Paper 2026/981

Profiling-Device-Free SASCA Framework for ML-KEM

Yuxuan Wang, Shanghai Jiao Tong University
Abstract

In side-channel analysis of ML-KEM (a NIST-standard PQC algorithm), SASCA is a powerful profiling attack. However, obtaining a profiling device strictly matching the target is challenging in practice. To address this, we propose the first profiling-device-free SASCA framework for ML-KEM. The framework first controls the NTT input by choosing ciphertexts and trains a leakage model. Subsequently, leveraging the similarity between NTT and INTT, it uses adversarial unsupervised domain adaptation to fine-tune the model for INTT and recover its secret input. Validated on real embedded devices, the framework achieves effective key recovery using a comparable number of traces to profiling SASCA.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
ML-KEMSide-Channel AttacksTransfer LearningSASCAAdversarial Networks
Contact author(s)
18588297218 @ sjtu edu cn
History
2026-05-19: approved
2026-05-18: received
See all versions
Short URL
https://ia.cr/2026/981
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/981,
      author = {Yuxuan Wang},
      title = {Profiling-Device-Free {SASCA} Framework for {ML}-{KEM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/981},
      year = {2026},
      url = {https://eprint.iacr.org/2026/981}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.