Shaofei Sun

dblp:237/8228 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 An Efficient Ensemble Framework to Assist Profiled Side-Channel Analysis by Machine Learning
abstract
The application of machine learning techniques in side-channel analysis has recently received increased attention. Finding the best hyperparameters to achieve optimal performance for machine learning models in side-channel analysis is still a challenging endeavor. In order to solve the problem, we present an efficient ensemble framework designed to support profiled side-channel analysis for attacking cryptographic devices with countermeasures. Our proposed framework can partially mitigate the impact of traditional countermeasures employed in cryptographic devices. Additionally, we introduce a novel voting method called elite voting, which leverages candidate keys with higher probabilities to recover the secret key and adjusts the voting weights for better candidate keys. Experimental results illustrate that our proposed framework can effectively recover the right key from cryptographic devices with countermeasures through multiple experiments. It enhances the signal-to-noise ratio of traces and successfully recovers the right key across various datasets. Furthermore, when compared to traditional methods, our elite voting method further enhances the performance of ensemble learning by reducing the number of traces needed to recover the secret key. It exhibits superior performance compared to other ensemble methods, as it can reduce the minimum required number of traces significantly.
Yaoling Ding, An Wang 0001, Shaofei Sun, Congming Wei, Liehuang Zhu
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2026 A UMAP-Based Clustering Side-Channel Analysis on Public-Key Cryptosystems
abstract
Horizontal analysis is a widely adopted method in side-channel analysis, particularly for public-key cryptosystems, where attackers aim to recover the key from a single trace. Current methods rely on trace segmentation, dimensionality reduction, and classification, but high noise and poor feature preservation hinder accuracy. Noise blurs cryptographic operation segment boundaries, and existing dimensionality reduction techniques fail to maintain the inherent distribution of trace points in a high-dimensional space. As a result, secret information recovery based on clustering remains inaccurate. This paper proposes an automated horizontal analysis framework named UMAP-HC to improve secret information recovery accuracy. The framework employs a sliding segmentation method to locate cryptographic operations in noisy traces with blurred segment boundaries. It leverages uniform manifold approximation and projection (UMAP) for feature preservation and hierarchical clustering for secret information recovery. Experimental results on four open access public-key algorithm power trace datasets, an SM2 power trace collected from a smart card, and an ECC power trace with dummy operation countermeasures demonstrate that UMAP-HC effectively classifies cryptographic operations, accurately locates operation segments, and recovers secret key. It achieves up to 100% recovery accuracy, surpassing previous methods by 40%-70%, with normalized mutual information reaching 1, an improvement of 0.02-0.99 over existing approaches.
Yuhan Qian, Yaoling Ding, Shaofei Sun, Congming Wei, An Wang 0001, Liehuang Zhu
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2025 An Effective Tool for Traces Preprocessing in Side-Channel Analysis: Ridge Energies Extraction From Synchrosqueezing Wavelet Transform
abstract
In recent years, deep learning methods have become prevalent in the field of side-channel analysis (SCA), leading to a decline in research on nonprofiled attacks and their preprocessing techniques. However, while deep-learning-based SCA methods can reduce the requirements for the quality of leakage signals, they do not fully resolve the need for preprocessing in SCA. Additionally, there is a lack of universal, nontrained preprocessing methods for side-channel leakage under various types of interference. In this article, a new method for preprocessing side channel leakage using synchrosqueezing wavelet transform and ridge energy extraction is proposed to deal with complex scenarios. This method involves two steps: first, applying synchrosqueezing theory to concentrate signal energy in the wavelet domain, and second, utilizing a dynamic path optimization algorithm to locate and extract ridge energy for subsequent attacks. Our proposed solution extracts key information features from the traces, effectively addressing trace distortion caused by varying levels of noise and random disturbances. We validate the effectiveness of our analysis and solution through extensive experiments on four public databases and two self-collected datasets containing power and electromagnetic leakage (EM) from both hardware and software encryption implementations. We compare our experimental results from four indicators: 1) success rate; 2) guessing entropy; 3) signal to noise ratio; and 4) normalized interclass varianc. Besides, we demonstrate the advantages of our method by comparing Measurements to Disclosure and on public datasets. Our method demonstrates significant potential for preprocessing traces in nonprofiled SCA.
Yuanzhen Wang, Shaofei Sun, Xiaofeng Wei, Md Sabbir Hosen
IEEE Internet Things J.3
2025 An Intelligent Framework for Cluster-Based Side-Channel Analysis on Public-Key Cryptosystems
abstract
Classical cluster-based side-channel analysis (SCA) uses clustering algorithms to analyze power traces and often, principal component analysis to reduce the dimension of data, resulting in that clustering may not deal well with high-dimensional traces, such as cryptographic algorithm implementations with countermeasures. In this article, we propose an intelligent framework for cluster-based SCA, which includes three steps of clustering, classification and correction, for processing large high-dimensional data. By combining unsupervised clustering and supervised deep learning techniques, the framework succeeds in mining the data for additional in-depth information. In addition, unlike traditional cluster-based SCA, our approach focuses on deep learning and deliberately avoids over-reliance on cluster labels during classification. And metrics for correction are adopted to achieve a high level of reliability in key recovery. Experiments on the RSA smart card based on Montgomery ladder implementation and FPGA-based ECC with random delay demonstrate that our framework can significantly improve the success rate with strong robustness.
Congming Wei, Shulin He, An Wang 0001, Shaofei Sun, Yaoling Ding, Liehuang Zhu
IEEE Internet Things J.4
2025 Make It Easy! Timing Leakage Analysis on Cryptographic Chips Based on Horizontal Leakage
abstract
Timing analysis presents a significant threat to cryptographic modules. However, traditional timing leakage analysis has notable limitations, especially when precise execution times cannot be obtained. In this article, we propose a novel timing leakage analysis method that leverages horizontal leakage in the power/electromagnetic channel by detecting the trace length of encryption processes under varying inputs. To demonstrate the effectiveness of our approach, we conducted systematic experimental evaluations across a range of cryptographic devices. In comparison to timing leakage analysis based on plaintext-ciphertext correlation, our method offers higher accuracy at lower testing costs and exhibits improved resistance to vertical noise.
Guangze Hong, An Wang 0001, Congming Wei, Yaoling Ding, Shaofei Sun, Liehuang Zhu
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2025 CL-SCA: A Contrastive Learning Approach for Profiled Side-Channel Analysis
abstract
Side-channel analysis (SCA) based on machine learning, particularly neural networks, has gained considerable attention in recent years. However, previous works predominantly focus on establishing connections between labels and related profiled traces. These approaches primarily capture label-related features and often overlook the connections between traces of the same label, resulting in the loss of some valuable information. Besides, the attack traces also contain valuable information that can be used in the training process to assist model learning. In this paper, we propose a profiled SCA approach based on contrastive learning named CL-SCA to address these issues. This approach extracts features by emphasizing the similarities among traces, thereby improving the effectiveness of key recovery while maintaining the advantages of the original SCA approach. Through experiments of different datasets from different platforms, we demonstrate that CL-SCA significantly outperforms other approaches. Moreover, by incorporating attack traces into the training process using our approach, we can further enhance its performance. This extension can improve the effectiveness of key recovery, which is fully verified through experiments on different datasets.
Annyu Liu, An Wang 0001, Shaofei Sun, Congming Wei, Yaoling Ding, Yongjuan Wang, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2024 An efficient heuristic power analysis framework based on hill-climbing algorithm
Shaofei Sun, Shijun Ding, An Wang 0001, Yaoling Ding, Congming Wei, Liehuang Zhu, Yongjuan Wang
Inf. Sci.1
2024 Time Is Not Enough: Timing Leakage Analysis on Cryptographic Chips via Plaintext-Ciphertext Correlation in Non-Timing Channel
abstract
In side-channel testing, the standard timing analysis works when the vendor can provide a measurement to indicate the execution time of cryptographic algorithms. In this paper, we find that there exists timing leakage in power/electromagnetic channels, which is often ignored in traditional timing analysis. Hence a new method of timing analysis is proposed to deal with the case where execution time is not available. Different execution time leads to different execution intervals, affecting the locations of plaintext and ciphertext transmission. Our method detects timing leakage by studying changes in plaintext-ciphertext correlation when traces are aligned forward and backward. Experiments are then carried out on different cryptographic devices. Furthermore, we propose an improved timing analysis framework which gives appropriate methods for different scenarios.
Congming Wei, Guangze Hong, An Wang 0001, Jing Wang 0150, Shaofei Sun, Yaoling Ding, Liehuang Zhu, Wenrui Ma
IEEE Trans. Inf. Forensics Secur.5