Paper 2026/338

Is it Really Broken? The Failure of DL-SCA Scoring Metrics under Non-Uniform Priors

Nathan Rousselot, Thales (France), LIRMM, University of Montpellier, CNRS
Karine Heydemann, Thales (France)
Loïc Masure, LIRMM, University of Montpellier, CNRS
Vincent Migairou, Thales (France)
Rémi Strullu, ANSSI, France
Abstract

This paper investigates a recent, claimed state-of-the-art attack on the ASCADv2 dataset, a higher-order masked and shuffled AES implementation, which we demonstrate to be a false positive. Despite successful validation using classical metrics, including a converging Guessing Entropy (GE), we prove that the model learned no actual side-channel leakage. Instead, it exploited a statistical bias in the intermediate value distribution. We argue that the usual scoring function used in the GE is an unreliable metric in the presence of such biases. To address this critical evaluation flaw, we propose a set of methods to avoid falling in this pitfall. First, we introduce pre-emptive methods to detect significant biases in the target's value distribution before profiling, as well as post-mortem ones to examine the resulting model. Second, we present guidelines to avoid regimes where the GE is unreliable, and we derive the Asymptotically Optimal Distinguisher, a new, lightweight distinguisher that provably neutralizes the influence of learned priors in the GE metric, thereby isolating the information gained purely from the side-channel leakage. We demonstrate our methodology by successfully identifying the ASCADv2 false positive and applying it to synthetically biased versions of the ASCADv1 dataset.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
Side-Channel AnalysisDeep LearningEvaluation MethodologyGuessing EntropyFalse PositiveDataset Bias
Contact author(s)
nathan rousselot @ thalesgroup com
karine heydemann @ thalesgroup com
loic masure @ lirmm fr
vincent migairou @ thalesgroup com
History
2026-02-23: approved
2026-02-20: received
See all versions
Short URL
https://ia.cr/2026/338
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/338,
      author = {Nathan Rousselot and Karine Heydemann and Loïc Masure and Vincent Migairou and Rémi Strullu},
      title = {Is it Really Broken? The Failure of {DL}-{SCA} Scoring Metrics under Non-Uniform Priors},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/338},
      year = {2026},
      url = {https://eprint.iacr.org/2026/338}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.