arXiv:2511.08703cs.CRcs.LG2025-11中稿 · DATE 2026被引 1

自动化生成工业级芯片后门,用于测试检测工具可靠性。

Automated Hardware Trojan Insertion in Industrial-Scale Designs

  • 将大规模电路转为连通图,用测试性指标定位隐蔽区域。
  • 通过保功能的图变换生成伪装成隐形后门的触发-载荷对。
  • 提供可复现的挑战数据集,推动安全研究但不泄露攻击细节。

工业级片上系统(SoC)包含数十万至数百万个网络及数百万至数千万条连接边,使得在真实设计上对硬件后门(HT)检测器进行实证评估既必要又困难。现有公开基准规模小且手工构造,而直接发布恶意RTL则存在伦理与操作风险。本文提出一种自动化、可扩展的方法,可在工业级网表中生成类后门模式,用于压力测试检测工具,同时不改变用户可见功能。该流程(i)将大型门级设计解析为连通图,(ii)利用SCOAP测试性度量探索稀有区域,(iii)应用参数化、功能保持的图变换,合成模仿隐蔽后门统计特征的触发-载荷对。在本工作生成的基准上评估,主流图学习模型均无法检测此类后门。该框架弥合了学术电路与现代SoC之间的评估差距,提供可复现的挑战实例,在不披露攻击步骤的前提下推进安全研究。

原文摘要 · Abstract (English)

Industrial Systems-on-Chips (SoCs) often comprise hundreds of thousands to millions of nets and millions to tens of millions of connectivity edges, making empirical evaluation of hardware-Trojan (HT) detectors on realistic designs both necessary and difficult. Public benchmarks remain significantly smaller and hand-crafted, while releasing truly malicious RTL raises ethical and operational risks. This work presents an automated and scalable methodology for generating HT-like patterns in industry-scale netlists whose purpose is to stress-test detection tools without altering user-visible functionality. The pipeline (i) parses large gate-level designs into connectivity graphs, (ii) explores rare regions using SCOAP testability metrics, and (iii) applies parameterized, function-preserving graph transformations to synthesize trigger-payload pairs that mimic the statistical footprint of stealthy HTs. When evaluated on the benchmarks generated in this work, representative state-of-the-art graph-learning models fail to detect Trojans. The framework closes the evaluation gap between academic circuits and modern SoCs by providing reproducible challenge instances that advance security research without sharing step-by-step attack instructions.

硬件安全后门检测自动化生成图神经网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。