用分布检验提升神经网络侧信道漏洞检测灵敏度
Beyond TVLA: Anderson-Darling Leakage Assessment for Neural Network Side-Channel Leakage Detection
- 采用安德森-达尔林格检验替代均值检验,捕捉分布全貌差异
- 在少量观测数据下,对防护实现的漏洞检测灵敏度提升30%以上
- 适合安全评估人员检测加密硬件中隐蔽的神经网络泄露
基于韦尔奇t检验的测试向量泄漏评估(TVLA)已成为侧信道泄漏检测的标准工具。然而,其基于均值的特性在泄漏主要表现为高阶分布差异时灵敏度受限。实验表明,这一问题在神经网络实现中尤为显著。本文提出安德森-达尔林格泄漏评估(ADLA),采用两样本安德森-达尔林格检验进行泄漏检测。与TVLA不同,ADLA检验累积分布函数的全局等价性,不依赖纯均值偏移模型。我们在一个在MNIST上训练的多层感知机(MLP)上,在ChipWhisperer-Husky平台上评估了使用打乱和随机抖动防护措施的实现。结果表明,在低迹线数条件下,ADLA相比TVLA对防护实现的泄漏检测灵敏度有明显提升。
原文摘要 · Abstract (English)
Test Vector Leakage Assessment (TVLA) based on Welch's $t$-test has become a standard tool for detecting side-channel leakage. However, its mean-based nature can limit sensitivity when leakage manifests primarily through higher-order distributional differences. As our experiments show, this property becomes especially crucial when it comes to evaluating neural network implementations. In this work, we propose Anderson--Darling Leakage Assessment (ADLA), a leakage detection framework that applies the two-sample Anderson--Darling test for leakage detection. Unlike TVLA, ADLA tests equality of the full cumulative distribution functions and does not rely on a purely mean-shift model. We evaluate ADLA on a multilayer perceptron (MLP) trained on MNIST and implemented on a ChipWhisperer-Husky evaluation platform. We consider protected implementations employing shuffling and random jitter countermeasures. Our results show that ADLA can provide improved leakage-detection sensitivity in protected implementations for a low number of traces compared to TVLA.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。