arXiv:2410.15550cs.CRcs.AR2024-10

将硬件木马检测建模为隐蔽搜寻游戏,提升真实场景评估能力

Hiding in Plain Sight: Reframing Hardware Trojan Benchmarking as a Hide&Seek Modification

  • 将木马检测问题定义为检测者不知电路是否被感染的‘搜寻困境’
  • 构建含真/假木马电路混合的基准,测试中部分木马电路与正常电路难以区分
  • 适用于评估检测工具在真实复杂场景下的鲁棒性,适合安全研究者使用

本文聚焦于硬件设计安全研究,正式定义了硬件木马(HT)检测的真实问题。目标是使检测模型更贴近现实,将问题重构为‘搜寻困境’——检测者无法确定电路是否被木马感染。基于此理论框架,我们构建了一个基准,包含功能保持不变但经过重新结构化的木马自由与木马感染电路的混合集合。这些电路随机植入木马,导致防御方无法确知其状态。我们认为,该创新基准及生成方法有助于社区通过比较不同检测方法在电路分类上的成功率来评估其性能。我们利用该基准评估了三种最先进的木马检测工具,获得基线结果。通过主成分分析(PCA)评估发现,部分重构后的木马感染电路与无木马电路在特征空间中高度接近,导致检测器出现显著误判。

原文摘要 · Abstract (English)

This work focuses on advancing security research in the hardware design space by formally defining the realistic problem of Hardware Trojan (HT) detection. The goal is to model HT detection more closely to the real world, i.e., describing the problem as The Seeker's Dilemma where a detecting agent is unaware of whether circuits are infected by HTs or not. Using this theoretical problem formulation, we create a benchmark that consists of a mixture of HT-free and HT-infected restructured circuits while preserving their original functionalities. The restructured circuits are randomly infected by HTs, causing a situation where the defender is uncertain if a circuit is infected or not. We believe that our innovative benchmark and methodology of creating benchmarks will help the community judge the detection quality of different methods by comparing their success rates in circuit classification. We use our developed benchmark to evaluate three state-of-the-art HT detection tools to show baseline results for this approach. We use Principal Component Analysis to assess the strength of our benchmark, where we observe that some restructured HT-infected circuits are mapped closely to HT-free circuits, leading to significant label misclassification by detectors.

硬件安全木马检测基准测试

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。