138
L. Batina et al.
where ¯
x and ¯
y are the empirical means of x and y, respectively.
• SOSD. In [230], the authors proposed as a selection method the sum of squared
differences, simply as:
SOSD(x, y) =
i,j >i
( ¯
x y i − ¯
x y j )
2 ,
(8.4)
where ¯
x y i is the mean of the traces where the model equals y i . Because of the
square term, SOSD is always positive. Another advantage of using the square is
that it enlarges big differences.
• SOST. SOST is the normalized version of SOSD [230] and is thus equivalent by
the pairwise student T-test:
SOST (x, y) =
i,j >i
⎛
⎝ ( ¯
x y i − ¯
x y j )/
σ 2
y i
n y i
+
σ 2
y j
n y j
⎞
⎠
2
(8.5)
with n y i and n y j being the number of traces where the model equals to y i and y j ,
respectively.
There are several more relevant works in the domain of feature selection and
SCA. The work of Lerman et al. [367] compared template attacks and machine
learning on dimensionality reduction. They concluded that template attacks are the
method of choice as long as a limited number of features can be identified in leakage
traces containing most of the relevant information. Zheng et al. looked into feature
selection techniques but they did not consider machine learning options [600].
Picek et al. conducted a detailed analysis of various feature selection techniques
where some are also based on machine learning (so-called wrapper and hybrid
methods) [477]. They concluded that commonly used feature selection techniques
in SCA are rarely the best ones and they mentioned L1 regularization as a powerful
feature selector in many scenarios.
8.3 Template Attacks
In this section, we start by explaining the details of template attacks, and after that
we give details about two techniques that emerged from template attacks—pooled
template attacks and stochastic attacks.
L. Batina et al.
where ¯
x and ¯
y are the empirical means of x and y, respectively.
• SOSD. In [230], the authors proposed as a selection method the sum of squared
differences, simply as:
SOSD(x, y) =
i,j >i
( ¯
x y i − ¯
x y j )
2 ,
(8.4)
where ¯
x y i is the mean of the traces where the model equals y i . Because of the
square term, SOSD is always positive. Another advantage of using the square is
that it enlarges big differences.
• SOST. SOST is the normalized version of SOSD [230] and is thus equivalent by
the pairwise student T-test:
SOST (x, y) =
i,j >i
⎛
⎝ ( ¯
x y i − ¯
x y j )/
σ 2
y i
n y i
+
σ 2
y j
n y j
⎞
⎠
2
(8.5)
with n y i and n y j being the number of traces where the model equals to y i and y j ,
respectively.
There are several more relevant works in the domain of feature selection and
SCA. The work of Lerman et al. [367] compared template attacks and machine
learning on dimensionality reduction. They concluded that template attacks are the
method of choice as long as a limited number of features can be identified in leakage
traces containing most of the relevant information. Zheng et al. looked into feature
selection techniques but they did not consider machine learning options [600].
Picek et al. conducted a detailed analysis of various feature selection techniques
where some are also based on machine learning (so-called wrapper and hybrid
methods) [477]. They concluded that commonly used feature selection techniques
in SCA are rarely the best ones and they mentioned L1 regularization as a powerful
feature selector in many scenarios.
8.3 Template Attacks
In this section, we start by explaining the details of template attacks, and after that
we give details about two techniques that emerged from template attacks—pooled
template attacks and stochastic attacks.
