Horizontal fusion, not profiling, lets them recover ML-DSA keys from a few traces, even with first-order masking.
trending21
01 02 Revisiting Simple Power Analysis of Polynomial Multiplication in the HQC Implementation eprint.iacr.orgRevisits HQC's decryption-time poly mul, finds the bitwise schoolbook still leaks under SPA, then patches it for free.03 Paper on cryogenic clock freezing for static side-channel attacks, with FPGA/SoC demos and a self-heating countermeasure. Cute thermostat.04 Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels arxiv.orgArXiv paper on an SSH compression side channel from shared state across multiplexed channels, because one bug wasn't enough.05 5GDescrambler: Locating, Descrambling, and Decoding 5G Scheduling Information (long version) arxiv.orgPassive 5G DCI descrambling via algebraic structure, skipping handshake leaks and brute force, now with commercial traces.06 Accelerating Post-Quantum Cryptography Security Evaluation with Analyzr™ — Secure-IC Technical Article | ChipEstimate.com chipestimate.comSecure-IC's article on Analyzr for ML-KEM/ML-DSA side-channel and physical attack testing, because PQC still needs paperwork.07 Which left-to-right scalar-mult ladders are actually constant-time? This paper checks three Comb variants and a recoder.08 Arxiv paper on a split-LLM gradient leak that spots real activations among decoys, because privacy audits love loopholes.09 Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity arxiv.orgCan you make side channels louder with EM injection? This paper says yes, using nonlinearity to eavesdrop on audio and sensors.10 Practice Makes (Im)Perfect: A Look Back at Benchmarking Practices for Microarchitectural Side-Channel Attacks arxiv.org83 papers, 19 recurring benchmark sins: this survey says microarchitectural side-channel claims are often hard to compare.11 Open EM side-channel traces for Kyber decapsulation on an STM32F407, 200k per implementation, plus share-level masked data.12 Paper on hardware-in-the-loop fault injection search, using RL and bandits to tune delay, voltage, and pulse width.13 Can a plain transformer recover full AES keys from uncropped traces on modest GPUs? This paper claims yes, on ASCAD and CHES-CTF.14 Exploiting Per-Core Leakage: Electromagnetic Side-Channel Monitoring of Multicore Architectures arxiv.orgEM side channels on multicore CPUs, with per-core leakage mapped on a SoC and a Pi 4. Because one core wasn't enough.15 Can GEA-1/2 survive random faults? This paper says no, with fault localization and key recovery in a ChipWhisperer sim.16 Efficient Soft Analytical Side-Channel Attacks on Large-Scale Cryptographic Computations eprint.iacr.orgRegion-wise pruning makes SASCA on ML-DSA NTTs practical, cutting the usual belief-propagation memory/runtime blowup.17 Can Falcon be done without an FPU? This walks through the fixed-point tricks, bounds, and tradeoffs to make it work.18 Paper on laser probing edge AI chips to recover LLM embeddings, weights, activations, and state, because memory was too mainstream.19 Network Security, Cryptography, and Quantum - Software Architecture Gathering 2026 software-architecture-gathering.comCovers crypto building blocks for network security, then wanders into side channels, blockchains, Shor, and post-quantum replacements.20 What's Your NIC Whispering? Network Threat Behavior Recognition via NIC Electromagnetic Side-Channel Leakage arxiv.orgYour NIC is apparently talking, and this paper classifies threat behavior from its electromagnetic leakage.21 Two-message CSIDH key exchange that blinds ephemerals under AEAD and ships C/Python code, benchmarks, and leakage audits.