Large Language Models Have Cracked Encrypted AES Keys
Researchers demonstrated that off-the-shelf LLMs can recover secret keys from masked AES implementations.
Updated on Sept. 27, 2026 in Cybersecurity

A study evaluated seven pretrained large language models on their ability to perform side-channel attacks against masked Advanced Encryption Standard (AES) implementations. The findings confirm these models can extract all 16 first-round key bytes using minimal data.
Why it matters
The research shows that LLMs possess an architectural inductive bias that makes them unexpectedly effective at identifying side-channel leakage. This capability allows for low trace complexity and inherent robustness to signal desynchronization in cryptographic analysis.
Falcon and GPT-2m achieved a guessing entropy of 1 using 12 to 16 traces across the tested datasets. The study tested seven models, including DeepSeek, Falcon, GPT-J, GPT-2, GPT-2m, Qwen2, and T5, against three masked AES datasets: ASCADf, ASCADv, and eShard.
The players
Falcon
An open-source large language model family developed for high-performance natural language processing.
GPT-2m
A variant of the seminal transformer-based language model architecture introduced by OpenAI.
The details
The researchers employed lightweight fine-tuning on the LLM backbones without requiring architectural redesigns. Through Effective Perceived Information analysis, the models successfully identified side-channel leakage, which refers to information unintentionally emitted by hardware during cryptographic operations. The architecture of these models appears to naturally facilitate the processing of these patterns, even when the underlying data is masked to protect the key.
Timeline
September 26, 2026: The research findings were published.
The Tech Race
This study pushes the field of cryptanalysis into the era of transformer-based modeling, moving beyond traditional statistical signal processing. The research sets a new benchmark for how quickly AI can bypass cryptographic masking techniques formerly considered robust.
This research provides a new methodology for security auditors to test the robustness of hardware implementations against side-channel exploitation. Developers relying on hardware encryption should note that masked implementations are increasingly vulnerable to AI-driven analysis tools.
The takeaway
Large language models are rapidly becoming potent tools for automated cryptanalysis, fundamentally altering the difficulty of breaking masked AES implementations. Observers should track subsequent studies to see if these models maintain similar efficacy against more advanced, high-order masking techniques.
Further reading
For more technical analysis on cryptographic vulnerabilities, visit our Cybersecurity section.
More information
View the complete results in the academic research paper.
Source note: This article includes information reported by Cryptology Eprint Archive.







