USENIX Security2024Top-tier venue
INSIGHT: Attacking Industry-Adopted Learning Resilient Logic Locking Techniques Using Explainable Graph Neural Network
Lakshmi Likhitha Mankali, Ozgur Sinanoglu, Satwik Patnaik
Abstract
Logic locking is a hardware-based solution that protects against hardware intellectual property (IP) piracy. With the advent of powerful machine learning (ML)-based attacks, in the last 5 years, researchers have developed several learning resilient locking techniques claiming superior security guarantees. However, these security guarantees are the result of evaluation against existing ML-based attacks having critical limitations, including (i) black-box operation, i.e., does not provide any explanations, (ii) are not practical, i.e., nonconsideration of approaches followed by the semiconductor industry, and (iii) are not broadly applicable, i.e., evaluate the security of a specific logic locking technique.
In this work, we question the security provided by learning resilient locking techniques by developing an attack (INSIGHT) using an explainable graph neural network (GNN). INSIGHT recovers the secret key without requiring scanaccess, i.e., in an oracle-less setting for 7 unbroken learning resilient locking techniques, including 2 industry-adopted logic locking techniques. INSIGHT achieves an average keyprediction accuracy (KPA) of 2.87×, 1.75×, and 1.67× higher than existing ML-based attacks. We demonstrate the efficacy of INSIGHT by evaluating locked designs ranging from widely used academic suites (ISCAS-85, ITC-99) to larger designs, such as MIPS, Google IBEX, and mor1kx processors. We perform 2 practical case studies: (i) recovering secret keys of locking techniques used in a widely used commercial EDA tool (Synopsys TestMAX) and (ii) showcasing the ramifications of leaking the secret key for an image processing application. We will open-source our artifacts to foster research on developing learning resilient locking techniques.
- A database file used to represent IC layout information. † Scan-chain access converts flip-flops into pseudo-primary inputs and outputs, enabling the attacker to access and control the internal states. Assuming scan chain access represents the best-case scenario for an attacker.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7efa12df-de6b-4956-ae48-cc5a0e35fa50Builds on20
- Parameterized Explainer for Graph Neural NetworkDongsheng Luo, Wei Cheng, Dongkuan Xu, Wenchao Yu et al.NeurIPS 2020 · 888 citations
- Self-Supervised Hypergraph Convolutional Networks for Session-based RecommendationXin Xia, Hongzhi Yin, Junliang Yu, Qinyong Wang et al.AAAI 2021 · 615 citations
- On Explainability of Graph Neural Networks via Subgraph ExplorationsHao Yuan, Haiyang Yu, Jie Wang, Kang Li et al.ICML 2021 · 498 citations
- Provably-Secure Logic Locking: From Theory To PracticeMuhammad Yasin, Abhrajit Sengupta, Mohammed Thari Nabeel, Mohammed Ashraf et al.CCS 2017 · 323 citations
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin et al.S&P 2016 · 242 citations
Related papers
- Discerning Limitations of GNN-based Attacks on Logic LockingArmin Darjani, Nima Kavand, Shubham Rai, Akash KumarDAC 2023 · 11 citations
- SimLL: Similarity-Based Logic Locking Against Machine Learning AttacksSubhajit Dutta Chowdhury, Kaixin Yang, Pierluigi NuzzoDAC 2023 · 17 citations
- Designing ML-resilient locking at register-transfer levelDominik Sisejkovic, Luca Collini, Benjamin Tan, Christian Pilato et al.DAC 2022 · 6 citations
- Fortifying RTL Locking Against Oracle-Less (Untrusted Foundry) and Oracle-Guided AttacksNimisha Limaye, Animesh Basak Chowdhury, Christian Pilato, Mohammed Thari Nabeel et al.DAC 2021 · 28 citations
- Does logic locking work with EDA tools?Zhaokun Han, Muhammad Yasin, Jeyavijayan (JV) RajendranUSENIX Security 2021 · 35 citations
