Paper 2025/1643

SCA-GPT: A Generation-Planning-Tool Assisted LLM Agent for Fully Automated Side-Channel Analysis on Cryptosystems

Wenquan Zhou, Beijing Institute of Technology
An Wang, Beijing Institute of Technology
Yaoling Ding, Beijing Institute of Technology
Annyu Liu, Beijing Institute of Technology
Jingqi Zhang, Beijing Institute of Technology
Jiakun Li, Beijing Institute of Technology
Liehuang Zhu, Beijing Institute of Technology
Abstract

Non-invasive security constitutes an essential component of hardware security, primarily involving side-channel analysis (SCA), with various international standards explicitly mandating rigorous testing. However, current SCA assessments rely on manual expert procedures, causing critical issues: inconsistent results due to expert variability, error-prone multi-step testing, and high costs with IP leakage risks for manufacturers lacking in-house expertise. Automated SCA tools that deliver consistent, expert-level evaluations are urgently needed. In recent years, large language models (LLMs) have been widely adopted in various fields owing to their emergent capabilities. Particularly, LLM agents equipped with tool-usage capabilities have significantly expanded the potential of these models to interact with the physical world. Motivated by these recent advances in LLM agents, we propose SCA-GPT, an end-to-end automated LLM agent framework tailored for SCA tasks. The framework integrates a domain-specific knowledge base with multiple SCA tools to enable retrievalaugmented generation for fully automated ISO/IEC 17825- compliant testing. As a core component of SCA-GPT, the expert knowledge base serves as the agent’s long-term memory, enabling precise retrieval and contextual reasoning during automated testing. We further present a domain-specific expert knowledge base construction approach and two complementary evaluation metrics. Retrieval experiments validate the effectiveness of our knowledge base construction, achieving strong performance with 84.44% and 98.33% on two complementary retrieval quality metrics. We further evaluate the overall framework across three leading LLMs: DeepSeek V3.1, Kimi K2 and Qwen3 Coder. The evaluation uses datasets spanning six cryptographic algorithms (e.g., AES, DES, RSA, ECDSA) and deploying on four hardware platforms, including smart cards, microcontrollers, and FPGAs. Results show that DeepSeek V3.1, Kimi K2, and Qwen3 Coder achieve accuracies of 83.8%, 77.8%, and 91.4%, respectively. The framework reduces evaluation time by 95.7% on average compared with manual procedures while maintaining equivalent assessment quality and automatically generating evaluation reports. Notably, SCA-GPT is the first advanced LLM agent specifically designed for SCA tasks.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Side-channel analysislarge language modelretrieval-augmented generationexpert knowledge base
Contact author(s)
wenquan2222222 @ gmail com
History
2026-01-24: revised
2025-09-11: received
See all versions
Short URL
https://ia.cr/2025/1643
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1643,
      author = {Wenquan Zhou and An Wang and Yaoling Ding and Annyu Liu and Jingqi Zhang and Jiakun Li and Liehuang Zhu},
      title = {{SCA}-{GPT}: A Generation-Planning-Tool Assisted {LLM} Agent for Fully Automated Side-Channel Analysis on Cryptosystems},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1643},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1643}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.