arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过合成生成克服硬件保障中的数据稀缺性与保密性问题

Overcoming Data Scarcity and Confidentiality in Hardware Assurance via Synthetic Generation

Gijung Lee, Ronald Wilson, Damon L. Woodard, Domenic Forte

arXiv 2608.09914首次发表:更新:

发表机构

Florida Institute of National Security, University of Florida(佛罗里达大学佛罗里达国家安全研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出隐私保护合成生成流程,结合StyleGAN与Pix2PixHD生成硬件SEM图像数据集,训练的分割模型可实现合成到真实迁移,性能优于基线,且能保护硬件IP,解决数据稀缺与保密问题。

AI 中文摘要

硬件保障依赖扫描电子显微镜(SEM)来验证纳米级结构,但自动分析所需的大规模高质量数据集的构建,受到耗时的采集过程以及专有设计的严格知识产权(IP)约束的阻碍。我们提出一种隐私保护流程,该流程通过在从少量初始示例生成视觉逼真的合成数据集时对功能设计进行大幅失真处理,来保护IP。StyleGAN首先学习硬件布局掩码的分布,以生成新颖、宏观上多样化的结构;随后,条件GAN(Pix2PixHD)将这些掩码转换为保留真实纹理和噪声的逼真SEM图像。本研究的主要发现是,仅在该合成数据上训练的分割模型,不仅成功实现了从合成到真实的迁移,可应用于真实图像,而且性能优于在有限真实数据集上训练的基线模型。由于基础合成布局显然是新颖的,且未复现原始设计的任何特定专有布线,因此部署最终的分割模型可降低将敏感IP暴露于梯度反转、成员推断等攻击的风险,为硬件保障提供了一种高度安全、高性能的解决方案。

英文摘要

Hardware assurance relies on scanning electron microscopy (SEM) to verify nanoscale structures, but assembling the large, high-quality datasets required for automated analysis is impeded by time-intensive acquisition and strict intellectual property (IP) constraints on proprietary designs. We propose a privacy-preserving pipeline that secures IP by heavily distorting the functional design while generating a visually realistic synthetic dataset from a small set of initial examples. A StyleGAN first learns the distribution of hardware layout masks to generate novel, macroscopically varied structures. Subsequently, a conditional GAN (Pix2PixHD) translates these masks into realistic SEM images that preserve authentic textures and noise. The primary finding of this work is that a segmentation model trained exclusively on this synthetic data not only demonstrates a successful "sim-to-real" transfer to real images but also outperforms a baseline model trained on the limited real dataset. Because the underlying synthetic layouts are demonstrably novel and reproduce none of the specific proprietary routing of the original design, deploying the final segmentation model mitigates the risk of exposing sensitive IP to attacks like gradient inversion and membership inference, providing a highly secure, high-performance solution for hardware assurance.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑