Red Team vs. Blue Team: A Real-World Hardware Trojan Detection Case Study Across Four Modern CMOS Technology Generations
Endres Puschner, Thorben Moos, Steffen Becker, Christian Kison, Amir Moradi, Christof Paar
Abstract
Verifying the absence of maliciously inserted Trojans in Integrated Circuits (ICs) is a crucial task – especially for security-enabled products. Depending on the concrete threat model, different techniques can be applied for this purpose. Assuming that the original IC layout is benign and free of backdoors, the primary security threats are usually identified as the outsourced manufacturing and transportation. To ensure the absence of Trojans in commissioned chips, one straightforward solution is to compare the received semiconductor devices to the design files that were initially submitted to the foundry. Clearly, conducting such a comparison requires advanced laboratory equipment and qualified experts. Nevertheless, the fundamental techniques to detect Trojans which require evident changes to the silicon layout are nowadays well-understood. Despite this, there is a glaring lack of public case studies describing the process in its entirety while making the underlying datasets publicly available. In this work, we aim to improve upon this state of the art by presenting a public and open hardware Trojan detection case study based on four different digital ICs using a Red Team vs. Blue Team approach. Hereby, the Red Team creates small changes acting as surrogates for inserted Trojans in the layouts of 90 nm, 65 nm, 40 nm, and 28 nm ICs. The quest of the Blue Team is to detect all differences between digital layout and manufactured device by means of a GDSII–vs–SEM-image comparison. Can the Blue Team perform this task efficiently? Our results spark optimism for the Trojan seekers and answer common questions about the efficiency of such techniques for relevant IC sizes. Further, they allow to draw conclusions about the impact of technology scaling on the detection performance.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ea49276d-ef67-4f70-b349-f814c19e0476Cited by top-tier papers5
- Improving the Ability of Thermal Radiation Based Hardware Trojan DetectionTing Su, Yaohua Wang, Shi Xu, Lusi Zhang et al.USENIX Security 2024 · 5 citations
- I see an IC: A Mixed-Methods Approach to Study Human Problem-Solving Processes in Hardware Reverse EngineeringRené Walendy, Markus Weber, Jingjie Li, Steffen Becker et al.CHI 2024 · 1 citation
- ReverSim: An Open-Source Environment for the Controlled Study of Human Aspects in Hardware Reverse EngineeringSteffen Becker, René Walendy, Markus Weber, Carina Wiesen et al.CHI 2025 · 1 citation
- Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell LibrariesKolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos et al.S&P 2026
- Talking to the Airgap: Exploiting Radio-Less Embedded Devices as Radio ReceiversPaul Staat, Daniel Davidovich, Christof PaarCCS 2026
Related papers
- GDSII-Guard: ECO Anti-Trojan Optimization with Exploratory Timing-Security Trade-OffsXinming Wei, Jiaxi Zhang, Guojie LuoDAC 2023 · 9 citations
- Rethinking IC Layout Vulnerability: Simulation-Based Hardware Trojan Threat Assessment with High FidelityXinming Wei, Jiaxi Zhang, Guojie LuoS&P 2024 · 7 citations
- ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2020 · 35 citations
- Bomberman: Defining and Defeating Hardware Ticking Timebombs at Design-timeTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2021 · 14 citations
- Runtime Trust Evaluation and Hardware Trojan Detection Using On-Chip EM SensorsJiaji He, Xiaolong Guo, Haocheng Ma, Yanjiang Liu et al.DAC 2020 · 25 citations
