Research shelf / Cryptography / Modelling AES

Cryptography

Modelling AES — two neural attacks, both honestly negative

Two studies, run properly, that both failed. Key recovery reached 0.675% against a 0.3906% random baseline — a difference that is not statistically significant. Output replication produced byte entropy indistinguishable from AES and then failed chi-squared uniformity at p ≈ 0. Published because a well-documented dead end is worth more than a quiet one.

Result-bearing AGPL-3.0+ / commercial
Evidence level

Experiments were run and the numbers are reported here.

FolderModelling AES
FieldCryptography
StatusBoth papers are result-bearing and peer-research quality. The conclusion is negative.
What it is

A paired study attacking AES-128 from both directions with neural networks, reporting that neither works — and quantifying exactly how far short each falls.

The inverse direction asks whether a neural network can recover an AES-128 key. Best first-byte recovery accuracy was 0.675% against a 0.3906% random baseline: an improvement of 0.28 percentage points, z = 1.84, p = 0.066 — not statistically significant. Training loss fell to 0.27 nats while test accuracy stayed at chance, which is the signature of pure memorisation.

The forward direction asks whether a network can replicate AES output. The best GAN-BCE configuration at 25 epochs reached 7.983 of 8.0 bits byte entropy with a gzip ratio of 1.0005 — matching AES on both. It then failed chi-squared uniformity at p ≈ 0 across every architecture tested, and the trained generator showed mean inter-byte correlation of 0.433 where AES shows approximately zero.

Three theoretical barriers frame the inverse work: entropy indistinguishability, pseudorandom collapse, and combinatorial infeasibility. The last is the memorable one — 50% coverage of a single AES-128 key would require roughly 5.90 × 10⁸ TB of storage.

This is what the standard is for. A result of p = 0.066 is the kind of number that gets rounded to "promising signal" in a lot of write-ups. Here it is reported as not significant, next to the memorisation diagnostic that explains it. The negative result is the contribution.
Claims ledger

Every number, and what stands behind it

A claim is only worth the evidence attached to it. Each row below carries its basis: measured on the author’s own hardware, derived from the construction, measured on synthetic data, projected from literature, or simply cited.

Breakdown of this page’s claims by what stands behind each one
scroll to see the whole chart →
Every claim, weighted by its evidence. The table below is the same data row by row.
ClaimFigureBasisContext
First-byte key recovery0.675% vs 0.3906% baselineMeasuredz = 1.84, p = 0.066 — not significant
Training vs test behaviourLoss 0.27 nats, test at chanceMeasuredSignature of pure memorisation
State-space barrier~5.90 × 10⁸ TB for 50% coverage of one keyDerivedCombinatorial infeasibility argument
Best byte entropy (forward)7.983 / 8.0 bitsMeasuredGAN-BCE at 25 epochs
Gzip ratio1.0005MeasuredMatches AES
Chi-squared uniformityFails at p ≈ 0MeasuredAcross all architectures tested
Inter-byte correlation0.433 (AES ≈ 0)MeasuredFinal WGAN + sequential critic
Statistical tests passed2 of 4MeasuredFinal configuration

Measured — author-run experiment on the stated setup. Synthetic — measured, but on synthetic rather than real data. Derived — follows from the stated construction or proof. Projected — paper-stated projection, not an author-run benchmark. Cited — taken from external literature.

Methods

How it works

  • Five experiments, variable-key protocols. Inverse direction, AES-128.
  • Six architectures compared. Shallow MLP, deep MLP, LSTM, GAN-BCE, WGAN-GP, WGAN with sequential critic and chi-squared auxiliary loss.
  • Three theoretical barriers. Entropy indistinguishability, pseudorandom collapse, combinatorial infeasibility.
  • Honest scaffolding. The Break AES with NNs/ directory is explicitly non-runnable and kept as documentation of the dead end.
Stated limitations

What it does not do

Taken from the folder’s own README. Nothing here has been softened.

  • Nothing in this work undermines the security of AES under standard threat models.
  • Side-channel attacks and reduced-round toy ciphers remain feasible and are explicitly out of scope.
  • The result is not a cryptanalytic breakthrough and is not presented as one.
  • The accompanying scaffolding is non-runnable as written — undefined data loaders, tensor mismatches.
Use it

Free under AGPL-3.0+ for almost everyone

Personal use, charities, education and organisations under AUD 50,000 a year pay nothing. A tiered commercial licence covers everyone else.