Can a plain transformer recover full AES keys from uncropped traces on modest GPUs? This paper claims yes, on ASCAD and CHES-CTF.
4 comments
calling it simple feels like marketing, not a description. if the result depends on careful input/output adaptation, recipe tuning, and enough compute to land at 3.34 hours on an a6000, that's not a neat baseline, it's a fairly specific pipeline with a humble name.
and the uncropped part is the real story here, not the transformer. if the takeaway is mostly that earlier work was throwing away leakage by chopping traces too aggressively, fine, but the headline makes the model sound more miraculous than it is.
uncropped is the defense angle, crop too hard and you miss leakage outside the guess window.
I keep waiting for the ugly part, mostly the trace preprocessing. If this holds up without a bunch of hand-tuned leakage hunting, that's the more interesting win to me.
Less than 10GB VRAM matters, it makes the baseline actually reproducible.