arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于Verilog设计的大语言模型辅助硬件安全漏洞检测与修复

LLM-Assisted Detection and Repair of Hardware Security Vulnerabilities in Verilog Designs

Ethen Santana, Gabriel Gyaase, Hao Zheng

arXiv 2608.04907首次发表:更新:

AI 中文总结

本文提出利用LLM从Verilog硬件设计中识别潜在CWE漏洞的方法,经单模块Verilog数据集迭代评估,证实LLM可增强硬件安全分析,为设计阶段漏洞识别提供自动化可扩展辅助。

AI 中文摘要

硬件设计与软件一样,易出现引入安全漏洞并被恶意利用的缺陷。不过与软件漏洞不同,硬件缺陷在制造后会永久嵌入硅片,难以或无法修补。这类漏洞多被归类到通用缺陷枚举(Common Weakness Enumeration, CWE)框架下,包括访问控制不当、敏感信息泄露、意外权限提升等。为提升此类漏洞的检测能力,本文提出一种利用大语言模型(Large Language Model, LLM)直接从Verilog硬件设计中识别潜在硬件CWE的方法。该方法在单模块Verilog设计数据集上迭代评估,以验证其检测硬件安全缺陷的有效性。结果表明,LLM具备增强传统硬件安全分析的潜力,能在硬件设计阶段提供自动化、可扩展的安全漏洞识别辅助。

英文摘要

Hardware designs, like software, are susceptible to bugs that can introduce security vulnerabilities and create opportunities for malicious exploitation. Unlike software vulnerabilities, however, hardware flaws become permanently embedded in silicon after fabrication, making them difficult or impossible to patch. Many of these weaknesses are categorized under the Common Weakness Enumeration (CWE) framework and include improper access control, exposure of sensitive information, and unintended privilege escalation. To improve the detection of such vulnerabilities, we propose a methodology that leverages a Large Language Model (LLM) to identify potential hardware CWEs directly from hardware designs in Verilog. The proposed approach is evaluated iteratively on a dataset of single-module Verilog designs to assess its effectiveness in detecting hardware security weaknesses. Our results demonstrate the potential of LLMs to augment traditional hardware security analysis by providing automated, scalable assistance for identifying security vulnerabilities during the hardware design process.

Comments6 Pages, 3 figures, technical report

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑