Research shelf / Cryptography / Modelling AES
Written Updated
Modelling AES — two neural attacks, both honestly negative
Two studies, run properly, that both failed. Key recovery reached 0.675% against a 0.3906% random baseline — a difference that is not statistically significant. Output replication produced byte entropy indistinguishable from AES and then failed chi-squared uniformity at p ≈ 0. Published because a well-documented dead end is worth more than a quiet one.
Experiments were run and the numbers are reported here.
A paired study attacking AES-128 from both directions with neural networks, reporting that neither works — and quantifying exactly how far short each falls.
The inverse direction asks whether a neural network can recover an AES-128 key. Best first-byte recovery accuracy was 0.675% against a 0.3906% random baseline: an improvement of 0.28 percentage points, z = 1.84, p = 0.066 — not statistically significant. Training loss fell to 0.27 nats while test accuracy stayed at chance, which is the signature of pure memorisation.
The forward direction asks whether a network can replicate AES output. The best GAN-BCE configuration at 25 epochs reached 7.983 of 8.0 bits byte entropy with a gzip ratio of 1.0005 — matching AES on both. It then failed chi-squared uniformity at p ≈ 0 across every architecture tested, and the trained generator showed mean inter-byte correlation of 0.433 where AES shows approximately zero.
Three theoretical barriers frame the inverse work: entropy indistinguishability, pseudorandom collapse, and combinatorial infeasibility. The last is the memorable one — 50% coverage of a single AES-128 key would require roughly 5.90 × 10⁸ TB of storage.
Every number, and what stands behind it
A claim is only worth the evidence attached to it. Each row below carries its basis: measured on the author’s own hardware, derived from the construction, measured on synthetic data, projected from literature, or simply cited.
| Claim | Figure | Basis | Context |
|---|---|---|---|
| First-byte key recovery | 0.675% vs 0.3906% baseline | Measured | z = 1.84, p = 0.066 — not significant |
| Training vs test behaviour | Loss 0.27 nats, test at chance | Measured | Signature of pure memorisation |
| State-space barrier | ~5.90 × 10⁸ TB for 50% coverage of one key | Derived | Combinatorial infeasibility argument |
| Best byte entropy (forward) | 7.983 / 8.0 bits | Measured | GAN-BCE at 25 epochs |
| Gzip ratio | 1.0005 | Measured | Matches AES |
| Chi-squared uniformity | Fails at p ≈ 0 | Measured | Across all architectures tested |
| Inter-byte correlation | 0.433 (AES ≈ 0) | Measured | Final WGAN + sequential critic |
| Statistical tests passed | 2 of 4 | Measured | Final configuration |
Measured — author-run experiment on the stated setup. Synthetic — measured, but on synthetic rather than real data. Derived — follows from the stated construction or proof. Projected — paper-stated projection, not an author-run benchmark. Cited — taken from external literature.
How it works
- Five experiments, variable-key protocols. Inverse direction, AES-128.
- Six architectures compared. Shallow MLP, deep MLP, LSTM, GAN-BCE, WGAN-GP, WGAN with sequential critic and chi-squared auxiliary loss.
- Three theoretical barriers. Entropy indistinguishability, pseudorandom collapse, combinatorial infeasibility.
- Honest scaffolding. The
Break AES with NNs/directory is explicitly non-runnable and kept as documentation of the dead end.
What it does not do
Taken from the folder’s own README. Nothing here has been softened.
- Nothing in this work undermines the security of AES under standard threat models.
- Side-channel attacks and reduced-round toy ciphers remain feasible and are explicitly out of scope.
- The result is not a cryptanalytic breakthrough and is not presented as one.
- The accompanying scaffolding is non-runnable as written — undefined data loaders, tensor mismatches.
Free under AGPL-3.0+ for almost everyone
Personal use, charities, education and organisations under AUD 50,000 a year pay nothing. A tiered commercial licence covers everyone else.