Zehua Qiao

dblp:301/5900 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-9727-3360ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Rejection Matters: Efficient Non-Profiling Side-Channel Attack on ML-DSA via Exploiting Public Templates
abstract
ML-DSA (formerly CRYSTALS-Dilithium), NIST’s primary post-quantum signature standard, is increasingly deployed along with the post-quantum transitions. Yet when the implementations of ML-DSA are deployed in practice, their physical security remains underexplored. In this work, we reveal a new attack surface against ML-DSA by exploiting the leakages from both rejected signing trials and the final accepted signing trial. We present, to the best of our knowledge, the first side-channel attack that simultaneously leverages leakage from both trials without relying on clone devices. Unlike traditional Secret-based Template Attacks, which require profiling the leakage of the sensitive intermediates on a clone device, our PTA (Public-based Template Attack) builds leakage templates solely from publicly available data on the target device itself. With challenge c known, we then perform CPA on the sensitive intermediates using traces from both rejected and accepted signing trials, quadrupling (on average) exploitable leakage per signing request for ML-DSA-44. The experimental results on power traces from an ARM Cortex-M4 board show that challenges c are fully recovered with only 96 traces, and then the key recovery succeeds in around 300 traces — a fact of 10x fewer than prior art. We highlight that our attack can be applied across all three ML-DSA variants with different security levels. Moreover, our attack works straightforwardly in the hedged (non-deterministic) mode of ML-DSA, demonstrating that the hedging offers no SCA protection in this scenario.
Wei Cheng 0003, Zehua Qiao, Yuejun Liu, Yongbin Zhou
DATE3
2026 Deep Learning-based Public Template Attack against ML-DSA on ARM Microcontrollers
Zehua Qiao, Wei Cheng 0003, Yuejun Liu, Yongbin Zhou
ISCAS2
2025 Efficient CNN-Based Side-Channel Attacks on Dilithium without Device Access
abstract
The post-quantum cryptography standard, released in August 2024, faces significant threats from side-channel attacks (SCAs). While non-profiled attacks demand extensive traces and time, profiled attacks, though more effective, require access to identical devices. This paper proposes a hybrid SCA on Dilithium, leveraging the strengths of both approaches. Our method profiles a template using leakage from operations with known variables, then applies it to target sensitive variables. Specifically, Convolutional Neural Networks (CNNs) are employed to model leakages from Inverse Number Theoretic Transform (INTT) operations. This model is subsequently used to recover private keys by targeting INTT operations involving c. Implemented on an ARM Cortex-M4 platform, our attack requires only 10/27/18 power traces to recover keys for Dilithium2/3/5, respectively, significantly reducing the number of traces compared to prior non-profiled attacks requiring hundreds.
Zehua Qiao, Yuejun Liu, Yongbin Zhou, Dixiao Du
ISCAS1
2024 A Novel Power Analysis Attack against CRYSTALS-Dilithium Implementation
abstract
Post-Quantum Cryptography (PQC) was proposed due to the potential threats quantum computer attacks against conventional public key cryptosystems, and four PQC algorithms besides CRYSTALS-Dilithium (Dilithium for short) have so far been selected for National Institute of Standards and Technology (NIST) standardization. However, the selected algorithms are still vulnerable to side-channel attacks in practice, and their physical security need to be further evaluated. This paper proposes two efficient power analysis attacks against Dilithium implementation, the optimized fast two-stage approach and the single-bit approach, aiming at reducing the key guess space. Our findings reveal that the optimized approach outperforms the conservative approach and the fast two-stage approach proposed in ICCD 2021 by factors of 338 and 49, respectively. Similarly, compared to these two approaches, the single-bit approach achieves acceleration of 367 times and 53 times, respectively.
Yuejun Liu, Yongbin Zhou, Yiwen Gao 0001, Zehua Qiao, Huaxin Wang
ETS5
2024 Attacking High-order Masked Cryptosystem via Deep Learning-based Side-Channel Analysis
abstract
Masking is widely considered as an effective countermeasure against side-channel analysis (SCA) due to its provable security and efficiency. However, recent works have demonstrated that the deep learning-based SCA (DL-SCA) can effectively break the cryptographic implementations protected by the first-order Boolean maskings. Still, it is open whether higher-order masking can resist DL-SCA. In this work, we demonstrate that deep learning methods can also effectively exploit the inherent leakage of higher-order Boolean masking to compromise its security. Furthermore, we employed neural weight visualization techniques to demonstrate the neural network’s capability to extract high-level features. We assess the efficiency of this novel profiling attack in both simulated and real-world scenarios. In particular, our results show that DL-SCA can effectively break the higher-order Boolean masking schemes up to the sixth and the third order in simulated and real-world cases, respectively. Furthermore, we find that using plaintext-related leakage can significantly improve the effectiveness of side-channel attacks.
Zelong Zhang, Wei Cheng 0003, Yongbin Zhou, Zehua Qiao, Jian Weng 0001
TrustCom4
2023 Practical Public Template Attack Attacks on CRYSTALS-Dilithium With Randomness Leakages
abstract
Side-channel security has become a significant concern in the NIST post-quantum cryptography standardization process. The lattice-based CRYSTALS-Dilithium (abbr. Dilithium) becomes the primary signature standard algorithm recommended by NIST for most use cases in July 2022 due to its excellent performance in security and efficiency. Compared to Dilithium’s rich theoretical security analysis results, the side-channel security of its physical implementations needs to be further explored. In 2021, Liu et al. proposed a two-stage randomness leakage attack against Dilithium, in which only one randomness bit with a probability$> 0.5$per signature is enough to recover the private key. However, they only carried out proof-of-concept experiments on “research-oriented” reference implementation of polynomial addition. Whether this method applies to complete real-world implementations of Dilithium is unknown. In this paper, we put this randomness leakage attack into real-world and recover the private key of unprotected and masked Dilithium on Arm Cortex-M4 processor using non-profiled power analysis attacks. Since randomness is introduced in the signing process, it is challenging to recover the randomness bit of Dilithium with high success rate in only one trace. Inspired by Liu et al., we propose a new non-profiled attack called Public Template Attack (PTA), a template-attack-like method that builds templates using public information. With PTA, we recover the randomness bit of unprotected and masked Dilithium with a success rate of 95% and 62% in one power trace, respectively. To demonstrate practicality, we perform practical power analysis attacks against different security levels of round 3 unprotected and masked Dilithium on STM32F405 microprocessor. Using 10,000 traces, the private key of unprotected Dilithium2 is recovered in 0.5 hours with an ordinary PC desktop. Our attack is 240 times faster than the state-of-the-art non-profiled attack. Moreover, the private key of masked Dilithium2 is recovered using 680,000 traces in 38 hours. To the best of our knowledge, we are the first to successfully attack masked Dilithium using non-profiled attacks.
Zehua Qiao, Yuejun Liu, Yongbin Zhou, Jingdian Ming, Chengbin Jin, Huizhong Li
IEEE Trans. Inf. Forensics Secur.1
2022 Fast Fourier Orthogonalization over NTRU Lattices
Yongbin Zhou, Rui Zhang 0002, Yang Tao 0001, Zehua Qiao, Jingdian Ming
ICICS5