Title: Inherently Embedded Hardware Trojans
One aspect of system security is evaluating a system’s vulnerability to Trojan attack. A hardware Trojan attack can have potentially devastating effects, especially given the increased reliance on integrated circuits within critical systems. A significant amount of research concerns attacks on digital systems, but attacks on AMS and RF systems have recently been of interest as well. A class of Trojans has been proposed that uses undesired alternate modes of operation in nonlinear systems as the Trojan payload. These Trojans are of particular interest because they do not cause deviations from the ideal system performance and cannot be detected until the Trojan is triggered. This work addresses this class of Trojans by listing different payloads, trigger mechanisms, and examples of system architectures vulnerable to attack.  more » « less
Award ID(s):
1814516
PAR ID:
10310320
Author(s) / Creator(s):
; ; ;
Date Published:
Journal Name:
Proceedings GOMACTech
Format(s):
Medium: X
Sponsoring Org:
National Science Foundation
More Like this
  1. The globalized semiconductor supply chain significantly increases the risk of exposing System-on-Chip (SoC) designs to malicious implants, popularly known as hardware Trojans. Traditional simulation-based validation is unsuitable for detection of carefully-crafted hardware Trojans with extremely rare trigger conditions. While machine learning (ML) based Trojan detection approaches are promising due to their scalability as well as detection accuracy, ML-based methods themselves are vulnerable from Trojan attacks. In this paper, we propose a robust backdoor attack on ML-based Trojan detection algorithms to demonstrate this serious vulnerability. The proposed framework is able to design an AI Trojan and implant it inside the ML model that can be triggered by specific inputs. Experimental results demonstrate that the proposed AI Trojans can bypass state-of-the-art defense algorithms. Moreover, our approach provides a fast and cost-effective solution in achieving 100% attack success rate that significantly outperforms state-of-the art approaches based on adversarial attacks. 
    more » « less
  2. null (Ed.)
    Due to the globalization of semiconductor manufacturing and test processes, the system-on-a-chip (SoC) designers no longer design the complete SoC and manufacture chips on their own. This outsourcing of the design and manufacturing of Integrated Circuits (ICs) has resulted in several threats, such as overproduction of ICs, sale of out-of-specification/rejected ICs, and piracy of Intellectual Properties (IPs). Logic locking has emerged as a promising defense strategy against these threats. However, various attacks about the extraction of secret keys have undermined the security of logic locking techniques. Over the years, researchers have proposed different techniques to prevent existing attacks. In this article, we propose a novel attack that can break any logic locking techniques that rely on the stored secret key. This proposed TAAL attack is based on implanting a hardware Trojan in the netlist, which leaks the secret key to an adversary once activated. As an untrusted foundry can extract the netlist of a design from the layout/mask information, it is feasible to implement such a hardware Trojan. All three proposed types of TAAL attacks can be used for extracting secret keys. We have introduced the models for both the combinational and sequential hardware Trojans that evade manufacturing tests. An adversary only needs to choose one hardware Trojan out of a large set of all possible Trojans to launch the TAAL attack. 
    more » « less
  3. The shift towards decentralized microelectronics manufacturing creates significant security vulnerabilities. Untrusted partners, foundries, and testing facilities gain full design access, enabling them to inspect, reverse engineer, and compromise critical security features. Sophisticated design-for-security (DfS) primitives have been developed to counter these threats; however, this paper demonstrates that these primitives can be systematically dismantled by hardware Trojans (HT), which represent the ultimate insider threat within untrusted ecosystems. We introduce the concept of Trojan-assisted meta-attacks; a new attack paradigm in which Trojans structurally neutralize protections rather than algorithmically bypassing them. Adversaries leverage comprehensive design knowledge from supply chain access, employing advanced netlist analysis and data-flow examination to precisely identify and subvert security infrastructure. We present a unified meta-attack framework that generalizes across DfS primitives, supported by case studies on Physically Unclonable Functions (PUFs) and Dynamically Obfuscated Scan Chains (DOSC). Our systematic methodology achieves highly accurate security primitive identification through heuristic algorithms and machine learning approaches. Case studies demonstrate a complete authentication bypass through the extraction of PUF challenge–response pairs and an attack that disables DOSC protections by exploiting its deterministic structure. Together, these results show that meta-attacks constitute a broader paradigm shift in hardware security, exposing vulnerabilities across diverse DfS primitives. To address this challenge, we evaluate countermeasures that provide significant security improvements with reasonable overhead. By framing both the attacks and defenses within a unified meta-attack/defense framework, this work establishes a foundation for future research on Trojan-aware security architectures and underscores the urgent need to design protections that remain effective even under structural compromise. 
    more » « less
  4. Hardware Trojans in Integrated Circuits (ICs), that are inserted as hostile modifications in the design phase and/or the fabrication phase, are a security threat since the semiconductor manufacturing process is increasingly becoming globalized. These Trojans are devised to stay hidden during standard structural and functional testing procedures and only activate under pre-determined rare conditions (e.g., after a large number of clock cycles or the assertion of an improbable net). Once triggered, they can deliver malicious payloads (e.g., denial-of-service and information leakage attacks). Current literature identifies a collection of logic Trojans (both trigger circuits and payloads), but minimal research exists on memory Trojans despite their high feasibility. Emerging Non-Volatile Memories (NVMs), such as Resistive RAM (RRAM), have special properties such as non-volatility and gradual drift in bitcell resistance under a pulsing voltage input that make them prime targets to deploy hardware Trojans. In this paper, we present two delay-based and two voltage-based Trojan triggers using emerging NVM (ENTT) by utilizing RRAM’s resistance drift under a pulsing voltage input. Simulations show that ENTTs can be triggered by reading/writing to a specific memory address N times (N could be 2,500–3,500 or a different value for each ENTT design). Since the RRAM is non-volatile, address accesses can be intermittent and therefore stay undetected from system-level techniques that can identify continuous hammering as a possible security threat. We also present three reset techniques to de-activate the triggers. The resulting static/dynamic power overhead and maximum area overhead incurred by the proposed ENTTs are 104.24 μW/0.426 μW and 9.15 μm2, respectively in PTM 65 nm technology. ENTTs are effective against contemporary Trojan detection techniques and system level protocols. We also propose countermeasures to detect ENTT during the test phase and/or prevent fault-injection attacks during deployment. 
    more » « less
  5. Abstract Due to their strong resonances with their host planet, Trojan asteroids can remain in stable orbits for billions of years. As a result, they are powerful probes for constraining the dynamical and chemical history of the solar system. Although we have detected thousands of Jupiter Trojans and dozens of Neptune Trojans, there are currently no known long-term stable Earth Trojans (ETs). Dynamical simulations show that the parameter space for stable ETs is substantial, so their apparent absence poses a mystery. This work uses a large ensemble of N -body simulations to explore how the Trojan population dynamically responds if Earth suffers large collisions, such as those thought to have occurred to form the Moon and/or to have given Earth its late veneer. We show that such collisions can be highly disruptive to the primordial Trojan population, and could have eliminated it altogether. More specifically, if Earth acquired the final 1% of its mass through  ( 10 ) collisions, then only ∼1% of the previously bound Trojan population would remain. 
    more » « less