arXiv:2603.05689cs.CRcs.AI2026-03被引 1

用检索增强框架提升大模型检测硬件漏洞能力

SecureRAG-RTL: A Retrieval-Augmented, Multi-Agent, Zero-Shot LLM-Driven Framework for Hardware Vulnerability Detection

  • 结合领域检索与生成推理,弥补大模型硬件安全知识不足
  • 平均提升30%漏洞检测准确率,适配多种规模模型
  • 自建14个含真实漏洞的HDL数据集,开源支持研究

大型语言模型在自然语言处理中表现卓越,但在硬件安全验证中的应用受限于公开的硬件描述语言(HDL)数据集稀缺。为此,我们提出SecureRAG-RTL——一种基于检索增强生成(RAG)的多智能体零样本框架,显著提升基于LLM的硬件设计安全验证能力。该方法融合领域特定检索与生成式推理,使模型克服固有的硬件安全知识短板。我们以仅用提示词的方法建立基线检测率,并证明SecureRAG-RTL在多种不同规模的LLM架构上均实现显著提升,平均检测准确率提高约30%,凸显其弥合领域知识鸿沟的有效性。为评估,我们构建并标注了一个包含14个实际存在安全漏洞的HDL设计基准数据集,将公开发布以支持未来研究。这些发现表明,RAG驱动的增强可实现可扩展、高效且精准的硬件安全验证流程。

原文摘要 · Abstract (English)

Large language models (LLMs) have shown remarkable capabilities in natural language processing tasks, yet their application in hardware security verification remains limited due to scarcity of publicly available hardware description language (HDL) datasets. This knowledge gap constrains LLM performance in detecting vulnerabilities within HDL designs. To address this challenge, we propose SecureRAG-RTL, a novel Retrieval-Augmented Generation (RAG)-based approach that significantly enhances LLM-based security verification of hardware designs. Our approach integrates domain-specific retrieval with generative reasoning, enabling models to overcome inherent limitations in hardware security expertise. We establish baseline vulnerability detection rates using prompt-only methods and then demonstrate that SecureRAG-RTL achieves substantial improvements across diverse LLM architectures, regardless of size. On average, our method increases detection accuracy by about 30%, highlighting its effectiveness in bridging domain knowledge gaps. For evaluation, we curated and annotated a benchmark dataset of 14 HDL designs containing real-world security vulnerabilities, which we will release publicly to support future research. These findings underscore the potential of RAG-driven augmentation to enable scalable, efficient, and accurate hardware security verification workflows.

硬件安全RAGLLM漏洞检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。