Beyond TVLA: Anderson-Darling Leakage Assessment for Neural Network Side-Channel Leakage Detection
Test Vector Leakage Assessment (TVLA) based on Welch's $t$-test has become a standard tool for detecting side-channel leakage. However, its mean-based nature can limit sensitivity when leakage manifests primarily through higher-order distributional differences. As our experiments show, this property becomes especially crucial when it comes to evaluating neural network implementations. In this work, we propose Anderson--Darling Leakage Assessment (ADLA), a leakage detection framework that applies the two-sample Anderson--Darling test for leakage detection. Unlike TVLA, ADLA tests equality of the full cumulative distribution functions and does not rely on a purely mean-shift model. We evaluate ADLA on a multilayer perceptron (MLP) trained on MNIST and implemented on a ChipWhisperer-Husky evaluation platform. We consider protected implementations employing shuffling and random jitter countermeasures. Our results show that ADLA can provide improved leakage-detection sensitivity in protected implementations for a low number of traces compared to TVLA.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
The efficiency of Anderson-Darling test with limited sample size: an application to Backtesting Counterparty Credit Risk internal model
This work presents a theoretical and empirical evaluation of Anderson-Darling test when the sample size is limited. The test can be applied in order to backtest the risk factors dynamics in the context of Counterparty Cr…
SafeML: Safety Monitoring of Machine Learning Classifiers through Statistical Difference Measure
Ensuring safety and explainability of machine learning (ML) is a topic of increasing relevance as data-driven applications venture into safety-critical application domains, traditionally committed to high safety standard…
BIG-bench Machine LearningDomain AdaptationGeneral ClassificationImage Classification+3Statistic-Based Security Analysis of Ring Oscillator PUFs
Ring oscillators (ROs) are a robust way to implement a physical unclonable function (PUF) into ASICs or FPGAs, but claims of predictability arose recently. We describe why this likely results from not using adjacent ROs …
Student't mixture models for stock indices. A comparative study
We perform a comparative study for multiple equity indices of different countries using different models to determine the best fit using the Kolmogorov-Smirnov statistic, the Anderson-Darling statistic, the Akaike inform…
Hardware-in-the-Loop Evaluation of Goodness of Fit (GoF) Testing for Dynamic Spectrum Sharing
In contrast to parametric spectrum sensing, non-parametric spectrum sensing can effectively detect the primary user's presence or absence without prior information about the primary user. Particularly, non-parametric spe…