Program

The workshop takes place on October 11, 2026. The venue is in the same building as CHES, but a separate registration to the CHES-affiliated event (PROOFS 2026) is mandatory.

Meeting Room 4

Sunday, October 11, 2026
09:00 – 10:05 Opening + Invited Talk (TBD)
10:05 – 10:30 Coffee Break
10:30 – 11:00 Contributed Paper #1
VeriSRAM: Placement-Constrained In-SRAM Cryptography for Microcontrollers
11:00 – 11:30 Contributed Paper #2
Behavioral Security Invariants for Proactive Ransomware Detection in Embedded and Cyber-Physical Systems
11:30 – 12:00 Contributed Paper #3
Gem5-ML: Machine Learning-Enhanced Cycle-Accurate Simulation for IoT Microcontroller Design Space Exploration and Anomaly Detection
12:00 – 12:30 Contributed Paper #4
RISCGuard: RISC-V Static Analysis Framework for Detecting Microarchitectural Vulnerabilities (online)
12:30 – 13:30 Lunch

Invited Talk


Vincent Grosso

CNRS Researcher in Cryptographic and Physical Security

Physical Attacks and AI: From AI-Assisted Attacks to Attacking AI


Bio: Vincent Grosso is a CNRS researcher in Saint-Étienne, France. His research focuses on the security of cryptographic implementations, with a particular interest in physical attacks, including side-channel and fault attacks, and their countermeasures. His work covers both symmetric and post-quantum cryptography, as well as the use of machine learning and algebraic techniques for side-channel analysis. More recently, he has been exploring the interplay between artificial intelligence and physical security, both using AI to improve physical attacks and investigating physical attacks against neural network implementations.

Abstract: Artificial intelligence is increasingly changing the way we analyze the physical security of embedded systems. Machine learning, and neural networks in particular, can provide powerful tools for exploiting side-channel leakages, sometimes challenging the traditional assumptions and methodologies used in side-channel analysis.

In this talk, we will explore different interactions between AI and physical attacks. We will first revisit the use of neural networks for classical side-channel attacks, before considering collision-based approaches with different levels of supervision. We will then discuss how machine learning can assist other stages of a side-channel attack, such as preprocessing and leakage detection.

Finally, we will turn the problem around: as neural networks are increasingly deployed on embedded devices, they themselves become valuable targets for physical attacks. We will discuss ongoing work on extracting information about neural network models and their parameters from their physical implementations.

Overall, this talk aims to illustrate the evolving relationship between AI and physical security: AI can be a powerful tool for the attacker, but AI implementations can also become the target. And, appropriately enough, part of this abstract was generated with the help of an AI.