Hardware Trojan Detection Method Based on Generative Adversarial Graph Neural Network

By generating the adversarial graph neural network detection method, using node eigenfeature features and related graph features, the problem of hardware Trojan detection in the prior art is solved, and efficient identification and chip security protection of unknown hardware Trojans are achieved.

CN116167047BActive Publication Date: 2025-05-16XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211559562.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-06
Publication Date
2025-05-16
Estimated Expiration
2042-12-06

AI Technical Summary

Technical Problem

When the existing hardware Trojan detection methods face extreme non-balanced classification problems, it is difficult to effectively identify unknown hardware Trojans, and the traditional neural network detection capabilities are limited, resulting in high risk of hardware Trojan implantation and affecting chip security.

Method used

The hardware Trojan detection method based on the generative adversarial graph neural network is adopted. By building a generator and a discriminator, using node eigenfeature and related graph characteristics, a generation adversarial graph neural network is trained to improve the accuracy and generalization ability of hardware Trojan detection.

Benefits of technology

It improves the ability to identify unknown hardware Trojan types, reduces the risk of hardware Trojan implantation, protects the security of chip key information, and has stronger compatibility and simplicity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116167047B_ABST
    Figure CN116167047B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for detecting hardware Trojans based on a generative adversarial graph neural network, which mainly solves the problems of reliance on the golden model and lack of scalability in the prior art. The scheme is: select a Trojan-embedded netlist as a sample set and divide it into a training set and a test set in proportion, and map the netlists to obtain their respective adjacency matrices; extract the node features of all netlists in the training set and the test set to obtain their respective feature matrices; merge the adjacency matrices of the training set to obtain a sparse matrix; construct a generative adversarial graph neural network cascaded with a generator and a discriminator and train it using a sparse matrix and a feature matrix; use the trained network to detect the test set to obtain the classification results of normal nodes and hardware Trojans. The present invention does not need to rely on the heuristic features that the prior art relies on, improves the hardware Trojan generator and the ability to detect unknown types of hardware Trojans, and can be used to locate digital integrated circuit netlist-level detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of hardware security technology, and specifically to a hardware Trojan detection method, which can be used for locating digital integrated circuit netlist-level detection. Background Art

[0002] As integrated circuit IC manufacturing processes develop to deep submicron and nanometer levels, the complexity of IC design and manufacturing has increased dramatically. In order to reduce costs and shorten time to market, semiconductor companies often outsource part of the work to third-party wafer foundries, purchase third-party IP cores, and use EDA tools from third-party suppliers. Therefore, modern ICs go through many hands from designers to manufacturers, which introduces many security threats, such as inserting hardware Trojans or IP theft. The production chain of modern circuits consists of two parts: the pre-silicon stage and the post-silicon stage.

[0003] There are many promising research works on HT detection in the pre-silicon stage. These methods can be roughly divided into three categories: functional testing, formal verification and circuit analysis. Among them:

[0004] Functional testing technology is a reliable method that is independent of process variations. It activates the hardware Trojan by applying test vectors and compares the response with the correct result. The possibility of observing the impact of the Trojan from the primary output can be improved by developing new test pattern generation algorithms. However, due to the many logical states in the circuit, functional testing cannot achieve 100% coverage and even has the problem of state explosion.

[0005] Formal verification detects hardware Trojans by checking whether the design satisfies a set of predefined security properties. Therefore, it cannot detect other unknown features introduced by Trojans.

[0006] Circuit analysis technology is a fast and reliable method. It identifies hardware Trojans by analyzing the circuit structure of the hardware Trojan and comparing it with the normal circuit. According to the different detection methods, circuit analysis can be divided into three categories: feature-based, testability-based, and structure learning-based.

[0007] Structural features are widely used in hardware Trojan detection methods, such as support vector machines (SVMs), neural networks, or random forests. In the past five years, feature-based hardware Trojan detection methods have shown high detection performance, reaching an accuracy of 90% or more. In order to ensure the accuracy of detection, the features used in these methods are obtained through heuristic methods. However, as the scale of the circuit increases, it is very time-consuming and requires constant updating to obtain hardware Trojan features through heuristic methods. At the same time, in the confrontation between hardware Trojan attacks and detection methods, the attack methods will also be updated and upgraded, making the current heuristic features invalid. Therefore, using heuristic feature-based methods to detect hardware Trojans is not a general solution. At the same time, for the work of hardware Trojan detection, since the number of hardware Trojan nodes is very small relative to the scale of normal circuits, it is an extremely unbalanced classification problem. The detection ability of traditional neural networks is very limited, and as the scale of the embedded netlist increases, the probability of detection will gradually decrease.

[0008] Existing literature 1: B Cakir, Malik S. "Hardware Trojan detection for gate-level ICs using signal correlation based clustering". Design, Automation & Test in Europe Conference & Exhibition. IEEE, 2015, proposed the first method to detect hardware Trojans based on structural features. This method successfully detected hardware Trojans by using structural features manually extracted from the benchmark netlist. However, this method requires a "golden model", that is, a design without Trojans embedded, for parameter comparison. However, the golden model is difficult to obtain in the entire design, which has great limitations. Moreover, due to the decrease in signal-to-noise ratio, the accuracy of this method decreases significantly with the increase of circuit scale and process variation.

[0009] Reference 2: Lu R, Shen H, Su Y, et al. "GramsDet: Hardware Trojan Detection Based on Recurrent Neural Network", 2019 IEEE 28th Asian Test Symposium. IEEE, 2019, proposed a method for hardware Trojan detection based on natural language processing, which first obtains embedded nodes by counting gate sequences, and then uses RNN to train the detection model for the circuit feature data set to be tested. The literature shows that: 82% of the true positive rate TPR, 96% of the true negative rate TNR and 46% of the F1 score were obtained. The training results of the model show that although this method has a high ability to identify normal nodes and correctly predict hardware Trojans, its ability to distinguish normal nodes from hardware Trojans is poor due to its low F1 score.

[0010] The problems arising from the above methods increase the risk of hardware Trojans being implanted into the product, resulting in the leakage of key information, changes in encryption functions, degradation of chip performance, or denial of chip services. Summary of the invention

[0011] The purpose of the present invention is to address the deficiencies of the above-mentioned prior art and propose a hardware Trojan detection method based on a generative adversarial graph neural network to improve the ability to distinguish normal nodes from hardware Trojans, reduce the risk of hardware Trojan implantation, and ensure the security of key information in the chip.

[0012] To achieve the above object, the technical solution of the present invention comprises the following steps:

[0013] (1) Select N netlists embedded with Trojans as sample sets and divide them into training sets and test sets in a ratio of 9:1, where N is greater than 16;

[0014] (2) Map the netlists of the training set and the test set respectively to obtain a directed acyclic graph of the test set and N-1 directed acyclic graphs of the training set. The structure of each directed acyclic graph is represented by G = (V, E), where G is the adjacency matrix of the entire netlist, V is all the gates in the netlist, and E is the connection relationship between the gates.

[0015] (3) Extract node features of all netlists in the training set and the test set respectively, and obtain the feature matrix B of the training set and the feature matrix B' of the test set. The extracted node features here include node intrinsic features and related graph features;

[0016] (4) Set the supernode SV and connect all nodes of the netlists in the training set to the supernode SV, so that multiple netlists are combined into one graph, that is, the adjacency matrix obtained in (2) is combined into a sparse matrix A;

[0017] (5) Constructing Generative Adversarial Graph Neural Network:

[0018] (5a) Establish a generator consisting of three fully connected layers cascaded in sequence and then connected in series with the SoftMax function.

[0019] (5b) Establish a discriminator consisting of three layers of graph convolutional neural networks cascaded in sequence;

[0020] (5c) Cascading the generator and the discriminator to form a generative adversarial graph neural network;

[0021] (6) Training Generative Adversarial Graph Neural Networks:

[0022] (6a) The sparse matrix A and feature matrix B in the training set are input into the generator of the generative adversarial graph neural network to generate features and connection relationships similar to hardware Trojan nodes, and then output to the discriminator of the generative adversarial graph neural network;

[0023] (6b) The discriminator generates the classification results of normal nodes and hardware Trojan nodes, and feeds the results back to the generator;

[0024] (6c) The generator calculates the loss value loss1 of the classification result, and the discriminator calculates the loss value loss2 of the classification result. These two loss values ​​loss1 and loss2 are used to update the matrix weights of each layer of the generator and the discriminator respectively through back propagation;

[0025] (6d) Repeat steps (6a) to (6c) until the loss value loss1 and the loss value loss2 converge to a balanced state, and obtain a trained generative adversarial graph neural network detection model;

[0026] (7) Input the test set netlist into the discriminator of the trained detection model to detect hardware Trojans and complete the identification of normal nodes and hardware Trojans.

[0027] Compared with the prior art, the present invention has the following advantages:

[0028] 1. Compared with the existing hardware Trojan detection method based on heuristic feature machine learning, the features used in the present invention are node intrinsic features and related graph features, which improves the ability to identify unknown hardware Trojan types; at the same time, since the features are fixed and there is no need to add new heuristic features, the present invention has stronger compatibility and simplicity, and it is easier to infer the original circuit structure information from the features.

[0029] 2. Since the present invention adopts an advanced generative adversarial graph neural network architecture for detection model training, it has stronger nonlinear expression ability and stronger generalization ability than traditional deep learning. At the same time, since adversarial learning is added in the process of training the generator to generate hardware Trojans, the discriminator can have a very strong hardware Trojan detection capability. The discriminator can distinguish hardware Trojans from normal nodes with a higher accuracy, thereby reducing the risk of hardware Trojan implantation and protecting the security of key chip information.

[0030] 3. In the present invention, since the discriminator feeds back the classification results of the generated normal nodes and hardware Trojan nodes to the generator, the generator is retrained and generates hardware Trojan nodes again for the discriminator to identify, thereby further improving the generator's ability to generate hardware Trojans. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 A flowchart for implementing the present invention;

[0032] Figure 2 A diagram of the architecture of a generative adversarial graph neural network constructed in the present invention;

[0033] Figure 3 It is the tsne dimension reduction graph obtained when the netlist S38584-T200 is tested by the present invention;

[0034] Figure 4 This is the tsne dimensionality reduction graph obtained when the netlist S38584-T300 is tested using the present invention. DETAILED DESCRIPTION

[0035] The embodiments and effects of the present invention are described in detail below with reference to the accompanying drawings.

[0036] Reference Figure 1 , the implementation steps of this example are as follows:

[0037] Step 1: Select a sample set that has been embedded with the Trojan netlist to obtain a training set and a test set.

[0038] The embedded Trojan netlist is a gate-level netlist, which is composed of a number of gate-level circuits, some of which are maliciously inserted by humans. When the circuit is working, the hardware Trojan will affect the normal circuit function or circuit power consumption.

[0039] 1.1) Select the sample set with the Trojan network table embedded:

[0040] Most of the netlists embedded with Trojans come from the Trust-Hub database. This example selects 17 netlists from the database as a sample set. These netlists embedded with hardware Trojans are:

[0041] RS232-T1000 combinational circuit, with 215 logic gates, including 13 hardware Trojan gates;

[0042] RS232-T1100 sequential circuit, with 216 logic gates, including 12 hardware Trojan gates;

[0043] RS232-T1200 sequential circuit, with 216 logic gates, including 14 hardware Trojan gates;

[0044] RS232-T1300 combinational circuit, with 213 logic gates, including 9 hardware Trojan gates;

[0045] RS232-T1400 sequential circuit, with 215 logic gates, including 13 hardware Trojan gates;

[0046] RS232-T1500 sequential circuit, with 216 logic gates, including 14 hardware Trojan gates;

[0047] RS232-T1600 sequential circuit, 214 logic gates in total, including 12 hardware Trojan gates;

[0048] S35932-T100 sequential circuit, with 5441 logic gates, including 15 hardware Trojan gates;

[0049] S35932-T200 combinational circuit, with 5334 logic gates, including 15 hardware Trojan gates;

[0050] S35932-T300 combinational circuit, with 5329 logic gates, including 44 hardware Trojan gates;

[0051] S38417-T100 combinational circuit, with 5341 logic gates, including 12 hardware Trojan gates;

[0052] S38417-T200 combinational circuit, with 5334 logic gates, including 15 hardware Trojan gates;

[0053] S38417-T300 sequential circuit, with 5329 logic gates, including 44 hardware Trojan gates;

[0054] S38584-T100 combinational circuit, with 6417 logic gates, including 9 hardware Trojan gates;

[0055] S38584-T200 sequential circuit, with 6473 logic gates, including 83 hardware Trojan gates;

[0056] S38584-T300 sequential circuit, with 7204 logic gates, including 730 hardware Trojan gates;

[0057] S15850-T100 sequential circuit, with 2182 logic gates, including 27 hardware Trojan gates;

[0058] 1.2) From the above 17 netlists, they are divided into training set and test set in a ratio of 9:1, that is, 16 netlists are selected as training sets for training graph neural networks, and the remaining 1 is used as a test set for discriminator verification.

[0059] Step 2: Map the netlists of the training set and the test set respectively.

[0060] 2.1) Use Python script to traverse the training set netlist files, perform text parsing and graph structure modeling on each netlist in the training set, and disconnect possible logical loops according to the gate type, gate name, and port connection relationship in the netlist to obtain a directed acyclic graph of each netlist: G = (V, E), where G is the adjacency matrix of the entire netlist, V is all the gates in the netlist, and E is the connection relationship between the gates;

[0061] 2.2) After traversing the training set netlist, the 16 adjacency matrices obtained are saved in the form of sparse matrices, thus completing the mapping process of the training set;

[0062] 2.3) Use the same method as mapping the training set to obtain the adjacency matrix of a test set and complete the mapping of the test set.

[0063] Step 3: Extract node features of all netlists in the training set and the test set respectively.

[0064] The node characteristics of the netlist mainly refer to the properties of the logic gates in the netlist and the distances between the logic gates. In this embodiment, they include: the number of cell types, degree, the minimum distance PI from the node to the main input, the minimum distance PO from the node to the main output, the centrality of the node, and the harmonicity of the node. Among them:

[0065] The number of cell types is the number of logic gate types in the netlist. Since gates of the same logic type with different fan-in and fan-out sizes will be classified into one category, the gate types will be simplified to basic gate types to eliminate the interference of fan-in and fan-out sizes and other reset signals, effectively reducing the dimension of the one-hot code. In this example, 18 gate types are summarized and represented by 18-dimensional one-hot codes.

[0066] Degree is the number of incoming and outgoing neighbors;

[0067] The minimum distance from a node to the main input refers to the minimum distance from the node to the forward register or input port, and the minimum distance from a node to the main output refers to the minimum distance from the node to the backward register or output port;

[0068] Centrality BC is defined as the ratio of the number of nodes v passed through in the shortest paths between all nodes on the graph to the number of shortest paths between all nodes. Its mathematical formula is as follows:

[0069] Where σ(x,y) is the total number of shortest paths between all nodes, and σ(x,y)|v is the number of nodes v passed through in the shortest paths between all nodes;

[0070] The harmonic betweenness HC is defined as the sum of the reciprocals of the shortest path distances from all other nodes to v, and its mathematical formula is as follows:

[0071] Where x is a node other than v, and d(x,v) is the shortest path length from x to v.

[0072] The specific implementation of this step is as follows:

[0073] 3.1) Use Python scripts to search, classify and count the nodes in the training set and test set netlists respectively through regular expressions. Use regular expressions to match each row of logic gate type, fan-in connection, fan-out connection, port, and port name. Based on this information, infer the connection relationship of the logic gate and obtain the number of fan-in and fan-out.

[0074] 3.2) Search the shortest path from a node to the remaining nodes through the Dijkstra algorithm, and calculate the minimum distance PI from the node to the main input, the minimum distance PO from the node to the main output, the central betweenness BC, and the harmonic betweenness HC according to the formula;

[0075] 3.3) After the extraction is completed, each node feature information will correspond to a 24-dimensional feature vector. All feature vectors are then concatenated into a feature matrix, which is normalized to eliminate the adverse effects caused by singular sample data.

[0076] In order to improve the calculation speed of central betweenness and reconciliation betweenness and reduce the complexity of the algorithm, this example sets a search depth threshold T=10, and stops searching when a level 10 node is found.

[0077] Step 4: Preprocess the data.

[0078] 4.1) Create a supernode SV;

[0079] In order to meet the model training requirements of GCN, the entire graph and training nodes need to be input. Therefore, a supernode SV is created in this example, and the corresponding node feature matrix of the newly added supernode is all 0;

[0080] 4.2) After collecting the connection relationships and features of the netlists in the training set, point all the nodes obtained in step 2 to the connection edges of the SV, so that all netlists are synthesized into a graph, that is, the adjacency matrices corresponding to all training sets are spliced ​​into a new matrix C:

[0081] 4.3) Add a row of vectors containing all 1s to the new matrix C to form a new adjacency matrix D, completing the preprocessing of the input generator data.

[0082] Step 5: Build a generative adversarial graph neural network including a generator and a discriminator.

[0083] 5.1) The generator consists of three fully connected layers and a SoftMax function. The three fully connected layers are cascaded in sequence, and the last fully connected layer is connected to the SoftMax function;

[0084] 5.2) Set the dimension of the first fully connected layer to (1, 200), the dimension of the second fully connected layer to (200, 400), the dimension of the third fully connected layer to (400, 200), and the output matrix dimension to (1, Nd), N d is the number of hardware Trojans in the training set;

[0085] 5.3) Through the SoftMax function, N d The dimensional vector is normalized and the output result is (N g , N d )-dimensional adjacency matrix E, which represents the connection relationship between the generated node and the existing hardware Trojan;

[0086] 5.4) Multiply the adjacency matrix E with the feature matrix of the original node to obtain the feature matrix F of the generated hardware Trojan, and use the feature matrix F as the input of the discriminator;

[0087] 5.5) The discriminator is a three-layer graph convolutional neural network GCN, and each layer of the graph convolutional neural network is cascaded in sequence;

[0088] 5.6) Set the dimension of the first layer of graph convolutional neural network to (Ng, 256), the dimension of the second layer of graph convolutional neural network to (256, 2), and the dimension of the third layer of graph convolutional neural network to (2, 2), where N g is the number of generated nodes;

[0089] 5.7) Cascade the generator and discriminator to form a generative adversarial graph neural network.

[0090] The GCN combines graph structure data in non-Euclidean space with neural networks to perform node transfer, aggregation and update calculations on the graph structure data. It aggregates the information of neighboring nodes for each node through the adjacency matrix of structural information, the feature matrix of node attributes and the weight matrix of training information, thereby maximizing the use of the structural characteristics of the graph to effectively and fully express the relationship information between different nodes.

[0091] The discriminator in the embodiment of the present invention can be implemented using a variety of graph neural networks, including but not limited to GCN, GraphSAGE, and GAT. The GCN used is implemented by the pytorch library, version 1.11; the information aggregation formula of a single-layer GCN is as follows:

[0092]

[0093] In the formula is the normalization process of the adjacency matrix of the initial graph, is the degree matrix of the graph; H (l) The figure is in l The characteristic matrix of the round time, W (l) The figure is in l The round-time weight parameter matrix; σ is the activation function of the GCN layer, preferably the ReLU function.

[0094] Step 6: Train the generative adversarial graph neural network.

[0095] 6.1) According to the generated nodes and the original node results classified by the discriminator, calculate the loss value loss1 of the generator:

[0096] loss1=L f +L l

[0097] In the formula is the cross entropy of the classification results of the generated node and the original node, where Y(i) is the probability of the i-th generated node, P(i) is the probability of the i-th original node, and l is the node set of the generated node and the original node;

[0098] To generate the average value of the Euclidean distance between the hardware Trojan features and the real hardware Trojan features, N g N is the number of generated hardware Trojans. d is the number of real hardware Trojans, H1(a) k The k-dimensional feature matrix of the a-th generated hardware Trojan output by the first layer of graph convolutional neural network, H1(b) k is the k-dimensional feature matrix of the b-th real hardware Trojan output by the first layer of graph convolutional neural network;

[0099] 6.2) According to the normal nodes and hardware Trojans classified by the discriminator, calculate the loss value loss2 of the discriminator:

[0100] loss2=L p +L g

[0101] In the formula is the cross entropy of the classification results of normal nodes and hardware Trojans, Y(i) is the probability of the mth hardware Trojan node, P(i) is the probability of the mth normal node, and n is the node set of hardware Trojan nodes and normal nodes;

[0102] is the average value of the Euclidean distance between the hardware Trojan features and the normal node features, N h is the number of hardware Trojans, N n is the number of normal nodes, H1(c) k H1(d) is the k-dimensional feature matrix of the c-th hardware Trojan output by the first-layer graph convolutional neural network. k It is the k-dimensional feature matrix of the d-th normal node output by the first layer of graph convolutional neural network;

[0103] 6.3) Use two loss values ​​loss1 and loss2 to back-propagate the generator and discriminator respectively to update the weight parameters of each layer, that is, use the loss value loss1 to back-propagate the generator to update the weight parameters of each layer in the generator, and use the loss value loss2 to back-propagate the discriminator to update the weight parameters of each layer in the discriminator;

[0104] 6.4) Repeat step 6.3) to repeatedly update the generator so that the features of the generated nodes are close to the weight parameter matrices of each layer of the features of the real hardware Trojan, and repeatedly update the weight parameter matrices of each layer of the discriminator so that it can correctly classify the hardware Trojan features and normal node features, until the discriminator's identification ability is maximized and the gap between the node distribution generated by the generator and the original node distribution is minimized, that is: When , we get a trained generative adversarial graph neural network, where D is the discriminator and G is the generator. x~Pdata(x) is the data distribution of the original nodes in the training set, z~pz(z) Data distribution for generating hardware Trojans for the generator.

[0105] Step 7: Detect hardware Trojans.

[0106] The feature matrix corresponding to the test set is input into the trained discriminator for detection, and the detection results of the proportion of normal nodes and hardware Trojans are output.

[0107] The effect of the present invention can be further illustrated by the following simulation experiment:

[0108] 1. Simulation conditions

[0109] The model algorithm of the experiment was built with pytorch, and data evaluation was implemented using Scikit-learn. The hardware used for the experiment was NVIDIA GeForce RTX 2080ti, Intel(R) Xeon(R) W-2123CPU@3.60Ghz and 16G running memory. The experimental method was leave-one-out cross-validation.

[0110] For the evaluation of the test results of the experiment, the present invention selects the following three contents as indicators of the experimental results, which are:

[0111] Recall is the ratio of identified hardware Trojans to all hardware Trojans, TP is the number of normal nodes correctly identified, and FN is the number of nodes incorrectly identified as Trojans;

[0112] Accuracy is the ratio of correctly identified hardware Trojans to detected hardware Trojans, and FP is the number of nodes incorrectly identified as normal nodes;

[0113] Fraction Used to comprehensively evaluate the classification effect of the model.

[0114] 2. Simulation Content

[0115] Simulation 1, the netlist S38584-T200 is tested by the present invention, and the tsne algorithm is used to reduce the dimension of the output of the first layer GCN of the discriminator, and the following is obtained: Figure 3 The dimensionality reduction diagram shown in the figure shows that area B is the distribution range of normal nodes, and area A is the distribution range of hardware Trojan nodes. Figure 3 It can be seen that normal nodes and hardware Trojan nodes are effectively separated and clustered together with the same type.

[0116] Simulation 2, the present invention is used to detect the netlist S38584-T300, and the tsne algorithm is used to reduce the dimension of the output of the first layer GCN of the discriminator, and the following is obtained: Figure 4 The dimensionality reduction diagram shown in the figure shows that area B is the distribution range of normal nodes, and area A is the distribution range of hardware Trojan nodes. Figure 4 It can be seen that normal nodes and hardware Trojan nodes are effectively separated and clustered together with the same type.

[0117] III. Comparative analysis of indicators between the present invention and existing detection methods

[0118] The present invention trains different training sets and test sets each time, and conducts 17 trainings in total to obtain 17 discriminators with different weight parameters. The recall rate R, precision rate P, and F1 score of each detection are calculated according to the above formula, and then the 17 results are summed to obtain the average values ​​of each item, and compared with the indicators of the existing XGBOOST method and RF method. The results are shown in Table 1:

[0119] Table 1 Comparison of the results of the present invention, XGBOOST method and RF method

[0120] method R P F1 XGBOOST 0.667 0.960 0.790 RF 0.577 0.986 0.618 The present invention 0.968 0.954 0.957

[0121] As can be seen from Table 1, the average recall rate R of the present invention reaches 96.8%, and the average F1 score reaches 95.7%, both of which are higher than the recall rate R and F1 score of the XGBOOST method and the RF method. Although the average accuracy P is slightly lower than the accuracy P of the XGBOOST method and the RF method, the hardware Trojan nodes can still be identified with a higher accuracy.

[0122] The above results show that the present invention can accurately detect hardware Trojans from the netlist and effectively protect the security of key information in the chip.

Claims

1. A hardware Trojan detection method based on generative adversarial graph neural network, characterized in that: It includes the following steps: (1) Select N netlists embedded with Trojans as the sample set, and divide them into a training set and a test set according to a ratio of 9:1, where N is greater than 16; (2) Map the netlists of the training set and the test set respectively to obtain a directed acyclic graph of the test set and N - 1 directed acyclic graphs of the training set. The structure of each directed acyclic graph is represented as G=(V, E), where G is the adjacency matrix of the entire netlist, V is all the gates in the netlist, and E is the connection relationship between the gates; (3) Extract the node features of all the netlists in the training set and the test set respectively to obtain the feature matrix B of the training set and the feature matrix B' of the test set; (4) Set the super node SV, and connect all the nodes of the netlists in the training set to the super node SV, so that multiple netlists are combined into a graph, that is, combine the adjacency matrices obtained in (2) into a sparse matrix A; (5) Construct a generative adversarial graph neural network: (5a) Establish a generator composed of three cascaded fully connected layers followed by a SoftMax function in series; (5b) Establish a discriminator composed of three cascaded graph convolutional neural networks; (5c) Cascade the generator and the discriminator to form a generative adversarial graph neural network; (6) Train the generative adversarial graph neural network: (6a) Input the sparse matrix A and the feature matrix B in the training set into the generator of the generative adversarial graph neural network to generate the features and connection relationships of nodes similar to hardware Trojans, and output them to the discriminator of the generative adversarial graph neural network; (6b) The discriminator generates the classification results of normal nodes and hardware Trojan nodes, and feeds back the results to the generator; (6c) The generator calculates the loss value loss1 of the classification results, and the discriminator calculates the loss value loss2 of the classification results. These two loss values loss1 and loss2 update the matrix weights of each layer of the generator and the discriminator respectively through backpropagation; (6d) Loop through steps (6a) to (6c) until the loss values loss1 and loss2 converge in balance to obtain a trained generative adversarial graph neural network detection model; (7) Input the test set netlist into the discriminator of the trained detection model for hardware Trojan detection to complete the identification of normal nodes and hardware Trojans.

2. The method according to claim 1, characterized in that: The node features extracted in step (3) include: gate type, Degree which is the number of in - and out - neighbors, the minimum distance from the node to the primary input, the minimum distance from the node to the primary output, the central betweenness of the node, and the harmonic betweenness of the node.

3. The method according to claim 1, characterized in that In step (3), when extracting the node features of all the netlists in the training set and the test set, it is to use regular expressions to retrieve, classify, and count the nodes in the training set and test set netlists in sequence first, and then perform normalization processing to obtain their respective feature matrices.

4. The method according to claim 1, characterized in that The three fully connected layers in step (5a) have the same structure but different parameters. That is, the parameter dimension of the weight matrix of the first layer is (1, X), the parameter dimension of the weight matrix of the second layer is (X, Y), and the parameter dimension of the weight matrix of the third layer is (Y, Nd), where 0 < X < Y < Nd < Ng, Nd is the number of hardware Trojans in the training set, and Ng is the number of hardware Trojans generated by the generator.

5. The method according to claim 1, characterized in that The SoftMax function in step (5a) is used to normalize the (1, Nd) dimensional matrix output by the third fully connected layer, and repeated Ng times to obtain a generator adjacency matrix of dimension (Ng, Nd), where Nd is the number of hardware Trojans in the training set and Ng is the number of hardware Trojans generated by the generator.

6. The method according to claim 1, characterized in that The three-layer graph convolutional neural network in step (5b) has the same structure, but different weight matrix parameter dimension parameters, that is, the first-layer weight matrix parameter dimension is (V, W), the second-layer weight matrix parameter dimension is (W, 2), and the third-layer weight matrix parameter dimension is (2, 2), where V is the dimension of node features, W is the number of columns of the first-layer weight matrix, and W>V.

7. The method according to claim 1, characterized in that In step (6c), the generator calculates the loss value loss1 of the classification result, and the formula is as follows: loss1=L l +L f in: is the cross entropy of the classification results of the generated node and the original node, where Y(i) is the probability of the i-th generated node, P(i) is the probability of the i-th original node, and l is the node set of the generated node and the original node; is the average value of the Euclidean distance between the generated hardware Trojan features and the real hardware Trojan features, where N g N is the number of generated hardware Trojans. d is the number of real hardware Trojans, H1(a) k The k-dimensional feature matrix of the a-th generated hardware Trojan output by the first layer of graph convolutional neural network, H1(b) k It is the k-dimensional feature matrix of the b-th real hardware Trojan output by the first layer of graph convolutional neural network.

8. The method according to claim 1, characterized in that In step (6c), the discriminator calculates the loss value loss2 of the classification result, and the formula is as follows: loss2=L p +L g in, is the cross entropy of the classification results of normal nodes and hardware Trojans, where Y(i) is the probability of the mth hardware Trojan node, P(i) is the probability of the mth normal node, and n is the node set of hardware Trojan nodes and normal nodes; is the average value of the Euclidean distance between the hardware Trojan features and the normal node features, where N h is the number of hardware Trojans, N n is the number of normal nodes, H1(c) k H1(d) is the k-dimensional feature matrix of the c-th hardware Trojan output by the first-layer graph convolutional neural network. k It is the k-dimensional feature matrix of the d-th normal node output by the first layer of graph convolutional neural network.

Citation Information

Patent Citations

  • Large-scale hardware Trojan horse library generation system and method based on generative adversarial network

    CN110941829A

  • Hardware Trojan horse detection method based on machine learning and hybrid sampling

    CN114611103A