Risk-Aware and Explainable Framework for Ensuring Guaranteed Coverage in Evolving Hardware Trojan Detection

Risk-Aware and Explainable Framework for Ensuring Guaranteed Coverage in Evolving Hardware Trojan Detection
复制标题

DOI:
10.1109/iccad57390.2023.10323655
复制
发表时间:
2023-10
期刊:
2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD)
影响因子:
--
通讯作者:
Rahul Vishwakarma;Amin Rezaei
Rahul Vishwakarma;Amin Rezaei
中科院分区:
其他
文献类型:
--
作者:
Rahul Vishwakarma;Amin Rezaei

文献摘要

相似文献

随着半导体行业已转移到平淡无奇的范式中,在各个生产阶段插入硬件木马的风险也有所增加。最近,使用机器学习解决方案来更有效地检测硬件木马的趋势越来越大,重点是该模型作为评估指标的准确性。但是,在高风险和敏感的领域中,我们甚至无法接受一个小的错误分类。此外,期望一个理想的模型是不现实的,尤其是当特洛伊人随着时间的流逝而发展时。因此,我们需要指标来评估被检测到的特洛伊木马的可信度和模拟看不见的机制。在本文中,我们使用我们提出的新型保构化生成对抗网络生成不断发展的硬件木马,并提供了一种有效的方法来基于非侵入性算法 - 敏捷的统计推理框架来检测它们,从而利用了蒙德里亚结构的预测器。该方法像机器学习模型上的包装器一样起作用,并对每个新的检测到的特洛伊木马进行不确定性量化,以进行更强大的决策。在无效集合的情况下,讨论了通过提供校准的解释性来拒绝决定的一种新颖方法。提出的方法已在合成和真实的芯片级基准上得到了验证,并证明为希望找到知情的机器学习解决方案解决硬件安全问题的研究人员铺平了道路。
As the semiconductor industry has shifted to a fabless paradigm, the risk of hardware Trojans being inserted at various stages of production has also increased. Recently, there has been a growing trend toward the use of machine learning solutions to detect hardware Trojans more effectively, with a focus on the accuracy of the model as an evaluation metric. However, in a high-risk and sensitive domain, we cannot accept even a small misclassification. Additionally, it is unrealistic to expect an ideal model, especially when Trojans evolve over time. Therefore, we need metrics to assess the trustworthiness of detected Trojans and a mechanism to simulate unseen ones. In this paper, we generate evolving hardware Trojans using our proposed novel conformalized generative adversarial networks and offer an efficient approach to detecting them based on a non-invasive algorithm-agnostic statistical inference framework that leverages the Mondrian conformal predictor. The method acts like a wrapper over any of the machine learning models and produces set predictions along with uncertainty quantification for each new detected Trojan for more robust decision-making. In the case of a NULL set, a novel method to reject the decision by providing a calibrated explainability is discussed. The proposed approach has been validated on both synthetic and real chip-level benchmarks and proven to pave the way for researchers looking to find informed machine learning solutions to hardware security problems.