Searcharxiv⌕ Search

arXiv subjects

Ján Mikulec

Publications and source records attributed to Ján Mikulec.

2 recordsLinked to original sources

Beyond TVLA: Anderson-Darling Leakage Assessment for Neural Network Side-Channel Leakage Detection

Test Vector Leakage Assessment (TVLA) is widely used for side-channel leakage detection, but its reliance on Welch's t-test makes it primarily sensitive to differences in the means of two leakage populations. Consequently, TVLA may fail to detect leakage that manifests through changes in other characteristics of the underlying distributions. We introduce Anderson-Darling Leakage Assessment (ADLA), a distribution-sensitive leakage assessment methodology based on the two-sample Anderson-Darling test. To facilitate direct comparison with conventional TVLA, we derive an ADLA decision threshold corresponding to the nominal significance level associated with the standard TVLA threshold of 4.5. We evaluate ADLA on a shuffling-protected embedded multilayer perceptron implementation under both fixed-versus-fixed and fixed-versus-random input configurations. Across the evaluated settings, ADLA produces clearer threshold exceedances than TVLA and reveals leakage locations that are not detected by the mean-based test. To assess the practical relevance of these additional leakage locations, we perform correlation power analysis using points of interest selected from the ADLA and TVLA statistics. The points identified by ADLA enable recovery of the exponent byte of the targeted model weight despite the presence of shuffling. These results demonstrate that distribution-sensitive testing can complement conventional TVLA by revealing exploitable side-channel leakage that may remain hidden from mean-based analysis.

cs.CR↗

Guess My Weight: Profiled Side-Channel Recovery of Floating-Point Neural-Network Weights

Neural-network parameters deployed on embedded devices may be exposed through physical side-channel leakage during inference. Existing side-channel attacks on floating-point neural-network parameters have often targeted reduced numerical precision, while recovering the complete IEEE-754 representation remains considerably more challenging because of the large and structured 32-bit candidate space. We present a profiled template attack for bit-exact recovery of an IEEE-754 single-precision neural-network weight from power measurements. The attack targets the floating-point multiplication between a known input and a first-layer weight. During profiling, multivariate Gaussian templates are learned from randomized network configurations using Hamming-weight classes of the multiplication result, while the remaining network parameters act as nuisance variables. To efficiently search the structured 32-bit floating-point candidate space, we use a hierarchical coarse-to-fine-to-exact procedure that progressively increases both the numerical and leakage-model resolution. Experiments on a ChipWhisperer-Lite with an Arm Cortex-M4 demonstrate recovery of the exact float32 representation of the target weight. In the evaluated setting, the attack reaches a bit-exact success rate of 99% with 171 traces and 100% from 263 traces onward. These results demonstrate that profiling can enable practical full-precision extraction of floating-point neural-network parameters from physical leakage.

cs.CR↗