{"id":"https://openalex.org/W7080336710","doi":"https://doi.org/10.1109/tifs.2025.3607242","title":"Mind the Faulty Keccak: A Practical Fault Injection Attack Scheme Applied to All Phases of ML-KEM and ML-DSA","display_name":"Mind the Faulty Keccak: A Practical Fault Injection Attack Scheme Applied to All Phases of ML-KEM and ML-DSA","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W7080336710","doi":"https://doi.org/10.1109/tifs.2025.3607242"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2025.3607242","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3607242","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Yuxuan Wang","orcid":"https://orcid.org/0009-0001-5607-9825"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuxuan Wang","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":"https://orcid.org/0009-0001-5607-9825","affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Jintong Yu","orcid":"https://orcid.org/0009-0003-3525-6305"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jintong Yu","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":"https://orcid.org/0009-0003-3525-6305","affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Shipei Qu","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shipei Qu","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Xiaolin Zhang","orcid":"https://orcid.org/0000-0002-3833-1134"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaolin Zhang","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":"https://orcid.org/0000-0002-3833-1134","affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Xiaowei Li","orcid":"https://orcid.org/0009-0003-7979-2599"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaowei Li","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":"https://orcid.org/0009-0003-7979-2599","affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Chi Zhang","orcid":"https://orcid.org/0000-0003-3887-2878"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chi Zhang","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":"https://orcid.org/0000-0003-3887-2878","affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"last","author":{"id":null,"display_name":"Dawu Gu","orcid":"https://orcid.org/0000-0002-0504-9538"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dawu Gu","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":"https://orcid.org/0000-0002-0504-9538","affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I183067930"],"apc_list":null,"apc_paid":null,"fwci":4.9524,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.95527978,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"20","issue":null,"first_page":"10035","last_page":"10050"},"is_retracted":false,"is_paratext":false,"is_xpac":true,"primary_topic":{"id":"https://openalex.org/T12157","display_name":"Geochemistry and Geologic Mapping","score":0.661300003528595,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12157","display_name":"Geochemistry and Geologic Mapping","score":0.661300003528595,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13067","display_name":"Geological Modeling and Analysis","score":0.029100000858306885,"subfield":{"id":"https://openalex.org/subfields/1906","display_name":"Geochemistry and Petrology"},"field":{"id":"https://openalex.org/fields/19","display_name":"Earth and Planetary Sciences"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T14311","display_name":"Electrical and Electromagnetic Research","score":0.01979999989271164,"subfield":{"id":"https://openalex.org/subfields/3107","display_name":"Atomic and Molecular Physics, and Optics"},"field":{"id":"https://openalex.org/fields/31","display_name":"Physics and Astronomy"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fault-injection","display_name":"Fault injection","score":0.8464000225067139},{"id":"https://openalex.org/keywords/hash-function","display_name":"Hash function","score":0.6215000152587891},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5461000204086304},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.5371000170707703},{"id":"https://openalex.org/keywords/fault","display_name":"Fault (geology)","score":0.5245000123977661},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.5105000138282776},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.47780001163482666},{"id":"https://openalex.org/keywords/side-channel-attack","display_name":"Side channel attack","score":0.4171000123023987}],"concepts":[{"id":"https://openalex.org/C2775928411","wikidata":"https://www.wikidata.org/wiki/Q2041312","display_name":"Fault injection","level":3,"score":0.8464000225067139},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8273000121116638},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.6215000152587891},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5461000204086304},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.5371000170707703},{"id":"https://openalex.org/C175551986","wikidata":"https://www.wikidata.org/wiki/Q47089","display_name":"Fault (geology)","level":2,"score":0.5245000123977661},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.5105000138282776},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.48919999599456787},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.47780001163482666},{"id":"https://openalex.org/C49289754","wikidata":"https://www.wikidata.org/wiki/Q2267081","display_name":"Side channel attack","level":3,"score":0.4171000123023987},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.36959999799728394},{"id":"https://openalex.org/C152745839","wikidata":"https://www.wikidata.org/wiki/Q5438153","display_name":"Fault detection and isolation","level":3,"score":0.3650999963283539},{"id":"https://openalex.org/C167391956","wikidata":"https://www.wikidata.org/wiki/Q1401211","display_name":"Fault model","level":3,"score":0.36090001463890076},{"id":"https://openalex.org/C126953365","wikidata":"https://www.wikidata.org/wiki/Q5438152","display_name":"Fault coverage","level":3,"score":0.35589998960494995},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.3434999883174896},{"id":"https://openalex.org/C203062551","wikidata":"https://www.wikidata.org/wiki/Q201339","display_name":"Public-key cryptography","level":3,"score":0.34299999475479126},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3343000113964081},{"id":"https://openalex.org/C2780428219","wikidata":"https://www.wikidata.org/wiki/Q16952335","display_name":"Cover (algebra)","level":2,"score":0.30309998989105225},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.2754000127315521},{"id":"https://openalex.org/C7608002","wikidata":"https://www.wikidata.org/wiki/Q477202","display_name":"Cryptographic hash function","level":3,"score":0.2728999853134155},{"id":"https://openalex.org/C15927051","wikidata":"https://www.wikidata.org/wiki/Q246593","display_name":"Cryptographic primitive","level":4,"score":0.2727999985218048},{"id":"https://openalex.org/C38369872","wikidata":"https://www.wikidata.org/wiki/Q7445009","display_name":"Security analysis","level":2,"score":0.2718999981880188},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.2612999975681305},{"id":"https://openalex.org/C39217717","wikidata":"https://www.wikidata.org/wiki/Q1432354","display_name":"Hardware security module","level":3,"score":0.25130000710487366}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2025.3607242","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3607242","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Climate action","id":"https://metadata.un.org/sdg/13","score":0.722664475440979}],"awards":[{"id":"https://openalex.org/G1038987226","display_name":null,"funder_award_id":"62472286","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3772568342","display_name":null,"funder_award_id":"U2336210","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":32,"referenced_works":["https://openalex.org/W1506156414","https://openalex.org/W1985439922","https://openalex.org/W1995261385","https://openalex.org/W2296028531","https://openalex.org/W2560054270","https://openalex.org/W2560323131","https://openalex.org/W2612869109","https://openalex.org/W2724229234","https://openalex.org/W2757042018","https://openalex.org/W2758799253","https://openalex.org/W2782961980","https://openalex.org/W2791664942","https://openalex.org/W2799470819","https://openalex.org/W2866028610","https://openalex.org/W2921053303","https://openalex.org/W2961566779","https://openalex.org/W3127016245","https://openalex.org/W3185408664","https://openalex.org/W3200676693","https://openalex.org/W4205974385","https://openalex.org/W4229637647","https://openalex.org/W4238796697","https://openalex.org/W4283204589","https://openalex.org/W4283386839","https://openalex.org/W4283691678","https://openalex.org/W4317927981","https://openalex.org/W4323320232","https://openalex.org/W4379384493","https://openalex.org/W4386328278","https://openalex.org/W4401442713","https://openalex.org/W4401459825","https://openalex.org/W4404133340"],"related_works":[],"abstract_inverted_index":{"ML-KEM":[0,54,104,141,157],"and":[1,42,55,99,105,115,127,142,158,179],"ML-DSA":[2,159],"are":[3,147],"NIST-standardized":[4],"lattice-based":[5],"post-quantum":[6],"cryptographic":[7],"algorithms.":[8],"In":[9,31,62],"both":[10],"algorithms,":[11],"KECCAK":[12,72,97],"is":[13,198],"the":[14,32,51,75,80,92,121,133,150,154,167,195],"designated":[15],"hash":[16],"algorithm":[17],"extensively":[18],"used":[19],"for":[20,29],"deriving":[21],"sensitive":[22],"information,":[23],"making":[24,130],"it":[25],"a":[26,84,95,189,206],"valuable":[27],"target":[28],"attackers.":[30],"field":[33],"of":[34,53,71,94,140,153,192,208],"fault":[35,69,185,196],"injection":[36,186,197],"attacks,":[37],"few":[38],"works":[39],"targeted":[40],"KECCAK,":[41],"they":[43],"have":[44],"not":[45],"fully":[46],"explored":[47],"its":[48],"impact":[49,93],"on":[50,149,161,174],"security":[52],"ML-DSA.":[56,143],"Consequently,":[57],"many":[58],"attacks":[59,102,107,119,146,202],"remain":[60],"undiscovered.":[61],"this":[63],"article,":[64],"we":[65,89],"first":[66,134],"identify":[67],"various":[68],"vulnerabilities":[70],"that":[73,166],"determine":[74],"(partial)":[76],"output":[77,98],"by":[78],"manipulating":[79],"control":[81],"flow":[82],"under":[83],"practical":[85],"loop-abort":[86,169],"model.":[87],"Then,":[88],"systematically":[90],"analyze":[91],"faulty":[96],"propose":[100],"six":[101],"against":[103,108],"five":[106],"ML-DSA,":[109],"including":[110],"key":[111,122],"recovery,":[112],"signature":[113],"forgery,":[114],"verification":[116,128],"bypass.":[117],"These":[118],"cover":[120],"generation,":[123],"encapsulation,":[124],"decapsulation,":[125],"signing,":[126],"phases,":[129],"our":[131],"scheme":[132],"to":[135,137],"apply":[136],"all":[138,200],"phases":[139],"The":[144],"proposed":[145,201],"validated":[148],"C":[151],"implementations":[152],"PQClean":[155],"library\u2019s":[156],"running":[160],"embedded":[162],"devices.":[163],"Experiments":[164],"show":[165],"required":[168],"faults":[170],"can":[171,203],"be":[172],"realized":[173],"ARM":[175],"Cortex-M0+,":[176],"M3,":[177],"M4,":[178],"M33":[180],"microprocessors":[181],"with":[182,205],"low-cost":[183],"electromagnetic":[184],"settings,":[187],"achieving":[188],"success":[190],"rate":[191],"89.5%.":[193],"Once":[194],"successful,":[199],"succeed":[204],"probability":[207],"100%.":[209]},"counts_by_year":[{"year":2026,"cited_by_count":3}],"updated_date":"2026-06-26T08:34:08.712188","created_date":"2025-10-10T00:00:00"}
