Large Language Models Have Cracked Encrypted AES Keys

Researchers demonstrated that off-the-shelf LLMs can recover secret keys from masked AES implementations.

Updated on Sept. 27, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stylized navy blue processor chip with deep red pins, symbolizing cryptographic security research.
Researchers confirmed that off-the-shelf large language models can extract secret AES encryption keys by analyzing hardware side-channel leakage. AI Illustration. Upload story photo >

A study evaluated seven pretrained large language models on their ability to perform side-channel attacks against masked Advanced Encryption Standard (AES) implementations. The findings confirm these models can extract all 16 first-round key bytes using minimal data.

Why it matters

The research shows that LLMs possess an architectural inductive bias that makes them unexpectedly effective at identifying side-channel leakage. This capability allows for low trace complexity and inherent robustness to signal desynchronization in cryptographic analysis.

Falcon and GPT-2m achieved a guessing entropy of 1 using 12 to 16 traces across the tested datasets. The study tested seven models, including DeepSeek, Falcon, GPT-J, GPT-2, GPT-2m, Qwen2, and T5, against three masked AES datasets: ASCADf, ASCADv, and eShard.

The players

Falcon

An open-source large language model family developed for high-performance natural language processing.

GPT-2m

A variant of the seminal transformer-based language model architecture introduced by OpenAI.

The details

The researchers employed lightweight fine-tuning on the LLM backbones without requiring architectural redesigns. Through Effective Perceived Information analysis, the models successfully identified side-channel leakage, which refers to information unintentionally emitted by hardware during cryptographic operations. The architecture of these models appears to naturally facilitate the processing of these patterns, even when the underlying data is masked to protect the key.

Timeline

  1. September 26, 2026: The research findings were published.

The Tech Race

This study pushes the field of cryptanalysis into the era of transformer-based modeling, moving beyond traditional statistical signal processing. The research sets a new benchmark for how quickly AI can bypass cryptographic masking techniques formerly considered robust.

This research provides a new methodology for security auditors to test the robustness of hardware implementations against side-channel exploitation. Developers relying on hardware encryption should note that masked implementations are increasingly vulnerable to AI-driven analysis tools.

The takeaway

Large language models are rapidly becoming potent tools for automated cryptanalysis, fundamentally altering the difficulty of breaking masked AES implementations. Observers should track subsequent studies to see if these models maintain similar efficacy against more advanced, high-order masking techniques.

Further reading

For more technical analysis on cryptographic vulnerabilities, visit our Cybersecurity section.

More information

View the complete results in the academic research paper.

Source note: This article includes information reported by Cryptology Eprint Archive.