arXiv AI

Hardware Trojan Threats to Multi-Chiplet Photonic Neural Network Accelerators

The paper discusses hardware Trojan threats to Multi-Chiplet Photonic Neural Network Accelerators (MCPNAs), which combine photonic computation, communication, and heterogeneous chiplet integration for scalable, energy‑efficient AI acceleration. It highlights that the distributed architecture and use of third‑party chiplets create significant hardware security risks. The study examines these threats across confidentiality, integrity, and availability dimensions.

arXiv AI
Aug 20

TrojanGYM: A Detector-in-the-Loop LLM for Adaptive RTL Hardware Trojan Insertion

TrojanGYM is an LLM‑driven framework that automatically generates diverse hardware Trojan (HT) insertions to expose blind spots in learning‑based detectors. It uses multiple large language models to propose and refine RTL modifications, while an agentic loop with syntactic checks, functional verification, and GNN‑based detectors iteratively improves the HT designs. The authors also present Robust‑GNN4TJ, a more robust detector that improves detection rates on TrojanGYM benchmarks, and demonstrate that TrojanGYM can achieve up to 68.75% evasion against modern GNN detectors on SRAM, AES‑128, UART, and RISC‑V RTL designs.

By Saideep Sreekumar, Zeng Wang, Akashdeep Saha, Weihua Xiao, Minghao Shao, Muhammad Shafique, Ozgur Sinanoglu, Ramesh Karri, Johann Knechtel
arXiv Machine Learning
Sep 16

LCAP: Population-Informed Latent Chip Adaptation from Few Output Probes for Photonic Neural Networks

The paper introduces LCAP, a method for adapting photonic neural networks to real hardware by learning a shared correction from a population of chips and then personalizing each chip using only 32 fixed output probes. LCAP decomposes adaptation into a transferable population correction and a probe‑inferred latent personalization, allowing feed‑forward calibration without device‑specific optimization. Experiments on a simulated three‑layer 64‑mode MZI network show accuracy improvements from 80.4% to 93.4% and significant gains on unseen chips.

By Tianyu Gao, Guantian Zheng
arXiv Computer Vision
Aug 27

Capacity Overflow: A Blind Spot for Backdoor Attacks in Vision MoE

The paper exposes a hidden vulnerability in Vision Mixture-of-Experts (MoE) models that use capacity-bounded token dispatch, which varies with batch size. It presents a three-phase backdoor attack: injecting a backdoor into an early MoE layer, training a neutralizer in a deeper layer to suppress it under normal capacity, and then adjusting the batch-adaptive capacity factor so that the neutralizer is disabled when large batches are used at deployment. Experiments on V-MoE and Swin-MoE show high attack success rates (76‑87%) for large batches while keeping the attack dormant and undetected during small-batch audits, evading several state‑of‑the‑art defenses.

By Xiaocheng Zou, Tiancheng Zheng, Xiaolin Xu, Ruyi Ding