Portability of Deep-Learning Side-Channel Attacks against Software Discrepancies

Portability of Deep-Learning Side-Channel Attacks against Software Discrepancies
复制标题

DOI:
10.1145/3558482.3590177
复制
发表时间:
2023-05
期刊:
Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子:
--
通讯作者:
Chenggang Wang;Mabon Ninan;S. Reilly;Joel Ward;William Hawkins;Boyang Wang;J. Emmert
Chenggang Wang;Mabon Ninan;S. Reilly;Joel Ward;William Hawkins;Boyang Wang;J. Emmert
中科院分区:
其他
文献类型:
--
作者:
Chenggang Wang;Mabon Ninan;S. Reilly;Joel Ward;William Hawkins;Boyang Wang;J. Emmert

文献摘要

相似文献

深度学习旁道攻击可以通过神经网络分析功耗来泄露设备上的加密密钥。然而,当训练数据(来自训练设备)和测试数据(来自测试设备)不一致时,深度学习侧信道攻击的可移植性可能会受到影响。最近的研究检查了针对两个设备之间的硬件差异的深度学习侧通道攻击的可移植性。在本文中,我们研究了针对训练设备和测试设备之间的软件差异的深度学习侧通道攻击的可移植性。具体来说,我们检查了可能导致软件差异的四个因素,包括随机延迟、指令重写、优化级别和代码混淆。我们的实验结果表明,每个因素引起的软件差异都会显着降低深度学习侧信道攻击的攻击性能,甚至阻止攻击者恢复密钥。为了减轻软件差异的影响,我们从攻击者的角度研究了三种缓解方法,包括调整兴趣点、域适应和多域训练。我们的结果表明,多领域培训是这三种方法中最有效的方法,但考虑到软件差异的多样性,它可能很难扩展。
Deep-learning side-channel attacks can reveal encryption keys on a device by analyzing power consumption with neural networks. However, the portability of deep-learning side-channel attacks can be affected when training data (from the training device) and test data (from the test device) are discrepant. Recent studies have examined the portability of deep-learning side-channel attacks against hardware discrepancies between two devices. In this paper, we investigate the portability of deep-learning side-channel attacks against software discrepancies between the training device and test device. Specifically, we examine four factors that can lead to software discrepancies, including random delays, instruction rewriting, optimization levels, and code obfuscation. Our experimental results show that software discrepancies caused by each factor can significantly downgrade the attack performance of deep-learning side-channel attacks, and even prevent an attacker from recovering keys. To mitigate the impacts of software discrepancies, we investigate three mitigation methods, including adjusting Points of Interest, domain adaptation, and multi-domain training, from the perspective of an attacker. Our results indicate that multi-domain training is the most effective approach among the three, but it can be difficult to scale given the diversity of software discrepancies.