ML-Enhanced AES Anomaly Detection for Real-Time Embedded Security

Advanced Encryption Standard (AES) is a widely adopted cryptographic algorithm, yet its practical implementations remain susceptible to side-channel and fault injection attacks. In this work, we propose a comprehensive framework that enhances AES-128 encryption security through controlled anomaly injection and real-time anomaly detection using both statistical and machine learning (ML) methods. We simulate timing and fault-based anomalies by injecting execution delays and ciphertext perturbations during encryption, generating labeled datasets for detection model training. Two complementary detection mechanisms are developed: a threshold-based timing anomaly detector and a supervised Random Forest classifier trained on combined timing and ciphertext features. We implement and evaluate the framework on both CPU and FPGA-based SoC hardware (PYNQ-Z1), measuring performance across varying block sizes, injection rates, and core counts. Our results show that ML-based detection significantly outperforms threshold-based methods in precision and recall while maintaining real-time performance on embedded hardware. Compared to existing AES anomaly detection methods, our solution offers a low-cost, real-time, and accurate detection approach deployable on lightweight FPGA platforms.

Paper

References (20)

04“An fpga-based online learning system for anomaly detection in iot networks,”2022 · 2022 International Conference on ReConFigurable Computing and FPGAs (ReConFig)
05“Machine learning in cyber-physical systems: Security, privacy, and trust,”2021 · IEEE Transactions on Industrial Informatics
06“Fault attack and detection techniques for aes encryption: A review,”2021 · Microprocessors and Microsystems
07“Efficient and low-overhead side-channel attack mitigation using timing thresholding,”2021 · IEEE Transactions on Computers
08“Fault injection attacks on aes: A review,”2021 · Information Security Journal
09“Random forest for anomaly detection in cyber-security,”2020 · IEEE Access
10“Side-channel attack detection techniques: A survey,”2020 · ACM Computing Surveys
11“Timing anomaly analysis and detection in cryptographic systems,”2020 · IEEE Transactions on Computers
12“A comprehensive survey on fault attacks and countermeasures for cryptographic devices,”2019 · IEEE Access

Scroll for more · 8 remaining

Similar papers

© 2026 NYSGPT2525 LLC