Score
Design, implement, and analyze countermeasures that reduce or eliminate unintended information leakage from hardware or software implementations via physical or logical side channels. Work includes creating constant-time routines, masking or obfuscating secret-dependent operations, adding balancing or noise, and producing correctness arguments plus empirical leakage evaluations to demonstrate mitigation effectiveness.
CMOS circuit power consumption exhibits data-dependent leakage, forming a critical vulnerability for power-side-channel attacks (e.g., differential power analysis). Existing countermeasures predominantly model leakage at the byte level, overlooking the decisive impact of single-bit leakage on overall security. Method: This paper introduces, for the first time, a fine-grained protection mechanism grounded in single-bit leakage modeling. We establish a bit-level leakage model to guide low-level netlist enhancement and implement customized masking and balancing at the gate level specifically targeting single-bit-sensitive paths. Contribution/Results: Our approach transcends traditional byte-level abstractions by suppressing information leakage at its root under classical leakage assumptions. Experimental evaluation demonstrates that cryptographic implementations protected by our method effectively resist side-channel attacks based on mainstream leakage models—including Hamming weight and Hamming distance—yielding substantial improvements in physical security.
Existing runtime side-channel vulnerability mitigation techniques often overlook hardware-specific characteristics, leading to over-mitigation, under-mitigation, or outright failure. This work proposes a novel hardware-software co-designed automated repair approach that, for the first time, integrates actual timing measurements from target embedded devices into the mitigation process. By combining empirical hardware timing analysis with software code transformation techniques, the method generates precise and efficient countermeasures applicable to C, C++, and Java source code. Experimental evaluation across five embedded and edge platforms demonstrates that the proposed approach significantly outperforms state-of-the-art tools such as PENDULUM and DifFuzzAR in terms of execution overhead, code size, and correctness.
Existing defenses against composite side-channel attacks—such as cache, single-step debugging, and ciphertext leakage—in Trusted Execution Environments (TEEs) either target isolated attack vectors or rely on oversimplified threat models, failing to balance security and practicality. Method: We propose the first dynamic obfuscation framework that simultaneously protects both code and data. It employs program-analysis-driven, fine-grained code block partitioning and integrates Oblivious RAM (ORAM) to jointly conceal execution flow and memory access patterns. The framework supports a generalized side-channel threat model and operates fully automatically. Contribution/Results: Our approach achieves provably optimal security under standard assumptions while significantly lowering deployment overhead. Experimental evaluation across realistic side-channel scenarios demonstrates effective prevention of execution-flow tracing, with overhead low enough to enable practical deployment in real-world TEEs.
This work addresses two critical challenges in timing-side-channel security analysis of binary programs: (1) decompiler-induced distortions that obscure constant-time (CT) or speculative constant-time (SCT) violations, and (2) incompleteness in CT/SCT verification due to non-transparent preprocessing. We introduce the formal notion of *transparent decompilation*, defined by the requirement that decompilation neither introduces nor eliminates CT/SCT violations—i.e., it preserves both program equivalence and security-relevant timing behaviors. Leveraging program equivalence and security-property preservation, we develop a static analysis framework integrating control- and data-flow constraints, and provide the first formal transparency proof for the RefleCT decompiler. Empirical evaluation reveals that mainstream decompilers implicitly eliminate violations, invalidating source-level analyses; meanwhile, existing CT analyzers suffer systematic false positives due to reliance on non-transparent preprocessors. Our work establishes the first verification paradigm for decompiler transparency and uncovers fundamental flaws in multiple widely used CT analysis tools.
This work reveals how modern compiler optimizations systematically undermine high-order constant-time (CT) implementations in cryptographic libraries, introducing secret-dependent timing side channels. To address this, we propose the first cross-architecture dynamic tracing analysis framework—supporting six CPU architectures—that integrates multi-architecture binary instrumentation, compiler optimization behavior modeling, and formal CT semantic verification. Empirically evaluating 44,604 real-world targets, we discover widespread compiler-induced CT violations across mainstream hardened libraries—including OpenSSL and Libsodium—demonstrating, for the first time at scale, that compilers are a primary root cause of CT defense failure. Our findings fundamentally challenge the prevailing “CT at source level guarantees security” paradigm. The framework provides both theoretical foundations and practical tooling for building compiler-aware side-channel resilience, enabling rigorous validation of CT guarantees throughout the compilation pipeline.
This work proposes SCAgent, a novel framework that leverages large language model (LLM) agents for automated side-channel discovery and verification—a task traditionally reliant on manual effort and challenging to scale in complex systems. SCAgent generates hypotheses through semantic reasoning over system documentation, mitigates hallucination via explicit verification mechanisms and semantic consistency constraints, and introduces time-shift-robust temporal features tailored for foundation models to enable efficient few-shot analysis. Evaluated on iOS, the framework successfully reproduces classic fingerprinting attacks and uncovers multiple previously unknown sensitive activities, demonstrating its capability to automatically and accurately identify side-channel vulnerabilities even with limited data.
This study investigates the effectiveness of code obfuscation techniques in impeding attackers’ comprehension of malicious logic and examines whether quantitative code complexity metrics can predict their impact on attack success rates and time-to-compromise. Through a controlled user study, it systematically evaluates, for the first time, the cumulative defensive efficacy of multiple obfuscation techniques—including control-flow flattening, string encryption, and virtualization—using both quantitative measures (e.g., comprehension time, success rate) and qualitative feedback (e.g., cognitive load assessments). It establishes an empirically validated link between objective complexity metrics (e.g., cyclomatic complexity, AST depth) and subjective attack difficulty. Results show that multi-layered obfuscation significantly increases attacker comprehension time (average +217%) and that certain metrics—particularly control-flow entropy—effectively predict attack failure probability. The work provides reproducible, evidence-based guidance for obfuscation strategy selection and software protection evaluation.
This work presents the first systematic evaluation of side-channel security for three verification schemes—unprotected, first-order, and higher-order masking—in ML-KEM’s FrodoKEM (FO) implementation on both microcontrollers and FPGAs. The study demonstrates that the high-bandwidth parallel processing inherent to FPGA architectures introduces significant first-order leakage during the verification step, rendering even higher-order masking insufficient to prevent full key recovery via power and electromagnetic side-channel attacks. These findings reveal that current hardware countermeasures for post-quantum cryptography face substantial challenges when deployed on highly parallel platforms, highlighting a critical gap in the practical security of lattice-based key encapsulation mechanisms in real-world high-performance environments.
Existing constant-time verification approaches either fail to accurately capture real-world execution behavior or are highly susceptible to environmental noise. This work proposes a lightweight, reliable, and hardware-agnostic dynamic analysis method that assesses constant-time compliance by comparing the consistency of instruction-mix distributions derived from low-level instruction traces of binary programs executed under varying secret inputs. By leveraging logical execution analysis, the approach effectively mitigates noise interference and precisely captures actual program behavior. Evaluated on multiple benchmarks comprising both known correct and non-constant-time implementations, the method achieves a 100% detection rate, demonstrating its effectiveness and robustness.
This work addresses the vulnerability of deep learning hardware deployed in safety-critical domains such as healthcare and finance to side-channel attacks, which can lead to the leakage of model architectures, parameters, and sensitive user data. The study systematically surveys existing vulnerabilities and presents the first comprehensive taxonomy of side-channel attack surfaces and defense strategies tailored to deep learning accelerators. By integrating hardware microarchitectural characteristics with physical leakage modeling, it establishes a holistic threat analysis framework that encompasses attack objectives, leakage sources, and mitigation mechanisms. Beyond clarifying the research landscape of current techniques, this paper identifies key challenges and outlines promising directions for future work, thereby offering both theoretical foundations and practical guidance for designing secure deep learning systems.