Analyzing Mask-Breaking Mechanisms: A Methodology for Deep Learning Side-channel Analysis
Abstract
Side-channel analysis (SCA) of cryptographic implementations remains a persistent threat, necessitating the certification of new products by independent evaluation labs. In recent years, deep learning-based SCA (DLSCA) has become a standard approach for worst-case evaluations, due to its ability to defeat diverse countermeasures. While achieving state-of-the-art performance, this comes at the cost of the evaluator's understanding of the attacks themselves. In this work, we propose a novel methodology based on mechanistic interpretability to understand how neural networks recombine shares to defeat the masking countermeasure. Concretely, to isolate the role of individual layers, we freeze the first few layers of a trained model and retrain the remainder while injecting ground-truth information about specific secret shares. This allows us to determine where exploitable share-related information is represented in the network and how it can be used. To demonstrate our approach, we analyze EffCNN and EstraNet on ASCADv1f and ASCADv1r, and EffCNN on the non-shuffled ESHARD benchmark. We find that injecting clean information about one share reveals which information about the other share remains exploitable by the model, highlighting that the models represent substantially more information about individual shares than they originally exploit. Furthermore, our method confirms that the organization of share-related information within the models follows the physical leakage characteristics, without requiring the manual effort of previous approaches and thereby allowing interpretability analyses to scale to more realistic models. Overall, our work suggests that injecting ground-truth share information is a promising direction for interpreting DLSCA models, going beyond prior approaches by revealing not only where share information is represented but also how much of it remains unexploited.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.