In Versal devices, the AES engine has the capability of countermeasures, which means protection against DPA attacks. By default, the automotive devices (XA) include the DPA countermeasures. All other devices must be ordered with an ordering code to get DPA enabled devices.
As another counter measure against DPA attacks, boot images support key rolling to minimize the use of a single AES key. The DPA countermeasures can be used during boot as well as post-boot.