ML-Enhanced AES Anomaly Detection for Real-Time Embedded Security

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chinnasami, Nishant, Stahle-Smith, Rye, Karakchi, Rasha
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916829016883200
author Chinnasami, Nishant
Stahle-Smith, Rye
Karakchi, Rasha
author_facet Chinnasami, Nishant
Stahle-Smith, Rye
Karakchi, Rasha
contents Advanced Encryption Standard (AES) is a widely adopted cryptographic algorithm, yet its practical implementations remain susceptible to side-channel and fault injection attacks. In this work, we propose a comprehensive framework that enhances AES-128 encryption security through controlled anomaly injection and real-time anomaly detection using both statistical and machine learning (ML) methods. We simulate timing and fault-based anomalies by injecting execution delays and ciphertext perturbations during encryption, generating labeled datasets for detection model training. Two complementary detection mechanisms are developed: a threshold-based timing anomaly detector and a supervised Random Forest classifier trained on combined timing and ciphertext features. We implement and evaluate the framework on both CPU and FPGA-based SoC hardware (PYNQ-Z1), measuring performance across varying block sizes, injection rates, and core counts. Our results show that ML-based detection significantly outperforms threshold-based methods in precision and recall while maintaining real-time performance on embedded hardware. Compared to existing AES anomaly detection methods, our solution offers a low-cost, real-time, and accurate detection approach deployable on lightweight FPGA platforms.
format Preprint
id arxiv_https___arxiv_org_abs_2507_04197
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ML-Enhanced AES Anomaly Detection for Real-Time Embedded Security
Chinnasami, Nishant
Stahle-Smith, Rye
Karakchi, Rasha
Cryptography and Security
Advanced Encryption Standard (AES) is a widely adopted cryptographic algorithm, yet its practical implementations remain susceptible to side-channel and fault injection attacks. In this work, we propose a comprehensive framework that enhances AES-128 encryption security through controlled anomaly injection and real-time anomaly detection using both statistical and machine learning (ML) methods. We simulate timing and fault-based anomalies by injecting execution delays and ciphertext perturbations during encryption, generating labeled datasets for detection model training. Two complementary detection mechanisms are developed: a threshold-based timing anomaly detector and a supervised Random Forest classifier trained on combined timing and ciphertext features. We implement and evaluate the framework on both CPU and FPGA-based SoC hardware (PYNQ-Z1), measuring performance across varying block sizes, injection rates, and core counts. Our results show that ML-based detection significantly outperforms threshold-based methods in precision and recall while maintaining real-time performance on embedded hardware. Compared to existing AES anomaly detection methods, our solution offers a low-cost, real-time, and accurate detection approach deployable on lightweight FPGA platforms.
title ML-Enhanced AES Anomaly Detection for Real-Time Embedded Security
topic Cryptography and Security
url https://arxiv.org/abs/2507.04197