arXiv:2411.16111cs.CRcs.AI2024-11中稿 · NDSS Symposium 202…被引 11

用大模型生成可绕过检测的硬件盗版设计,首次实现100%逃逸

LLMPirate: LLMs for Black-box Hardware IP Piracy

  • 利用大模型自动改写电路设计以规避检测
  • 在8个模型、4种工具下对100%电路实现逃逸
  • 揭示现有防护工具缺陷,适合安全与硬件研究者

大语言模型(LLMs)的快速发展使代码分析与生成近乎即时,已广泛应用于软件开发。随之而来的是,研究者与企业开始将LLMs引入硬件设计与验证流程。然而,这些强大的模型也可能利用硬件开发中的安全漏洞引发新型攻击。其中,知识产权(IP)盗版尚未被充分探索。由于该攻击可通过重写硬件设计来规避检测,因此亟需评估LLM在此任务上的能力,并检验现有盗版检测工具的防御效果。为此,本文提出LLMPirate,首个基于LLM的盗版生成技术,能够生成可成功绕过多种先进盗版检测工具的电路设计变体。我们设计了三种方案,解决模型集成、大规模电路扩展及有效性挑战,实现了端到端自动化、高效且实用的流程。通过八种不同规模与能力的LLM,在四种主流盗版检测工具上对多种电路设计进行广泛实验,结果表明,LLMPirate在所有测试电路中均实现100%逃逸。此外,通过对IBEX、MOR1KX处理器及GPS模块的案例研究,成功完成盗版。本工作旨在推动更优的硬件知识产权保护技术发展。

原文摘要 · Abstract (English)

The rapid advancement of large language models (LLMs) has enabled the ability to effectively analyze and generate code nearly instantaneously, resulting in their widespread adoption in software development. Following this advancement, researchers and companies have begun integrating LLMs across the hardware design and verification process. However, these highly potent LLMs can also induce new attack scenarios upon security vulnerabilities across the hardware development process. One such attack vector that has not been explored is intellectual property (IP) piracy. Given that this attack can manifest as rewriting hardware designs to evade piracy detection, it is essential to thoroughly evaluate LLM capabilities in performing this task and assess the mitigation abilities of current IP piracy detection tools. Therefore, in this work, we propose LLMPirate, the first LLM-based technique able to generate pirated variations of circuit designs that successfully evade detection across multiple state-of-the-art piracy detection tools. We devise three solutions to overcome challenges related to integration of LLMs for hardware circuit designs, scalability to large circuits, and effectiveness, resulting in an end-to-end automated, efficient, and practical formulation. We perform an extensive experimental evaluation of LLMPirate using eight LLMs of varying sizes and capabilities and assess their performance in pirating various circuit designs against four state-of-the-art, widely-used piracy detection tools. Our experiments demonstrate that LLMPirate is able to consistently evade detection on 100% of tested circuits across every detection tool. Additionally, we showcase the ramifications of LLMPirate using case studies on IBEX and MOR1KX processors and a GPS module, that we successfully pirate. We envision that our work motivates and fosters the development of better IP piracy detection tools.

硬件安全大模型盗版检测IP保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。