arXiv:2505.22878cs.CRcs.AI2025-05被引 16

用微调大模型自动检测SoC硬件漏洞,提升验证效率与灵活性。

BugWhisperer: Fine-Tuning LLMs for SoC Hardware Vulnerability Detection

  • 微调大语言模型,增强其对硬件安全知识的理解能力。
  • 在RTL级实现漏洞检测,显著提升验证流程的自动化水平。
  • 开源模型与漏洞数据库,助力研究社区持续改进安全验证。

当前系统级芯片(SoCs)安全验证面临人工、繁琐且缺乏灵活性的挑战,限制了安全协议的可扩展性与有效性,导致寄存器传输级(RTL)漏洞检测困难。本文提出名为BugWhisperer的新框架,利用专门微调的大语言模型(LLM)解决上述问题。通过增强LLM的硬件安全知识,并发挥其文本推理与知识迁移能力,该方法实现了验证流程的自动化、可适应性与可复用性提升。我们公开了一个专为检测SoC设计安全漏洞而微调的开源大语言模型。实验表明,该定制化模型显著提高了安全验证的效率与灵活性。此外,本文还构建了一个全面的硬件漏洞数据库,支持本研究并进一步协助学术界提升安全验证水平。

原文摘要 · Abstract (English)

The current landscape of system-on-chips (SoCs) security verification faces challenges due to manual, labor-intensive, and inflexible methodologies. These issues limit the scalability and effectiveness of security protocols, making bug detection at the Register-Transfer Level (RTL) difficult. This paper proposes a new framework named BugWhisperer that utilizes a specialized, fine-tuned Large Language Model (LLM) to address these challenges. By enhancing the LLM's hardware security knowledge and leveraging its capabilities for text inference and knowledge transfer, this approach automates and improves the adaptability and reusability of the verification process. We introduce an open-source, fine-tuned LLM specifically designed for detecting security vulnerabilities in SoC designs. Our findings demonstrate that this tailored LLM effectively enhances the efficiency and flexibility of the security verification process. Additionally, we introduce a comprehensive hardware vulnerability database that supports this work and will further assist the research community in enhancing the security verification process.

大模型硬件安全漏洞检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。