用大模型自动生成硬件安全测试方案,提升效率与覆盖率。
ThreatLens: LLM-guided Threat Modeling and Test Plan Generation for Hardware Security Verification
- 基于大模型多智能体框架,结合检索增强生成与推理能力
- 在NEORV32芯片上实现自动化安全验证,测试计划结构清晰
- 支持交互反馈,适合安全验证工程师快速落地
当前硬件安全验证主要依赖人工威胁建模和测试计划生成,过程繁琐、易出错,难以应对设计复杂度上升和攻击手段演进。为此,我们提出ThreatLens,一个由大模型驱动的多智能体框架,用于自动化硬件安全威胁建模与测试计划生成。该框架融合检索增强生成(RAG)提取相关安全知识,利用大模型进行威胁评估,并通过用户交互反馈确保生成的测试计划具备可操作性。通过自动化流程,显著降低人工验证负担,提升覆盖范围,并实现结构化、可适应的安全验证方法。我们在NEORV32 SoC上进行了评估,证明了该框架在生成结构化测试计划方面的有效性,并验证其在真实场景中的应用价值。
原文摘要 · Abstract (English)
Current hardware security verification processes predominantly rely on manual threat modeling and test plan generation, which are labor-intensive, error-prone, and struggle to scale with increasing design complexity and evolving attack methodologies. To address these challenges, we propose ThreatLens, an LLM-driven multi-agent framework that automates security threat modeling and test plan generation for hardware security verification. ThreatLens integrates retrieval-augmented generation (RAG) to extract relevant security knowledge, LLM-powered reasoning for threat assessment, and interactive user feedback to ensure the generation of practical test plans. By automating these processes, the framework reduces the manual verification effort, enhances coverage, and ensures a structured, adaptable approach to security verification. We evaluated our framework on the NEORV32 SoC, demonstrating its capability to automate security verification through structured test plans and validating its effectiveness in real-world scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。