142
L. Batina et al.
is the fact that they attack AES [235, 274, 279, 285, 363–365, 367, 475, 476, 479,
481]. More recently, deep learning (DL) techniques started to capture the attention
of the SCA community. Accordingly, the first results confirmed expectations,
with most of the early attention being paid to convolutional convolutional neural
networks [122, 329, 386, 482].
As far as we know, when considering machine learning-based attacks on other
ciphers, there are only a few papers. Heuser et al. consider Internet of Things
scenarios and lightweight ciphers where they compare 11 lightweight ciphers and
AES in terms of their SCA resilience and conclude that lightweight ciphers cannot
be considered to be significantly less resilient than AES [274, 276].
Semi-supervised Techniques
Semi-supervised learning is positioned in the middle between supervised and
unsupervised learning. There, the basic idea is to take advantage of a large quantity
of unlabeled data during a supervised learning procedure [517]. This approach
assumes that the attacker is able to possess a device to conduct a profiling phase but
has limited capacities. This may reflect a more realistic scenario in some practical
applications, as the attacker may be limited by time or resources, or also face
implemented countermeasures, which prevent him from taking an arbitrarily large
amount of side-channel measurements while knowing the secret key of the device.
The first application of semi-supervised SCA was done by Lerman et al.,
where the authors conclude that the semi-supervised setting cannot compete with
a supervised setting [366]. Note, the authors compared the supervised attack with
n + m labeled traces for all classes with a semi-supervised attack with n labeled
traces for one class and m unlabeled traces for other unknown classes (i.e., in total
n + m traces). Picek et al. conduct an analysis of two semi-supervised paradigms
(self-training and graph-based learning) where they show that it is possible to
improve the accuracy of classifiers if semi-supervised learning is used [480]. What
is especially interesting is that they show how semi-supervised learning is able to
significantly improve the behavior of the template attack when the profiling set is
(very) small.
8.4.1 Conducting Sound Machine Learning Analysis
Since it is not possible (in general) to expect machine learning techniques to give us
theoretical observations or proofs of results, we need to rely on a set of procedures
to run experiments such that the results are convincing and easy to reproduce. In the
next section, we briefly discuss several steps to be considered in order to make the
analysis more reproducible.
Datasets
When preparing the data for machine learning analysis, it is necessary to discuss
the number of measurements, the number of features, and the number of classes
(if known). Additionally, if the data come from different distributions, one needs to
L. Batina et al.
is the fact that they attack AES [235, 274, 279, 285, 363–365, 367, 475, 476, 479,
481]. More recently, deep learning (DL) techniques started to capture the attention
of the SCA community. Accordingly, the first results confirmed expectations,
with most of the early attention being paid to convolutional convolutional neural
networks [122, 329, 386, 482].
As far as we know, when considering machine learning-based attacks on other
ciphers, there are only a few papers. Heuser et al. consider Internet of Things
scenarios and lightweight ciphers where they compare 11 lightweight ciphers and
AES in terms of their SCA resilience and conclude that lightweight ciphers cannot
be considered to be significantly less resilient than AES [274, 276].
Semi-supervised Techniques
Semi-supervised learning is positioned in the middle between supervised and
unsupervised learning. There, the basic idea is to take advantage of a large quantity
of unlabeled data during a supervised learning procedure [517]. This approach
assumes that the attacker is able to possess a device to conduct a profiling phase but
has limited capacities. This may reflect a more realistic scenario in some practical
applications, as the attacker may be limited by time or resources, or also face
implemented countermeasures, which prevent him from taking an arbitrarily large
amount of side-channel measurements while knowing the secret key of the device.
The first application of semi-supervised SCA was done by Lerman et al.,
where the authors conclude that the semi-supervised setting cannot compete with
a supervised setting [366]. Note, the authors compared the supervised attack with
n + m labeled traces for all classes with a semi-supervised attack with n labeled
traces for one class and m unlabeled traces for other unknown classes (i.e., in total
n + m traces). Picek et al. conduct an analysis of two semi-supervised paradigms
(self-training and graph-based learning) where they show that it is possible to
improve the accuracy of classifiers if semi-supervised learning is used [480]. What
is especially interesting is that they show how semi-supervised learning is able to
significantly improve the behavior of the template attack when the profiling set is
(very) small.
8.4.1 Conducting Sound Machine Learning Analysis
Since it is not possible (in general) to expect machine learning techniques to give us
theoretical observations or proofs of results, we need to rely on a set of procedures
to run experiments such that the results are convincing and easy to reproduce. In the
next section, we briefly discuss several steps to be considered in order to make the
analysis more reproducible.
Datasets
When preparing the data for machine learning analysis, it is necessary to discuss
the number of measurements, the number of features, and the number of classes
(if known). Additionally, if the data come from different distributions, one needs to
