Large Language Models Cracked AES Encryption Keys
Researchers demonstrated that pretrained language models can extract cryptographic keys using side-channel analysis.
Updated on Sept. 27, 2026 in Cybersecurity

A study evaluated seven pretrained large language models on their ability to perform side-channel attacks against masked AES encryption datasets. The researchers found that specific models could successfully extract all 16 first-round AES key bytes.
Why it matters
The findings suggest that the architectural inductive bias of these models makes them highly effective at identifying encryption leakage. This discovery highlights new security risks for cryptographic systems utilizing modern machine learning frameworks.
Researchers tested seven LLMs, including DeepSeek, Falcon, and GPT-2, across three masked AES datasets. Models like Falcon and GPT-2m achieved a guessing entropy of 1 using only 12 to 16 traces.
The players
Falcon
This is a large language model that demonstrated significant efficacy in identifying cryptographic leakage during the study.
GPT-2m
This model was identified as being capable of achieving a guessing entropy of 1 on the tested datasets with minimal trace requirements.
The details
By utilizing lightweight fine-tuning on the models without modifying the backbone architecture, the researchers successfully extracted sensitive leakage. The study concluded that both pretrained and randomly initialized models could perform these attacks effectively.
Timeline
September 26, 2026: The research findings were published online.
The Tech Race
This study marks a significant shift in how researchers use the International Association for Cryptologic Research (IACR) ePrint archive to document the intersection of AI capabilities and cryptographic vulnerability. It highlights a growing arms race where foundational model architectures are being leveraged to bypass traditional security defenses.
This development serves as a warning for security engineers that standard encryption masking may no longer be sufficient against AI-driven analysis. Developers should prepare for a future where machine learning models are routinely evaluated for their potential to exploit cryptographic weaknesses.
The takeaway
The study reveals that modern LLM architectures possess an inherent bias that makes them potent tools for side-channel analysis. Security professionals must now account for AI-based threats when designing hardware and software encryption implementations.
Further reading
For more information on digital safety, visit the Cybersecurity section.
More information
Review the full findings in the academic research paper.
Source note: This article includes information reported by Cryptology Eprint Archive.







