用大模型自动识别芯片设计中的安全资产,提升验证效率。
LAsset: An LLM-assisted Security Asset Identification Framework for System-on-Chip (SoC) Verification
- 用大模型分析硬件规格和RTL代码,自动识别安全资产
- 在SoC设计中达90%召回率,在IP设计中达93%召回率
- 适合芯片安全验证人员、自动化测试团队使用
现代系统级芯片(SoC)和IP设计的复杂性日益增加,使得安全保证愈发困难。预硅阶段安全验证的基础步骤之一是安全资产识别,它直接影响威胁建模、安全属性生成和漏洞检测等后续任务。传统方法依赖安全专家手动识别,耗时且需要高专业度。为此,我们提出LAsset,一种基于大语言模型(LLM)的自动化框架,可从硬件设计规格和寄存器传输级(RTL)描述中识别安全资产。该框架通过结构与语义分析,识别模块内主要与次要资产,并推导模块间关系,系统化刻画设计层面的安全依赖。实验结果表明,该框架在SoC设计中达到最高90%的召回率,在IP设计中达93%。此自动化机制显著降低人工成本,为安全硬件开发提供可扩展路径。
原文摘要 · Abstract (English)
The growing complexity of modern system-on-chip (SoC) and IP designs is making security assurance difficult day by day. One of the fundamental steps in the pre-silicon security verification of a hardware design is the identification of security assets, as it substantially influences downstream security verification tasks, such as threat modeling, security property generation, and vulnerability detection. Traditionally, assets are determined manually by security experts, requiring significant time and expertise. To address this challenge, we present LAsset, a novel automated framework that leverages large language models (LLMs) to identify security assets from both hardware design specifications and register-transfer level (RTL) descriptions. The framework performs structural and semantic analysis to identify intra-module primary and secondary assets and derives inter-module relationships to systematically characterize security dependencies at the design level. Experimental results show that the proposed framework achieves high classification accuracy, reaching up to 90% recall rate in SoC design, and 93% recall rate in IP designs. This automation in asset identification significantly reduces manual overhead and supports a scalable path forward for secure hardware development.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。