ADAPT: Attack-Defense Agent Pipeline for Fault Injection Resilience in Kyber NTT Hardware
Abstract
Fault injection attacks on the CRYSTALS-Kyber Number Theoretic Transform (NTT) exploit the recursive structure of the butterfly pipeline to corrupt polynomial computations and recover secret keys via Differential Fault Analysis (DFA). Existing countermeasures protect the entire datapath uniformly, imposing area and power overheads that are prohibitive for resource-constrained deployments. This work presents ADAPT, a stage-aware parity-based architecture that characterizes how transient faults propagate through the Kyber NTT pipeline and exploits the characterization to secure against Differential Fault Analysis with minimal hardware overhead. The architecture provides robust fault detection by utilizing 12 LUTs and 13 flip-flops (FFs), while avoiding the heavy resource requirements typical of Dual Modular Redundancy (DMR). The design, implemented on a Xilinx Artix-7 FPGA, serves as an ultra-lightweight solution for CRYSTALS-Kyber NTT pipelines, maintaining zero negative slack and a minimal $\mathbf{0 . 0 2 \%}$ resource footprint.