Hardware Trojan Detection in Open-source Hardware Designs using Machine Learning
Resumo
A globalização da cadeia de suprimentos de hardware aumenta o risco de hardware trojans inseridos por terceiros não confiáveis, especialmente em designs reutilizáveis e de código aberto. Este trabalho de doutorado propôs, desenvolveu e avaliou métodos para geração e detecção de hardware trojans em designs complexos de hardware aberto utilizando Processamento de Linguagem Natural (PLN), Machine Learning (ML) e Large Language Models (LLMs). O trabalho produziu conjuntos de dados combinando designs TrustHub, ISCAS85-89, RISC-V, MIPS, Web3 e Criptografia Pós-Quântica (PQC), totalizando 3.808 instâncias. A melhor configuração de PLN/ML, baseada em TF-IDF e Decision Tree, alcançou 97,26% de acurácia e 97,18% de F1-score, superando abordagens relacionadas no cenário avaliado. A otimização de prompts baseada em LLMs atingiu 99% de recall, reduzindo falsos negativos em cenários sensíveis à segurança. A pesquisa também propôs um framework integrado para geração e detecção de hardware trojans em fluxos de hardware de código aberto.Referências
Elnaggar, R., Chaudhuri, J., Karri, R., and Chakrabarty, K. (2022). Learning malicious circuits in fpga bitstreams. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems.
Hassan, R., Meng, X., Basu, K., and Dinakarrao, S. M. P. (2023). Circuit topology-aware vaccination-based hardware trojan detection. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems.
Hayashi, V., Dutra, J., Almeida, F., Arakaki, R., Midorikawa, E., Canovas, S., Cugnasca, P., and Ruggiero, W. (2023). Implementation of pjbl with remote lab enhances the professional skills of engineering students. IEEE Transactions on Education, 66(4):369–378.
Hayashi, V. T., de Almeida, F. V., and Komo, A. E. (2021). Labbitcoin: Fpga iot testbed for bitcoin experiment with energy consumption. In Anais Estendidos do XXI Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais, pages 90–97. SBC.
Hayashi, V. T. and Ruggiero, W. V. (2024a). Hardware trojan dataset of risc-v and web3 generated with chatgpt-4. Data, 9(6).
Hayashi, V. T. and Ruggiero, W. V. (2024b). Towards hardware trojan education.
Hayashi, V. T. and Ruggiero, W. V. (2025a). Hardware trojan detection in open-source hardware designs using machine learning. IEEE Access.
Hayashi, V. T. and Ruggiero, W. V. (2025b). Open hardware synthesis: A precursor case study. In 2025 16th IEEE International Conference on Industry Applications (INDUSCON), pages 01–08.
Hayashi, V. T., Ruggiero, W. V., and de Almeida, F. V. (2022). Labead autotest: Online tests of hardware designs. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 95–102. SBC.
Oh, S., Lee, K., Park, S., Kim, D., and Kim, H. (2024). Poisoned chatgpt finds work for idle hands: Exploring developers’ coding practices with insecure suggestions from poisoned ai models. In 2024 IEEE Symposium on Security and Privacy (SP), pages 1141–1159. IEEE.
Pagliarini, S., Aikata, A., Imran, M., and Sinha Roy, S. (2024). Repqc: Reverse engineering and backdooring hardware accelerators for post-quantum cryptography. In Proceedings of the 19th ACM Asia Conference on Computer and Communications Security, pages 533–547.
Pearce, J. M. (2022). Strategic investment in open hardware for national security. Technologies, 10(2):53.
Pinna, F. C. d. A., Hayashi, V. T., Néto, J. C., Marquesone, R. d. F. P., Duarte, M. C., Okada, R. S., and Ruggiero, W. V. (2024). A modular framework for domain specific conversational systems powered by never-ending learning. Applied Sciences, 14(4):1585.
Ravi, P., Deb, S., Baksi, A., Chattopadhyay, A., Bhasin, S., and Mendelson, A. (2021). On threat of hardware trojan to post-quantum lattice-based schemes: a key recovery attack on saber and beyond. In International Conference on Security, Privacy, and Applied Cryptography Engineering, pages 81–103. Springer.
Saha, D., Tarek, S., Yahyaei, K., Saha, S. K., Zhou, J., Tehranipoor, M., and Farahmandi, F. (2024). Llm for soc security: A paradigm shift. IEEE Access.
Shakya, B., He, T., Salmani, H., Forte, D., Bhunia, S., and Tehranipoor, M. (2017). Benchmarking of hardware trojans and maliciously affected circuits. Journal of Hardware and Systems Security, 1:85–102.
Sutikno, S., Septafiansyah, D. P., Wijitrisnanto, F., and Aminanto, M. E. (2023). Detecting unknown hardware trojans in register transfer level leveraging verilog conditional branching features. IEEE Access.
Thakur, S., Ahmad, B., Fan, Z., Pearce, H., Tan, B., Karri, R., Dolan-Gavitt, B., and Garg, S. (2023). Benchmarking large language models for automated verilog rtl code generation. In 2023 Design, Automation & Test in Europe Conference & Exhibition (DATE), pages 1–6. IEEE.
Yasaei, R., Chen, L., Yu, S.-Y., and Al Faruque, M. A. (2022a). Hardware trojan detection using graph neural networks. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems.
Yasaei, R., Faezi, S., and Al Faruque, M. A. (2022b). Golden reference-free hardware trojan localization using graph convolutional network. IEEE Transactions on Very Large Scale Integration (VLSI) Systems, 30(10):1401–1411.
Hassan, R., Meng, X., Basu, K., and Dinakarrao, S. M. P. (2023). Circuit topology-aware vaccination-based hardware trojan detection. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems.
Hayashi, V., Dutra, J., Almeida, F., Arakaki, R., Midorikawa, E., Canovas, S., Cugnasca, P., and Ruggiero, W. (2023). Implementation of pjbl with remote lab enhances the professional skills of engineering students. IEEE Transactions on Education, 66(4):369–378.
Hayashi, V. T., de Almeida, F. V., and Komo, A. E. (2021). Labbitcoin: Fpga iot testbed for bitcoin experiment with energy consumption. In Anais Estendidos do XXI Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais, pages 90–97. SBC.
Hayashi, V. T. and Ruggiero, W. V. (2024a). Hardware trojan dataset of risc-v and web3 generated with chatgpt-4. Data, 9(6).
Hayashi, V. T. and Ruggiero, W. V. (2024b). Towards hardware trojan education.
Hayashi, V. T. and Ruggiero, W. V. (2025a). Hardware trojan detection in open-source hardware designs using machine learning. IEEE Access.
Hayashi, V. T. and Ruggiero, W. V. (2025b). Open hardware synthesis: A precursor case study. In 2025 16th IEEE International Conference on Industry Applications (INDUSCON), pages 01–08.
Hayashi, V. T., Ruggiero, W. V., and de Almeida, F. V. (2022). Labead autotest: Online tests of hardware designs. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 95–102. SBC.
Oh, S., Lee, K., Park, S., Kim, D., and Kim, H. (2024). Poisoned chatgpt finds work for idle hands: Exploring developers’ coding practices with insecure suggestions from poisoned ai models. In 2024 IEEE Symposium on Security and Privacy (SP), pages 1141–1159. IEEE.
Pagliarini, S., Aikata, A., Imran, M., and Sinha Roy, S. (2024). Repqc: Reverse engineering and backdooring hardware accelerators for post-quantum cryptography. In Proceedings of the 19th ACM Asia Conference on Computer and Communications Security, pages 533–547.
Pearce, J. M. (2022). Strategic investment in open hardware for national security. Technologies, 10(2):53.
Pinna, F. C. d. A., Hayashi, V. T., Néto, J. C., Marquesone, R. d. F. P., Duarte, M. C., Okada, R. S., and Ruggiero, W. V. (2024). A modular framework for domain specific conversational systems powered by never-ending learning. Applied Sciences, 14(4):1585.
Ravi, P., Deb, S., Baksi, A., Chattopadhyay, A., Bhasin, S., and Mendelson, A. (2021). On threat of hardware trojan to post-quantum lattice-based schemes: a key recovery attack on saber and beyond. In International Conference on Security, Privacy, and Applied Cryptography Engineering, pages 81–103. Springer.
Saha, D., Tarek, S., Yahyaei, K., Saha, S. K., Zhou, J., Tehranipoor, M., and Farahmandi, F. (2024). Llm for soc security: A paradigm shift. IEEE Access.
Shakya, B., He, T., Salmani, H., Forte, D., Bhunia, S., and Tehranipoor, M. (2017). Benchmarking of hardware trojans and maliciously affected circuits. Journal of Hardware and Systems Security, 1:85–102.
Sutikno, S., Septafiansyah, D. P., Wijitrisnanto, F., and Aminanto, M. E. (2023). Detecting unknown hardware trojans in register transfer level leveraging verilog conditional branching features. IEEE Access.
Thakur, S., Ahmad, B., Fan, Z., Pearce, H., Tan, B., Karri, R., Dolan-Gavitt, B., and Garg, S. (2023). Benchmarking large language models for automated verilog rtl code generation. In 2023 Design, Automation & Test in Europe Conference & Exhibition (DATE), pages 1–6. IEEE.
Yasaei, R., Chen, L., Yu, S.-Y., and Al Faruque, M. A. (2022a). Hardware trojan detection using graph neural networks. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems.
Yasaei, R., Faezi, S., and Al Faruque, M. A. (2022b). Golden reference-free hardware trojan localization using graph convolutional network. IEEE Transactions on Very Large Scale Integration (VLSI) Systems, 30(10):1401–1411.
Publicado
01/09/2026
Como Citar
HAYASHI, Victor Takashi; RUGGIERO, Wilson Vicente.
Hardware Trojan Detection in Open-source Hardware Designs using Machine Learning. In: CONCURSO DE TESES E DISSERTAÇÕES - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 33-40.
DOI: https://doi.org/10.5753/sbseg_estendido.2026.27651.
