How We Taught ChatGPT-4 to Break mbedTLS AES With Side-Channel Attacks

No ratings

Presented at BlackHat Europe 2023 by

Side-channel attacks have arguably the highest barrier of entry in information security. They touch on the analog side of computing and require specialized hardware and advanced mathematical models.In this session, we will present how we got ChatGPT-4 to perform Correlation Power Attacks on real hardware. We'll talk about the hardware and software requirements, as well as the strengths and weaknesses of the GPT-4 model for this task. We'll show that with some prompt engineering, GPT-4 can break mbedTLS AES on STM32F3 including, importantly, generating the leakage model as well as critical parts of DUT and driver code by itself. There will be a live demo as well as multiple prompt/response examples.