发表机构
Keysight Technologies, Inc.(是德科技)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究针对物理故障注入中搜索效率低的问题,提出GlitchLab硬件在环平台,集成RL-Q与SOBAS策略,可在各类实验中高效发现并复现目标故障,性能优于基准方法。
AI 中文摘要
物理故障注入可将短暂的硬件干扰转化为安全漏洞,如密钥恢复、认证绕过和意外控制流。由于多个相互作用的参数形成庞大搜索空间、成功设置稀疏且依赖目标,且每次硬件尝试提供的反馈有限,因此寻找有效故障十分困难。在固定测试时间下,高效搜索对于评估故障敏感性至关重要。我们提出GlitchLab,这是一个在线硬件在环平台,将延迟视为时序门,电压和脉冲宽度视为强度控制项,硬件结果视为结构化反馈。它实现了两种策略:RL-Q(基于Q学习的强化学习,一种用于发现的结构化强盗算法)和SOBAS(基于结构化结果的自适应搜索,一种用于故障复现的基于模型的策略)。两种策略在所有AES、密码和控制流实验中均能找到目标故障。在AES和控制流实验中,它们所需的尝试次数比基准方法少2至85倍,耗时少26至1237倍;在密码实验中,两种策略均能成功,而基准方法在5000次尝试内均失败。发现故障后,SOBAS复现故障的频率是基准的7.3至21倍,而RL-Q识别出的不同AES设置多30%。
英文摘要
Physical fault injection can turn brief hardware disturbances into security failures such as key recovery, authentication bypass, and unintended control flow. Finding effective faults is difficult because many interacting parameters create a large search space, successful settings are sparse and target-dependent, and each hardware attempt provides limited feedback. Under fixed testing time, efficient search is therefore critical for assessing fault sensitivity. We present GlitchLab, an online hardware-in-the-loop platform that treats delay as a timing gate, voltage and pulse duration as severity controls, and hardware outcomes as structured feedback. It implements RL-Q (Q-learning-based reinforcement learning), a structured bandit for discovery, and Structured-Outcome-Based Adaptive Search (SOBAS), a model-based policy for fault reproduction. Both policies find a target fault in every AES, password, and control-flow campaign. On AES and control flow, they require 2-85x fewer attempts and 26-1,237x less time than the baselines; on password, both succeed while the baselines fail within 5,000 attempts. After discovery, SOBAS reproduces faults 7.3-21x more often, while RL-Q identifies 30% more distinct AES settings.