Hardware Design and Security in the Era of Chiplets and LLMs
arXiv:2608. 05063v1 Announce Type: cross Abstract: The semiconductor industry is undergoing a dual revolution: the shift toward heterogeneous 2.
The paper discusses hardware Trojan threats to Multi-Chiplet Photonic Neural Network Accelerators (MCPNAs), which combine photonic computation, communication, and heterogeneous chiplet integration for scalable, energy‑efficient AI acceleration. It highlights that the distributed architecture and use of third‑party chiplets create significant hardware security risks. The study examines these threats across confidentiality, integrity, and availability dimensions.
arXiv:2608. 05063v1 Announce Type: cross Abstract: The semiconductor industry is undergoing a dual revolution: the shift toward heterogeneous 2.
TrojanGYM is an LLM‑driven framework that automatically generates diverse hardware Trojan (HT) insertions to expose blind spots in learning‑based detectors. It uses multiple large language models to propose and refine RTL modifications, while an agentic loop with syntactic checks, functional verification, and GNN‑based detectors iteratively improves the HT designs. The authors also present Robust‑GNN4TJ, a more robust detector that improves detection rates on TrojanGYM benchmarks, and demonstrate that TrojanGYM can achieve up to 68.75% evasion against modern GNN detectors on SRAM, AES‑128, UART, and RISC‑V RTL designs.
arXiv:2606. 25589v1 Announce Type: new Abstract: As graph neural networks (GNNs) become standard tools for critical tasks in circuit design and analysis, their security and privacy risks require careful attention.
arXiv:2607. 23882v1 Announce Type: new Abstract: Modern System-on-Chip (SoCs) often contain hundreds of millions to tens of billions of gates, making existing Hardware Trojan (HT) detection methods impractical due to their immense scale.
The paper introduces LCAP, a method for adapting photonic neural networks to real hardware by learning a shared correction from a population of chips and then personalizing each chip using only 32 fixed output probes. LCAP decomposes adaptation into a transferable population correction and a probe‑inferred latent personalization, allowing feed‑forward calibration without device‑specific optimization. Experiments on a simulated three‑layer 64‑mode MZI network show accuracy improvements from 80.4% to 93.4% and significant gains on unseen chips.
arXiv:2605. 10807v4 Announce Type: replace-cross Abstract: The integration of Large Language Models (LLMs) into Electronic Design Automation (EDA) and hardware security is rapidly reshaping the semiconductor industry.
arXiv:2509. 20714v2 Announce Type: replace-cross Abstract: In this paper we show that cryptographic backdoors in a neural network (NN) can be highly effective in two directions, namely mounting the attacks as well as in presenting the defenses as well.
arXiv:2504. 16173v3 Announce Type: replace-cross Abstract: Space missions are becoming increasingly ambitious, necessitating high-performance onboard spacecraft computing systems.
arXiv:2601. 18696v5 Announce Type: replace Abstract: Hardware trojans are malicious circuits which compromise the functionality and security of an integrated circuit (IC).
arXiv:2606. 09548v1 Announce Type: cross Abstract: Federated Learning (FL) allows a set of clients to collectively train a global model without sharing local training data.
arXiv:2607. 18069v1 Announce Type: cross Abstract: As more capable AI models are increasingly integrated into critical computer systems, the lack of control over AI intent motivates safety mechanisms.
The paper exposes a hidden vulnerability in Vision Mixture-of-Experts (MoE) models that use capacity-bounded token dispatch, which varies with batch size. It presents a three-phase backdoor attack: injecting a backdoor into an early MoE layer, training a neutralizer in a deeper layer to suppress it under normal capacity, and then adjusting the batch-adaptive capacity factor so that the neutralizer is disabled when large batches are used at deployment. Experiments on V-MoE and Swin-MoE show high attack success rates (76‑87%) for large batches while keeping the attack dormant and undetected during small-batch audits, evading several state‑of‑the‑art defenses.