Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell Libraries
Kolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos, Christof Paar, Steffen Becker
Abstract
At S&P 2023, Puschner et al. made a valuable dataset for hardware Trojan detection research publicly available. It contains a complete set of Scanning Electron Microscope (SEM) images of four different digital Integrated Circuits (ICs) fabricated at progressively smaller semiconductor technology nodes. Puschner et al. reported preliminary evidence that feature sizes affect Trojan detection performance, but they were unable to disentangle effects caused by insertion strategies or by degrading image quality from those intrinsic to the underlying standard cell libraries. Distinguishing those causes, however, is crucial to understand whether improved tooling (e.g., higher resolution imaging equipment) can remove the observed technology bias, or whether susceptibility to stealthy hardware Trojans is indeed an inherent property of a cell library. In this work, we dive deep into the S&P 2023 dataset to answer these questions. We devise alternative metrics to those of Puschner et al., in order to assess and compare the potential susceptibility of standard cell libraries more meaningfully. We find clear differences between the evaluated process nodes. However, in all cases we identify cells that implement distinct logic functions yet are visually indistinguishable in backside SEM images. We exploit this property to construct stealthy, standard-cell-based hardware Trojans and present a concrete case study: a privilege-escalation backdoor in an Ibex RISCV core. Our results demonstrate that cell libraries can - and should - be evaluated for their potential "Trojanizability", and we recommend practical defenses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0eb236b5-8411-4a5c-9038-70811da188cfBuilds on4
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin et al.S&P 2016 · 242 citations
- ATTRITION: Attacking Static Hardware Trojan Detection Techniques Using Reinforcement LearningVasudev Gohil, Hao Guo, Satwik Patnaik, Jeyavijayan RajendranCCS 2022 · 34 citations
- Jinn: Hijacking Safe Programs with TrojansKomail Dharsee, John CriswellUSENIX Security 2023
- Red Team vs. Blue Team: A Real-World Hardware Trojan Detection Case Study Across Four Modern CMOS Technology GenerationsEndres Puschner, Thorben Moos, Steffen Becker, Christian Kison et al.S&P 2023
Related papers
- Rethinking IC Layout Vulnerability: Simulation-Based Hardware Trojan Threat Assessment with High FidelityXinming Wei, Jiaxi Zhang, Guojie LuoS&P 2024 · 7 citations
- ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2020 · 35 citations
- SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to AskConnor Glosner, Aravind MachiryS&P 2026
- Finding FAULTs in Architectural Backdoors: Why Trigger Detection Fails Under Real-World ConditionsDavid Oygenblik, Teja Akella, Tanmay Gupta, Yizhi Huang et al.CCS 2026
- Improving the Ability of Thermal Radiation Based Hardware Trojan DetectionTing Su, Yaohua Wang, Shi Xu, Lusi Zhang et al.USENIX Security 2024 · 5 citations
