse Engineering how Networks Learn Group OperationsBilal Chughtai, Lawrence Chan, Neel NandaICML 2023 · 144 citations
Related papers
- SoK: Neural Network Extraction Through Physical Side ChannelsPéter Horváth, Dirk Lauret, Zhuoran Liu, Lejla BatinaUSENIX Security 2024 · 11 citations
- Cross-Device Profiled Side-Channel Attacks using Meta-Transfer LearningHonggang Yu, Haoqi Shan, Maximillian Panoff, Yier JinDAC 2021 · 38 citations
- Learning From A Big Brother - Mimicking Neural Networks in Profiled Side-channel AnalysisDaan van der Valk, Marina Krcek, Stjepan Picek, Shivam BhasinDAC 2020 · 9 citations
- On the Success Rate of Side-Channel Attacks on Masked Implementations: Information-Theoretical Bounds and Their Practical UsageAkira Ito, Rei Ueno, Naofumi HommaCCS 2022 · 18 citations
- There's always a bigger fish: a clarifying analysis of a machine-learning-assisted side-channel attackJack Cook, Jules Drean, Jonathan Behrens, Mengjia YanISCA 2022 · 35 citations
