The Number Theoretic Transform (NTT) is a critical component in the NIST-standardized Post-Quantum Cryptography (PQC) algorithm ML-KEM. Soft Analytical Side-Channel Attacks (SASCA) are a powerful class of attacks against NTT. SASCA first derives probability vectors for multiple correlated intermediates via profiling attacks, then leverages Belief Propagation (BP) to generate the marginal distribution of the target. While SASCA itself does not specify a profiling method, nearly all existing SASCA works targeting the NTT rely on Template Attacks (TA). In this paper, we present an alternative approach: a SASCA framework, Neur-SASCA, that integrates neural networks with BP. Compared to TA-based approaches, this framework features a higher level of automation, as it directly processes raw NTT traces without requiring manual trace alignment or localization of all leakage points. It also exhibits advantages in real-world complex scenarios characterized by high non- Gaussian noise, trace misalignment, or cross-device settings. The framework comprises an end-to-end network that directly processes raw NTT traces and yields predictions for all intermediate values (integrated with a transfer learning architecture designed for cross-device scenarios), a regularization algorithm that converts classification outputs into probability vectors, and a GPU-accelerated fast BP implementation. On a dataset collected from a real SAM4S microprocessor, when the same device is used for both profiling and analysis (laboratory setup), Neur-SASCA can recover the complete NTT input with a 100% success rate using only 900 profiling traces, whereas the TA-based method achieves a 56% success rate when using 2,900 profiling traces. When different devices are employed for profiling and attack (cross-device scenario), Neur-SASCA still enables successful analysis with a success rate of 97%, while the TA-based method is no longer effective.
Paper
Full text
Neur-SASCA: High-Noise-Tolerant and Automated Single-Trace Attack against NTT
Semantic Scholar · 2026
Abstract
The Number Theoretic Transform (NTT) is a critical component in the NIST-standardized Post-Quantum Cryptography (PQC) algorithm ML-KEM. Soft Analytical Side-Channel Attacks (SASCA) are a powerful class of attacks against NTT. SASCA first derives probability vectors for multiple correlated intermediates via profiling attacks, then leverages Belief Propagation (BP) to generate the marginal distribution of the target. While SASCA itself does not specify a profiling method, nearly all existing SASCA works targeting the NTT rely on Template Attacks (TA). In this paper, we present an alternative approach: a SASCA framework, Neur-SASCA, that integrates neural networks with BP. Compared to TA-based approaches, this framework features a higher level of automation, as it directly processes raw NTT traces without requiring manual trace alignment or localization of all leakage points. It also exhibits advantages in real-world complex scenarios characterized by high non- Gaussian noise, trace misalignment, or cross-device settings. The framework comprises an end-to-end network that directly processes raw NTT traces and yields predictions for all intermediate values (integrated with a transfer learning architecture designed for cross-device scenarios), a regularization algorithm that converts classification outputs into probability vectors, and a GPU-accelerated fast BP implementation. On a dataset collected from a real SAM4S microprocessor, when the same device is used for both profiling and analysis (laboratory setup), Neur-SASCA can recover the complete NTT input with a 100% success rate using only 900 profiling traces, whereas the TA-based method achieves a 56% success rate when using 2,900 profiling traces. When different devices are employed for profiling and attack (cross-device scenario), Neur-SASCA still enables successful analysis with a success rate of 97%, while the TA-based method is no longer effective.
References (38)
Scroll for more · 26 remaining