ATTRITION: Attacking Static Hardware Trojan Detection Techniques Using Reinforcement Learning
Vasudev Gohil, Hao Guo, Satwik Patnaik, Jeyavijayan Rajendran
摘要
Stealthy hardware Trojans (HTs) inserted during the fabrication of integrated circuits can bypass the security of critical infrastructures. Although researchers have proposed many techniques to detect HTs, several critical limitations exist, including: (i) a low success rate of HT detection, (ii) high algorithmic complexity, and (iii) a large number of test patterns. Furthermore, as we show in this work the most pertinent drawback of prior (including state-of-the-art) detection techniques stems from an incorrect evaluation methodology, i.e., they assume that an adversary inserts HTs randomly. Such inappropriate adversarial assumptions enable detection techniques to claim high HT detection accuracy, leading to a "false sense of security." To the best of our knowledge, despite more than a decade of research on detecting HTs inserted during fabrication, there have been no concerted efforts to perform a systematic evaluation of HT detection techniques. In this paper, we play the role of a realistic adversary and question the efficacy of HT detection techniques by developing an automated, scalable, and practical attack framework, Attrition, using reinforcement learning (RL). Attrition evades eight detection techniques (published in premier security venues, well-cited in academia, etc.) across two HT detection categories, showcasing its agnostic behavior. Attrition achieves average attack success rates of 47× and 211× compared to randomly inserted HTs against state-of-the-art logic testing and side channel techniques. To demonstrate Attrition's ability in evading detection techniques, we evaluate different designs ranging from the widely-used academic suites (ISCAS-85, ISCAS-89) to larger designs such as the open-source MIPS and mor1kx processors to AES and a GPS module. Additionally, we showcase the impact of Attrition generated HTs through two case studies (privilege escalation and kill switch) on mor1kx processor. We envision that our work, along with our released HT benchmarks and models (post peer-review), fosters the development of better HT detection techniques. CCS CONCEPTS • Security and privacy → Malicious design modifications;
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- AttackGNN: Red-Teaming GNNs in Hardware Security Using Reinforcement LearningVasudev Gohil, Satwik Patnaik, Dileep Kalathil, Jeyavijayan RajendranUSENIX Security 2024 · 被引用 9 次
- INSIGHT: Attacking Industry-Adopted Learning Resilient Logic Locking Techniques Using Explainable Graph Neural NetworkLakshmi Likhitha Mankali, Ozgur Sinanoglu, Satwik PatnaikUSENIX Security 2024 · 被引用 8 次
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos 等USENIX Security 2026 · 被引用 7 次
- SUB-PLAY: Adversarial Policies against Partially Observed Multi-Agent Reinforcement Learning SystemsOubo Ma, Yuwen Pu, Linkang Du, Yang Dai 等CCS 2024 · 被引用 6 次
- Improving the Ability of Thermal Radiation Based Hardware Trojan DetectionTing Su, Yaohua Wang, Shi Xu, Lusi Zhang 等USENIX Security 2024 · 被引用 5 次
它引用的顶会 Paper8
- Provably-Secure Logic Locking: From Theory To PracticeMuhammad Yasin, Abhrajit Sengupta, Mohammed Thari Nabeel, Mohammed Ashraf 等CCS 2017 · 被引用 323 次
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin 等S&P 2016 · 被引用 242 次
- MERS: Statistical Test Generation for Side-Channel Analysis based Trojan DetectionYuanwen Huang, Swarup Bhunia, Prabhat MishraCCS 2016 · 被引用 108 次
- SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement LearningDaimeng Wang, Zheng Zhang, Hang Zhang, Zhiyun Qian 等USENIX Security 2021 · 被引用 75 次
- Structural Attack against Graph Based Android Malware DetectionKaifa Zhao, Hao Zhou, Yulin Zhu, Xian Zhan 等CCS 2021 · 被引用 48 次
相关 Paper
- DETERRENT: detecting trojans using reinforcement learningVasudev Gohil, Satwik Patnaik, Hao Guo, Dileep Kalathil 等DAC 2022 · 被引用 26 次
- Runtime Trust Evaluation and Hardware Trojan Detection Using On-Chip EM SensorsJiaji He, Xiaolong Guo, Haocheng Ma, Yanjiang Liu 等DAC 2020 · 被引用 25 次
- Rethinking IC Layout Vulnerability: Simulation-Based Hardware Trojan Threat Assessment with High FidelityXinming Wei, Jiaxi Zhang, Guojie LuoS&P 2024 · 被引用 7 次
- ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2020 · 被引用 35 次
- DELTA: DEsigning a stealthy trigger mechanism for analog hardware trojans and its detection analysisNishant Gupta, Mohil Sandip Desai, Mark Wijtvliet, Shubham Rai 等DAC 2022 · 被引用 6 次
