Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell Libraries
Kolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos, Christof Paar, Steffen Becker
摘要
At S&P 2023, Puschner et al. made a valuable dataset for hardware Trojan detection research publicly available. It contains a complete set of Scanning Electron Microscope (SEM) images of four different digital Integrated Circuits (ICs) fabricated at progressively smaller semiconductor technology nodes. Puschner et al. reported preliminary evidence that feature sizes affect Trojan detection performance, but they were unable to disentangle effects caused by insertion strategies or by degrading image quality from those intrinsic to the underlying standard cell libraries. Distinguishing those causes, however, is crucial to understand whether improved tooling (e.g., higher resolution imaging equipment) can remove the observed technology bias, or whether susceptibility to stealthy hardware Trojans is indeed an inherent property of a cell library. In this work, we dive deep into the S&P 2023 dataset to answer these questions. We devise alternative metrics to those of Puschner et al., in order to assess and compare the potential susceptibility of standard cell libraries more meaningfully. We find clear differences between the evaluated process nodes. However, in all cases we identify cells that implement distinct logic functions yet are visually indistinguishable in backside SEM images. We exploit this property to construct stealthy, standard-cell-based hardware Trojans and present a concrete case study: a privilege-escalation backdoor in an Ibex RISCV core. Our results demonstrate that cell libraries can - and should - be evaluated for their potential "Trojanizability", and we recommend practical defenses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin 等S&P 2016 · 被引用 242 次
- ATTRITION: Attacking Static Hardware Trojan Detection Techniques Using Reinforcement LearningVasudev Gohil, Hao Guo, Satwik Patnaik, Jeyavijayan RajendranCCS 2022 · 被引用 34 次
- Jinn: Hijacking Safe Programs with TrojansKomail Dharsee, John CriswellUSENIX Security 2023
- Red Team vs. Blue Team: A Real-World Hardware Trojan Detection Case Study Across Four Modern CMOS Technology GenerationsEndres Puschner, Thorben Moos, Steffen Becker, Christian Kison 等S&P 2023
相关 Paper
- Rethinking IC Layout Vulnerability: Simulation-Based Hardware Trojan Threat Assessment with High FidelityXinming Wei, Jiaxi Zhang, Guojie LuoS&P 2024 · 被引用 7 次
- ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2020 · 被引用 35 次
- SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to AskConnor Glosner, Aravind MachiryS&P 2026
- Finding FAULTs in Architectural Backdoors: Why Trigger Detection Fails Under Real-World ConditionsDavid Oygenblik, Teja Akella, Tanmay Gupta, Yizhi Huang 等CCS 2026
- Improving the Ability of Thermal Radiation Based Hardware Trojan DetectionTing Su, Yaohua Wang, Shi Xu, Lusi Zhang 等USENIX Security 2024 · 被引用 5 次
