VLDB 2026 Research / reviewers in the wild / expert
Annelie Heuser
dblp:68/10491
· DBLP profile ↗
30ranked-venue papers
5as first author
7since 2021 · last 2022
0000-0002-1095-5420ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 2 first-author · 7 since 2021Systems, architecture and hardware · 8 · 3 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-authorArtificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | ULTRA: Ultimate Rootkit Detection over the AirabstractRootkits are the most challenging malware threats against server and desktop systems. They are created by highly skilled actors and are deployed in advanced persistent threat attacks. Lately and even in the future, rootkits will become a real threat to billions of IoT devices. Existing malware detection techniques based on static or dynamic analysis face major shortcomings, which become more apparent when it is necessary to detect threats on IoT devices. Duy-Phuc Pham, Damien Marion 0001, Annelie Heuser |
RAID | 3 |
| 2021 | Accurate and Robust Malware Analysis through Similarity of External Calls Dependency Graphs (ECDG)abstractMalware is a primary concern in cybersecurity, being one of the attacker’s favorite cyberweapons. Over time, malware evolves not only in complexity but also in diversity and quantity. Malware analysis automation is thus crucial. In this paper we present ECDGs, a shorter call graph representation, and a new similarity function that is accurate and robust. Toward this goal, we revisit some principles of malware analysis research to define basic primitives and an evaluation paradigm addressed for the setup of more reliable experiments. Our benchmark shows that our similarity function is very efficient in practice, achieving speedup rates of 3.30x and 354,11x wrt. radiff2 for the standard and the cache-enhanced implementations, respectively. Our evaluations generate clusters that produce almost unerring results - homogeneity score of 0.983 for the accuracy phase - and marginal information loss for a highly polluted dataset - NMI score of 0.974 between initial and final clusters of the robustness phase. Overall, ECDGs and our similarity function enable autonomous frameworks for malware search and clustering that can assist human-based analysis or improve classification models for malware analysis. Cassius Puodzius, Olivier Zendra, Annelie Heuser, Lamine Noureddine |
ARES | 3 |
| 2021 | Obfuscation Revealed: Leveraging Electromagnetic Signals for Obfuscated Malware ClassificationabstractThe Internet of Things (IoT) is constituted of devices that are exponentially growing in number and in complexity. They use numerous customized firmware and hardware, without taking into consideration security issues, which make them a target for cybercriminals, especially malware authors. Duy-Phuc Pham, Damien Marion 0001, Matthieu Mastio, Annelie Heuser |
ACSAC | 4 |
| 2021 | Trace-to-Trace Translation for SCA
Christophe Genevey-Metat, Annelie Heuser, Benoît Gérard |
CARDIS | 2 |
| 2021 | Profiled Side-Channel Analysis in the Efficient Attacker Framework
Stjepan Picek, Annelie Heuser, Guilherme Perin, Sylvain Guilley |
CARDIS | 2 |
| 2021 | SE-PAC: A Self-Evolving PAcker Classifier against rapid packers evolutionabstractPackers are widespread tools used by malware authors to hinder static malware detection and analysis. Identifying the packer used to pack a malware is essential to properly unpack and analyze the malware, be it manually or automatically. While many well-known packers are used, there is a growing trend for new custom packers that make malware analysis and detection harder. Research works have been very effective in identifying known packers or their variants, with signature-based, supervised machine learning or similarity-based techniques. However, identifying new packer classes remains an open problem. Lamine Noureddine, Annelie Heuser, Cassius Puodzius, Olivier Zendra |
CODASPY | 2 |
| 2021 | Poster: Obfuscation Revealed - Using Electromagnetic Emanation to Identify and Classify MalwareabstractIn this poster we present a novel approach of using side channel information to identify the kinds of malware threats that are targeting IoT devices. Although in the presence of obfuscation techniques that can prevent static or symbolic binary analysis, a malware researcher may obtain detailed information about malware type and identification using our method by leveraging side channel by electromagnetism rather than software-layer malware analysis. By capturing 100,000 measurement traces from an IoT system infected with different malware samples, we can obtain this information without altering the actual hardware. As a result, it can be implemented without any overhead, regardless of the resources available. Furthermore, our method has the advantage of non-trivial for malware authors to avoid. We were able to distinguish malware families based on side-channel knowledge without being able to see what exact hardware was involved. We were able to predict three generic malware forms (and one benign class) with a 99.89% percent accuracy in our tests. Furthermore, our results show that we are able to classify altered malware samples with unseen obfuscation techniques during the training phase, and to determine what kind of obfuscations, which makes our approach particularly useful for malware analysts. Duy-Phuc Pham, Damien Marion 0001, Annelie Heuser |
EuroS&P | 3 |
| 2020 | Towards Secure Composition of Integrated Circuits and Electronic Systems: On the Role of EDAabstractModern electronic systems become evermore complex, yet remain modular, with integrated circuits (ICs) acting as versatile hardware components at their heart. Electronic design automation (EDA) for ICs has focused traditionally on power, performance, and area. However, given the rise of hardware-centric security threats, we believe that EDA must also adopt related notions like secure by design and secure composition of hardware. Despite various promising studies, we argue that some aspects still require more efforts, for example: effective means for compilation of assumptions and constraints for security schemes, all the way from the system level down to the "bare metal"; modeling, evaluation, and consideration of security-relevant metrics; or automated and holistic synthesis of various countermeasures, without inducing negative cross-effects.In this paper, we first introduce hardware security for the EDA community. Next we review prior (academic) art for EDA-driven security evaluation and implementation of countermeasures. We then discuss strategies and challenges for advancing research and development toward secure composition of circuits and systems. Johann Knechtel, Elif Bilge Kavun, Francesco Regazzoni 0001, Annelie Heuser, Anupam Chattopadhyay, Debdeep Mukhopadhyay, Soumyajit Dey, Yunsi Fei, Yaacov Belenky, Itamar Levi, Tim Güneysu, Patrick Schaumont, Ilia Polian |
DATE | 4 |
| 2020 | Mind the Portability: A Warriors Guide through Realistic Profiled Side-channel Analysis
Shivam Bhasin, Anupam Chattopadhyay, Annelie Heuser, Dirmanto Jap, Stjepan Picek, Ritu Ranjan Shrivastwa |
NDSS | 3 |
| 2020 | Lightweight Ciphers and Their Side-Channel ResilienceabstractSide-channel attacks represent a powerful category of attacks against cryptographic devices. Still, side-channel analysis for lightweight ciphers is much less investigated than for instance for AES. Although intuition may lead to the conclusion that lightweight ciphers are weaker in terms of side-channel resistance, that remains to be confirmed and quantified. In this paper, we consider various side-channel analysis metrics which should provide an insight on the resistance of lightweight ciphers against side-channel attacks. In particular, for the non-profiled scenario we use the theoretical confusion coefficient and empirical optimal distinguisher. Our study considers side-channel attacks on the first, the last, or both rounds simultaneously. Furthermore, we conduct a profiled side-channel analysis using various machine learning attacks to recover 4-bit and 8-bit intermediate states of the cipher. Our results show that the difference between AES and lightweight ciphers is smaller than one would expect, and even find scenarios in which lightweight ciphers may be more resistant. Interestingly, we observe that the studied 4-bit S-boxes have a different side-channel resilience, while the difference in the 8-bit ones is only theoretically present. Annelie Heuser, Stjepan Picek, Sylvain Guilley, Nele Mentens |
IEEE Trans. Computers | 1 |
| 2019 | An automated and scalable formal process for detecting fault injection vulnerabilities in binariesabstractSummary Fault injection has increasingly been used both to attack software applications and to test system robustness. Detecting fault injection vulnerabilities has been approached with a variety of different but limited methods. This paper proposes an extension of a recently published general model checking based process to detect fault injection vulnerabilities in binaries. This new extension makes the general process scalable to real‐world implementations, which is demonstrated by detecting vulnerabilities in different cryptographic implementations. Thomas Given-Wilson, Annelie Heuser, Nisrine Jafri, Axel Legay |
Concurr. Comput. Pract. Exp. | 2 |
| 2019 | CC Meets FIPS: A Hybrid Test Methodology for First Order Side Channel AnalysisabstractCommon Criteria (CC) and FIPS 140-3 are two popular side channel testing methodologies. Test Vector Leakage Assessment Methodology (TVLA), a potential candidate for FIPS, can detect the presence of side-channel information in leakage measurements. However, TVLA results cannot be used to quantify side-channel vulnerability and it is an open problem to derive its relationship with side channel attack success rate (SR), i.e., a common metric for CC. In this paper, we extend the TVLA testing beyond its current scope. Precisely, we derive a concrete relationship between TVLA and signal to noise ratio (SNR). The linking of the two metrics allows direct computation of success rate (SR) from TVLA for given choice of intermediate variable and leakage model and thus unify these popular side channel detection and evaluation metrics. An end-to-end methodology is proposed, which can be easily automated, to derive attack SR starting from TVLA testing. The methodology works under both univariate and multivariate setting and is capable of quantifying any first order leakage. Detailed experiments have been provided using both simulated traces and real traces on SAKURA-GW platform. Additionally, the proposed methodology is benchmarked against previously published attacks on DPA contest v4.0 traces, followed by extension to jitter based countermeasure. The result shows that the proposed methodology provides a quick estimate of SR without performing actual attacks, thus bridging the gap between CC and FIPS. Debapriya Basu Roy, Shivam Bhasin, Sylvain Guilley, Annelie Heuser, Sikhar Patranabis, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 4 |
| 2019 | A Systematic Evaluation of Profiling Through Focused Feature SelectionabstractProfiled side-channel attacks consist of several steps one needs to take. An important, but sometimes ignored, step is a selection of the points of interest (features) within side-channel measurement traces. A large majority of the related works start the analyses with an assumption that the features are preselected. Contrary to this assumption, here, we concentrate on the feature selection step. We investigate how advanced feature selection techniques stemming from the machine learning domain can be used to improve the attack efficiency. To this end, we provide a systematic evaluation of the methods of interest. The experiments are performed on several real-world data sets containing software and hardware implementations of AES, including the random delay countermeasure. Our results show that wrapper and hybrid feature selection methods perform extremely well over a wide range of test scenarios and a number of features selected. We emphasize L1 regularization (wrapper approach) and linear support vector machine (SVM) with recursive feature elimination used after chi-square filter (Hybrid approach) that performs well in both accuracy and guessing entropy. Finally, we show that the use of appropriate feature selection techniques is more important for an attack on the high-noise data sets, including those with countermeasures, than on the low-noise ones. Stjepan Picek, Annelie Heuser, Alan Jovic, Lejla Batina |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2018 | Improving Side-Channel Analysis Through Semi-supervised Learning
Stjepan Picek, Annelie Heuser, Alan Jovic, Karlo Knezevic, Tania Richmond |
CARDIS | 2 |
| 2018 | Scalable Approximation of Quantitative Information Flow in Programs
Fabrizio Biondi, Michael A. Enescu, Annelie Heuser, Axel Legay, Kuldeep S. Meel, Jean Quilbeuf |
VMCAI | 3 |
| 2017 | Trade-Offs for S-Boxes: Cryptographic Properties and Side-Channel Resilience
Claude Carlet, Annelie Heuser, Stjepan Picek |
ACNS | 2 |
| 2017 | Side-channel analysis and machine learning: A practical perspectiveabstractThe field of side-channel analysis has made significant progress over time. Side-channel analysis is now used in practice in design companies as well as in test laboratories, and the security of products against side-channel attacks has significantly improved. However, there are still some remaining issues to be solved for side-channel analysis to become more effective. Side-channel analysis consists of two steps, commonly referred to as identification and exploitation. The identification consists of understanding the leakage and building suitable models. The exploitation consists of using the identified leakage models to extract the secret key. In scenarios where the model is poorly known, it can be approximated in a profiling phase. There, machine learning techniques are gaining value. In this paper, we conduct extensive analysis of several machine learning techniques, showing the importance of proper parameter tuning and training. In contrast to what is perceived as common knowledge in unrestricted scenarios, we show that some machine learning techniques can significantly outperform template attacks when properly used. We therefore stress that the traditional worst case security assessment of cryptographic implementations, that mainly includes template attacks, might not be accurate enough. Besides that, we present a new measure called the Data Confusion Factor that can be used to assess how well machine learning techniques will perform on a certain dataset. Stjepan Picek, Annelie Heuser, Alan Jovic, Simone A. Ludwig, Sylvain Guilley, Domagoj Jakobovic, Nele Mentens |
IJCNN | 2 |
| 2017 | PFD - A Flexible Higher-Order Masking SchemeabstractBased on the idea of secret sharing, masking is one of the most popular countermeasure to prevent side channel attacks (SCAs). Despite the redundant time and resource consumption, the existing masking schemes have constant speed and resources, and thus unsuitable for different applications with variable demand for time or space. Motivated by the reconfiguration technology of programmable hardware and disjunctive normal form expression of any logic function, we define a random variable logic circuit to reach the same security for any-order masking schemes. During the encryption, we induce random sequences and utilize them as configuration sequences to generate variable logic circuits, whose results are independent from the original and divided into several shares. We call our new approach polynomial function division (PFD) masking. Furthermore, we analyze the effectiveness and proof the security of PFD in theory. Our experiments using PFD on the advanced encryption standard (AES) algorithm show that the space complexity is almost as small as an implementation of the original AES without any countermeasure. Moreover, due to the flexible structure of PFD, the cost-to-efficiency ratio of PFD is much lower than state-of-the art in software, and its flexibility is coin with the reconfigurable chip. Ming Tang 0002, Zhipeng Guo 0002, Annelie Heuser, Yanzhen Ren, Jean-Luc Danger |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2017 | Stochastic Collision AttackabstractOn the one hand, collision attacks have been introduced in the context of side-channel analysis for attackers who exploit repeated code with the same data without having any knowledge of the leakage model. On the other hand, stochastic attacks have been introduced to recover leakage models of internally processed intermediate secret variables. Both techniques have shown advantages and intrinsic limitations. Most collision attacks, for instance, fail in exploiting all the leakages (e.g., only a subset of matching samples are analyzed), whereas stochastic attacks cannot involve linear regression with the full basis (while the latter basis is the most informative one). In this paper, we present an innovative attacking approach, which combines the flavors of stochastic and collision attacks. Importantly, our attack is derived from the optimal distinguisher, which maximizes the success rate when the model is known. Notably, we develop an original closed-form expression, which shows many benefits by using the full algebraic description of the leakage model. Using simulated data, we show in the unprotected case that, for low noise, the stochastic collision attack is superior to the state of the art, whereas asymptotically and thus, for higher noise, it becomes equivalent to the correlation-enhanced collision attack. Our so-called stochastic collision attack is extended to the scenario where the implementation is protected by masking. In this case, our new stochastic collision attack is more efficient in all scenarios and, remarkably, tends to the optimal distinguisher. We confirm the practicability of the stochastic collision attack thanks to experiments against a public data set (DPA contest v4). Furthermore, we derive the stochastic collision attack in case of zero-offset leakage that occurs in protected hardware implementations and use simulated data for comparison. Eventually, we underline the capability of the new distinguisher to improve its efficiency when the attack multiplicity increases. Nicolas Bruneau, Claude Carlet, Sylvain Guilley, Annelie Heuser, Emmanuel Prouff, Olivier Rioul |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Taylor Expansion of Maximum Likelihood Attacks for Masked and Shuffled Implementations
Nicolas Bruneau, Sylvain Guilley, Annelie Heuser, Olivier Rioul, François-Xavier Standaert, Yannick Teglia |
ASIACRYPT (1) | 3 |
| 2016 | Inter-class vs. mutual information as side-channel distinguishersabstractA novel “interclass information” side-channel distinguisher is compared to mutual information analysis. Interclass information possesses properties similar to mutual information but uses a different comparing strategy between the underlying conditional distributions. It is shown that interclass information can outperform mutual information in side-channel analysis, especially under low noise. The theoretical comparison is confirmed by simulations. Olivier Rioul, Annelie Heuser, Sylvain Guilley, Jean-Luc Danger |
ISIT | 2 |
| 2015 | Less is More - Dimensionality Reduction from a Theoretical PerspectiveabstractInternational audience Nicolas Bruneau, Sylvain Guilley, Annelie Heuser, Damien Marion 0001, Olivier Rioul |
CHES | 3 |
| 2014 | Detecting Hidden Leakages
Amir Moradi 0001, Sylvain Guilley, Annelie Heuser |
ACNS | 3 |
| 2014 | Masks Will Fall Off - Higher-Order Optimal Distinguishers
Nicolas Bruneau, Sylvain Guilley, Annelie Heuser, Olivier Rioul |
ASIACRYPT (2) | 3 |
| 2014 | Good Is Not Good Enough - Deriving Optimal Distinguishers from Communication Theory
Annelie Heuser, Olivier Rioul, Sylvain Guilley |
CHES | 1 |
| 2014 | Attacking Suggest Boxes in Web Applications Over HTTPS Using Side-Channel Stochastic Algorithms
Alexander Schaub 0001, Emmanuel Schneider, Alexandros Hollender, Vinicius Calasans, Laurent Jolie, Robin Touillon, Annelie Heuser, Sylvain Guilley, Olivier Rioul |
CRiSIS | 7 |
| 2013 | Time-Frequency Analysis for Second-Order Attacks
Pierre Belgarric, Shivam Bhasin, Nicolas Bruneau, Jean-Luc Danger, Nicolas Debande, Sylvain Guilley, Annelie Heuser, Zakaria Najm, Olivier Rioul |
CARDIS | 7 |
| 2012 | A New Difference Method for Side-Channel Analysis with High-Dimensional Leakage Models
Annelie Heuser, Michael Kasper, Werner Schindler, Marc Stöttinger |
CT-RSA | 1 |
| 2012 | Revealing side-channel issues of complex circuits by enhanced leakage modelsabstractIn the light of implementation attacks a better understanding of complex circuits of security sensitive applications is an important issue. Appropriate evaluation tools and metrics are required to understand the origin of implementation flaws within the design process. The selected leakage model has significant influence on the reliability of evaluation results concerning the side-channel resistance of a cryptographic implementation. In this contribution we introduce methods, which determine the accuracy of the leakage characterization and allow to quantify the signal-to-noise ratio. This allows a quantitative assessment of the side-channel resistance of an implementation without launching an attack. We validate the conclusions drawn from our new methods by real attacks and obtain similar results. Compared to the commonly used Hamming Distance model in our experiments enhanced leakage models increased the attack efficiency by up to 500%. Annelie Heuser, Werner Schindler, Marc Stöttinger |
DATE | 1 |
| 2011 | How a Symmetry Metric Assists Side-Channel Evaluation - A Novel Model Verification Method for Power AnalysisabstractSide-channel analysis has become an important field of research for the semiconductor industry and for the academic sector as well. Of particular interest is constructive side-channel analysis as it supports a target-oriented associated design process. The main goal is to increase the side-channel resistance of cryptographic implementations within the design phase by a combination of advanced stochastic methods with design methods, tools, and countermeasures. In this contribution we present a new enhanced tool that utilizes symmetry properties to assist the side-channel evaluation of cryptographic implementations. This technique applies a symmetry metric, which is introduced as an engineering tool to verify the suitability of the leakage model in the evaluation phase of security-sensitive designs. Additionally, this approach also supports the designer in the selection of appropriate time instants. Annelie Heuser, Michael Kasper, Werner Schindler, Marc Stöttinger |
DSD | 1 |