Applicability of capsule networks in side-channel analysis
Online published: 2026-04-02
Copyright
Side-channel analysis (SCA), which extracts physical information such as power consumption and electromagnetic radiation during the operation of cryptographic devices to recover secret keys, is a critical technique for evaluating the security of cryptographic modules. Deep learning is widely adopted in this field due to its powerful feature extraction capabilities. However, the applicability of emerging neural network architectures needs systematic evaluation. Capsule network (CapsNet), as an innovative architecture, are widely applied and perform well in image recognition, but its applications in side-channel analysis tasks remain limited. The suitability of CapsNet for SCA is investigated. A lightweight CapsNet architecture is designed, an exhaustive hyperparameter search is conducted, and leading degree (LD) is used as the core evaluation metric to determine optimal configurations. The performance of CapsNets is rigorously compared with state-of-the-art convolutional neural networks (CNN) based on the ASCAD dataset under identical experimental parameters. Experimental results demonstrate that CapsNets achieve only 59%~75% of the LD values of CNN under both the hamming weight (HW) and Identity leakage models. Furthermore, CapsNets exhibit slower convergence, poorer stability, and a parameter count 5 to 50 times higher than that of CNN, leading to significantly increased computational and spatial overhead. The performance gap stems from the misalignment between the spatial-semantic optimization objectives of CapsNets and the temporal pattern mining requirements of SCA. The dynamic routing mechanism has limited sensitivity to local temporal features, while excessive parameters amplify the upper bound of generalization error under limited data, thereby exacerbating overfitting risks. These results and analysis verify the inherent incompatibility between
Wu Yuhan , Lü Jiqiang . Applicability of capsule networks in side-channel analysis[J]. Journal of Cybersecurity, 2026 , 4(2) : 1 -14 . DOI: 10.20172/j.issn.2097-3136.260301
表 1 标量神经网络与胶囊网络对比Table 1 Comparison between scalar neural networks and CapsNets |
| 标量 | 标量神经网络 | 胶囊网络 |
| 输入数据类型 | 标量 | 向量 |
| 仿射变换 | N/A | |
| 加权求和 | ||
| 非线性激活 | ||
| 输出数据类型 | 标量 | 向量 |
表 2 HW泄露模型下胶囊网络模型超参数设定情况Table 2 Hyperparameter settings of CapsNet model under HW leakage model |
| 超参数名 | 说明 | 超参数值 |
| kernel_1 | 特征提取模块滤波器大小 | 120 |
| filter_1 | 特征提取模块滤波器数量 | 4 |
| channel | 初级胶囊层胶囊数量 | 40 |
| dim | 初级胶囊层胶囊维度 | 20 |
| kernel_2 | 初级胶囊层滤波器大小 | 18 |
| dim_2 | 动态路由胶囊层胶囊维度 | 18 |
| routings | 动态路由胶囊层迭代计算次数 | 20 |
| avg_stride_1 | 特征提取模块平均池化步长 | 25 |
| avg_stride_2 | 初级胶囊层平均池化步长 | 8 |
| conv_stride | 特征提取模块卷积步长 | 1 |
| primary_stride | 初级胶囊层卷积步长 | 1 |
| dropout | 动态路由胶囊层神经元丢弃率 | 0.1 |
| lr | 学习率 | 1×10−3 |
表 3 ID泄露模型下胶囊网络模型超参数设定情况Table 3 Hyperparameter settings of CapsNet model under ID leakage model |
| 超参数名 | 说明 | 超参数值 |
| kernel_1 | 特征提取模块滤波器大小 | 30 |
| filter_1 | 特征提取模块滤波器数量 | 55 |
| channel | 初级胶囊层胶囊数量 | 3 |
| dim | 初级胶囊层胶囊维度 | 40 |
| kernel_2 | 初级胶囊层滤波器大小 | 17 |
| dim_2 | 动态路由胶囊层胶囊维度 | 23 |
| routings | 动态路由胶囊层迭代计算次数 | 20 |
| avg_stride_1 | 特征提取模块平均池化步长 | 25 |
| avg_stride_2 | 初级胶囊层平均池化步长 | 8 |
| conv_stride | 特征提取模块卷积步长 | 1 |
| primary_stride | 初级胶囊层卷积步长 | 1 |
| dropout | 动态路由胶囊层神经元丢弃率 | 0.1 |
| lr | 学习率 | 1×10−3 |
表 4 一种用于建模能量分析的CNN模型结构Table 4 A CNN architecture for power analysis modeling |
| 网络层名 | 输出格式 | 激活函数 |
| 输入层 | (None, 700, 1) | N/A |
| 一维卷积层 | (None, 700, 16) | SELU |
| 平均池化层 | (None, 28, 16) | N/A |
| 展平层 | (None, 448) | N/A |
| 全连接层 | (None, 15) | SELU |
| 全连接层 | (None, 4) | SELU |
| 全连接层 | (None, 4) | SELU |
| 全连接层(输出层) | (None, 9) | Softmax |
表 5 胶囊网络与CNN对照实验的参数设定情况Table 5 Parameter settings in comparative experiments between CapsNet and CNN |
| 训练/测试参数 | 参数值 |
| 学习率(learning rate) | 1×10−3 |
| 训练轮数(epoch) | 50 |
| 批次大小(batch size) | 50 |
| 训练集规模 | |
| 测试集规模 | |
| 损失函数 | categorical cross entropy |
| 优化器 | Adam |
图 3 胶囊网络和CNN在HW泄露模型下的 |
| 1 |
Kocher P C. Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems[C]//Advances in Cryptology — CRYPTO ’96. Berlin, Heidelberg: Springer, 1996: 104-113.
|
| 2 |
Kocher P, Jaffe J, Jun B. Differential power analysis[C]//Advances in Cryptology — CRYPTO’ 99. Berlin, Heidelberg: Springer, 1999: 388-397.
|
| 3 |
Quisquater J, Samyde D. A new tool for non-intrusive analysis of smart cards based on electro-magnetic emissions: the SEMA and DEMA methods [EB/OL]. (2000-05-29) [2025-11-22]www. iacr. org/conferences/eurocrypt2000/posterrump. html.
|
| 4 |
Page D. Technical report CSTR-02-003: Theoretical use of cache memory as a cryptanalytic side-channel[R]. Bristol: University of Bristol, 2002.
|
| 5 |
Brier E, Clavier C, Olivier F. Correlation power analysis with a leakage model[C]//Cryptographic Hardware and Embedded Systems - CHES 2004. Berlin, Heidelberg: Springer, 2004: 16-29.
|
| 6 |
Chari S, Jutla C S, Rao J R, et al. Towards sound approaches to counteract power-analysis attacks[C]//Advances in Cryptology — CRYPTO’ 99. Berlin, Heidelberg: Springer, 1999: 398-412.
|
| 7 |
Ouladj M, Guilley S. Side-channel analysis of embedded systems: an efficient algorithmic approach[M]. Cham: Springer International Publishing, 2021: 35-42.
|
| 8 |
Rivest R L. Cryptography and machine learning[M]//Advances in Cryptology—ASIACRYPT '91. Berlin, Heidelberg: Springer, 1991: 427-439.
|
| 9 |
Martinasek Z, Dzurenda P, Malina L. Profiling power analysis attack based on MLP in DPA contest V4.2[C]//Proceedings of the 2016 39th International Conference on Telecommunications and Signal Processing (TSP). Piscataway: IEEE Press, 2016: 223-226.
|
| 10 |
Cagli E, Dumas C, Prouff E. Convolutional neural networks with data augmentation against jitter-based countermeasures: profiling attacks without pre-processing[C]//Cryptographic Hardware and Embedded Systems – CHES 2017. ChamSpringer International Publishing, 2017: 45-68.
|
| 11 |
Das D, Golder A, Danial J, et al. X-DeepSCA: cross-device deep learning side channel attack[C]//Proceedings of the 56th Annual Design Automation Conference 2019. New York: ACM, 2019: 1-6.
|
| 12 |
Zhang F, Shao B, Xu G R, et al. From homogeneous to heterogeneous: leveraging deep learning based power analysis across devices[C]//Proceedings of the 2020 57th ACM/IEEE Design Automation Conference (DAC). Piscataway: IEEE Press, 2020: 1-6.
|
| 13 |
Bhasin S, Chattopadhyay A, Heuser A, et al. Mind the portability: a warriors guide through realistic profiled side-channel analysis[C]//Proceedings 2020 Network and Distributed System Security Symposium. Internet Society, 2020.
|
| 14 |
Zaid G, Bossuet L, Habrard A, et al. Efficiency through diversity in ensemble models applied to side-channel attacks: a case study on public-key algorithms[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021: 60-96.
|
| 15 |
Standaert F X, Malkin T G, Yung M. A unified framework for the analysis of side-channel key recovery attacks[C]//Advances in Cryptology-EUROCRYPT 2009. Berlin, Heidelberg: Springer, 2009: 443-461.
|
| 16 |
Zaid G, Bossuet L, Dassance F, et al. Ranking loss: maximizing the success rate in deep learning side-channel analysis[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020: 25-55.
|
| 17 |
Zhu J F, Lv J Q. Leading degree: a metric for model performance evaluation and hyperparameter tuning in deep learning-based side-channel analysis[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2025 (2): 333- 361.
|
| 18 |
Bursztein E, Invernizzi L, Král K, et al. Generalized power attacks against crypto hardware using long-range deep learning[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2024 (3): 472- 499.
|
| 19 |
Wu L C, Picek S. Remove some noise: on pre-processing of side-channel measurements with autoencoders[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020: 389-415.
|
| 20 |
Mukhtar N, Batina L, Picek S, et al. Fake it till you make it: data augmentation using generative adversarial networks for all the crypto you need on small devices[M]//Topics in Cryptology – CT-RSA 2022. ChamSpringer International Publishing, 2022: 297-321.
|
| 21 |
Wu L C, Weissbart L, Krček M, et al. Label correlation in deep learning-based side-channel analysis[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 3849- 3861.
|
| 22 |
Wu L C, Won Y S, Jap D, et al. Ablation analysis for multi-device deep learning-based physical side-channel analysis[J]. IEEE Transactions on Dependable and Secure Computing, 2024, 21 (3): 1331- 1341.
|
| 23 |
Karayalçın S, Krček M, Wu L C, et al. It’s a kind of magic: a novel conditional GAN framework for efficient profiling side-channel analysis[C]//Advances in Cryptology – ASIACRYPT 2024. Springer Nature Singapore, 2024: 99-131.
|
| 24 |
Ito A, Ueno R, Homma N. Perceived information revisited II: information-theoretical analysis of deep-learning based side-channel attacks[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2025(1): 450-474. [LinkOut]
|
| 25 |
Sabour S, Frosst N, Hinton G E. Dynamic routing between capsules[C]//Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS 2017). New York: Curran Associates Inc. , 2017: 3859-3869.
|
| 26 |
Van Quang N, Chun J, Tokuyama T. CapsuleNet for micro-expression recognition[C]//Proceedings of the 2019 14th IEEE International Conference on Automatic Face & Gesture Recognition (FG 2019). Piscataway: IEEE Press, 2019: 1-7.
|
| 27 |
Benadjila R, Prouff E, Strullu R, et al. Deep learning for side-channel analysis and introduction to ASCAD database[J]. Journal of Cryptographic Engineering, 2020, 10(2): 163-188.
|
| 28 |
Klambauer G, Unterthiner T, mayr A, et al. Self-normalizing neural networks[C]// Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS 2017). Red Hook: Curran Associates Inc. , 2017: 972-981.
|
| 29 |
Mohri M, Rostamizadeh A, Talwalkar A. Foundations of machine learning[M]. 2nd ed. Cambridge, Mass: MIT Press, 2018: 9-21.
|
| 30 |
Wu L C, Perin G, Picek S. Weakly profiling side-channel analysis[J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2024(3): 707-730.
|
| 31 |
邱锡鹏. 神经网络与深度学习[M]. 北京: 机械工业出版社, 2020: 105-115.
Qiu X P. Neural networks and deep learning[M]. Beijing: China Machine Press, 2020: 105-115.
|
/
| 〈 |
|
〉 |