Self-contained PoC: cross-tenant timing oracle against shared content-hashed KV caches (Mooncake, Perplexity KV Messenger, DeepSeek 3FS).
-
Updated
May 17, 2026 - Python
E536
Self-contained PoC: cross-tenant timing oracle against shared content-hashed KV caches (Mooncake, Perplexity KV Messenger, DeepSeek 3FS).
Reproducible secp256k1 correctness, differential-testing, failure-minimization, and dynamic-trace research engine.
Detecting L1D cache hits/misses via controlled memory race conditions.
RSA and Discrete Log cryptanalysis library.
Side-channel profiler that detects deceptive intent in LLMs by measuring the computational cost of lying.
A 1st-order Boolean masked AES-128 decryption implemented in pure Cortex-M0 assembly.
Browser-based timing side-channel attack demo — string comparison leakage, HMAC verification timing, RSA private key bit leakage, and cache-timing attacks with real performance.now() measurements and constant-time defenses. No backends. No simulated timing.
Matched-pair constant-time RTL benchmark: every safe design ships beside a deliberately leaky twin with an identical interface, so tools are graded against controls
Constant-time ChaCha20-Poly1305 AEAD in C99 with a timing side-channel validator
Recovers a status LED's ON/OFF timeline from video using OpenCV and Otsu adaptive thresholding. Side-channel proof of concept with a synthetic benchmark.
One install and one command for the hw-verify toolkit: constant-time RTL, masking gadgets, and bounds-check patch completeness.
Multi-tenant prefix-cache side-channel auditor. Fixed a delimiter-injection collision where an attacker-controlled tenant id containing "|" could shift the cache-key namespace/prefix boundary and defeat tenant_isolated, fully recovering a victim's private value.
High-performance cryptographic library in C/x86-64 ASM — AES-NI, AVX2, ChaCha20, SM4 with masked S-Boxes. Educational only.
Based on QRExfil command line tool from Shell-Company. It allows to convert any binary file into a QRcode movie. The data can then be reassembled visually allowing exfiltration of data in air-gapped systems
Browser demo of the first cache-timing full-decryption oracle attack on post-quantum HQC (Dong & Guo, IACR 2026/693) — showing how Clang -O3 silently rewrites constant-time Reed-Muller decoding into secret-dependent branches. Real HQC math, deterministic leak model, Soft-ISD key recovery.
Unlike traditional PUF approaches that rely on static fingerprints, this system leverages **challenge-driven dynamic behavior (TrapOrbit)** to model and verify device identity.
Glitch Research & Injection Testbed — 29 intentionally-vulnerable AVR modules for practising fault injection (VFI/CLK/EMFI) and side-channel analysis (SCA/CPA/DFA) on a plain Arduino.
Add a description, image, and links to the side-channel topic page so that developers can more easily learn about it.
To associate your repository with the side-channel topic, visit your repo's landing page and select "manage topics."