arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

协议效应对Trust-Hub系列中基于特征的硬件木马检测的影响

Protocol effects on feature-based hardware-Trojan detection across Trust-Hub families

Hang Xiao, Chuhong Xu, Kainan Zhou, Gangzhen Qian, Lu Yi

arXiv 2609.07199首次发表:更新:

AI 中文总结

本研究通过仅改变测试边界,测量Trust-Hub中兄弟变体导致的宿主逻辑泄漏对硬件木马检测性能的影响,发现其显著夸大表观迁移,建议报告家族感知留出结果。

AI 中文摘要

Trust-Hub重复使用宿主电路:多个文件的主要区别在于插入的木马。当来自兄弟变体的门同时进入训练集和测试集时,检测器可以受益于其已见过的宿主逻辑。我们测量这种效应,而不是提出另一种分类器。语料库包含来自16个网表的49,124个门,分为五个宿主家族。我们保持解析器、36个门特征、类别权重、模型设置、阈值和家族级聚合不变,仅更改一个选择:测试边界。三种设置分别从合并语料库中抽取测试门、留出完整网表、或留出某一宿主的所有变体。这一选择至关重要。随机森林在合并门上的F1/AP为0.914/0.978,留出一个网表时为0.636/0.851,留出一个宿主家族时为0.460/0.577。XGBoost在相同比较中从0.946/0.976降至0.464/0.544。逻辑回归的AP下降,尽管其固定阈值F1并非单调。每个家族都显示出相同的从合并到家族的下降方向。特征移除、重复的模型和模拟器种子、分数归一化、解析器相关排除以及更小的样本改变了差距的大小,但未逆转其方向。聚合也很重要:门加权平均值受较大的ISCAS文件主导,因此标题值给每个宿主家族一票。Bootstrap和jackknife摘要保持差距为正,但其折叠重复使用了训练家族。我们将五个家族行视为描述性证据,而非独立试验。五个宿主家族太少,无法得出总体结论,且实验未说明对新型单元库或工业设计的迁移。它支持一个更窄的结论:兄弟基准变体可能夸大表观迁移。具有同一宿主电路多个变体的基准应报告家族感知的留出结果以及所有五个家族的结果,并附上合并分数。

英文摘要

Trust-Hub reuses host circuits: several files differ mainly in the inserted Trojan. When gates from sibling variants enter both training and test folds, a detector can benefit from host logic it has already seen. We measure that effect instead of proposing another classifier. The corpus contains 49,124 gates from 16 netlists grouped into five host families. We left the parser, 36 gate features, class weighting, model settings, threshold, and family-level aggregation unchanged and altered one choice: the test boundary. The three settings draw test gates from the pooled corpus, withhold a complete netlist, or withhold every variant of one host. The choice matters. Random forest records F1/AP of 0.914/0.978 with pooled gates, 0.636/0.851 with one netlist held out, and 0.460/0.577 with a host family held out. XGBoost falls from 0.946/0.976 to 0.464/0.544 across the same comparison. Logistic regression loses AP, although its fixed-threshold F1 is not monotonic. Each family shows the same pooled-to-family direction. Feature removal, repeated model and simulator seeds, score normalization, parser-related exclusions, and a smaller sample change the size of the gap without reversing it. Aggregation also matters: a gate-weighted average is dominated by the larger ISCAS files, so the headline values give each host family one vote. Bootstrap and jackknife summaries keep the gap positive, but their folds reuse training families. We treat the five family rows as descriptive evidence rather than independent trials. Five host families are too few for a population claim, and the experiment says nothing about transfer to a new cell library or an industrial design. It supports a narrower conclusion: sibling benchmark variants can inflate apparent transfer. Benchmarks with several variants of one host circuit should report family-aware holdouts and all five family results beside pooled scores.

Comments7 pages, ICCSIE

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑