Attention mechanism fused graph neural network hardware Trojan horse detection method and system
Through the graph neural network hardware Trojan detection method with a fusion attention mechanism, the inherent, local and global features in the netlist circuit code are extracted, and the problem of low accuracy and efficiency of hardware Trojan detection in the existing technology is solved, and efficient detection of large-scale integrated circuits is achieved.
Patent Information
- Application Number
- CN202510092455.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-21
AI Technical Summary
The existing hardware Trojan detection methods based on graph neural networks have problems such as overcompression, oversmoothing and difficulty in scaling for large-scale designs, resulting in low detection accuracy and efficiency.
The graph neural network hardware Trojan detection method adopts the fusion attention mechanism. By mapping the netlist circuit code into a directed graph, graph embedding, graph segmentation and graph sampling, the inherent features, local features and global features of the node are extracted, and feature fusion is performed, and finally detection is performed through the classification model.
It significantly improves the accuracy and efficiency of hardware Trojan detection, can effectively detect Payload diffusion type Trojans, and expands to large-scale integrated circuit designs.
Smart Images

Figure CN120012084A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer and electronic technology, and specifically relates to a method and system for detecting hardware Trojans in a graph neural network integrating an attention mechanism. Background Art
[0002] The scale and complexity of modern system-on-chip (SoC) designs make it increasingly challenging and expensive for chip manufacturers to design, manufacture, and test every component in-house. Time-to-market pressures and resource constraints have driven SoC designers to turn to third-party electronic design automation (EDA) tools and IP cores, as well as global outsourcing of design, manufacturing, and testing services. However, reliance on untrusted IP and EDA tools significantly increases the risk of malicious entities inserting malicious circuits, i.e., hardware Trojans, in the integrated circuit supply chain. Hardware Trojans can perform a variety of attack purposes, such as leaking information, changing functionality, degrading performance, or denying services. The consequences of undetected hardware Trojans (HTs) in chips are very deadly, especially for chips in critical infrastructure, military systems, medical devices, etc. Since hardware Trojan attacks are carefully designed and difficult to trigger under normal working conditions, Trojans are difficult to detect. Hardware Trojan detection is a difficult point in current research. At a higher level of abstraction, the flexibility of IP cores makes it easier for attackers to design and implant hardware Trojans. In addition, the process of implanting HTs at the manufacturing stage is much more complicated than that at the design stage. Therefore, pre-silicon HT detection is an effective countermeasure to address system-level chip security issues. Identifying and removing HT early in the design phase can effectively reduce the cost and risk of removing HT later.
[0003] The gate-level netlist describes the circuit from the perspective of circuit elements and their connections. It can capture subtle changes and anomalies that may not be detected at the RTL level, which helps to detect hardware Trojans more effectively. RTL circuits can also be synthesized into gate-level netlists, which facilitates the use of various detection and verification tools. In addition, detection at the gate-level netlist stage helps to identify security risks introduced in the supply chain and ensure the integrity of the entire system. Therefore, detecting hardware Trojans at the gate level is a hot topic and difficulty in current research.
[0004] At present, there are many research works on gate-level detection of hardware Trojans. Among them, the application of graph neural network (GNN) to hardware Trojan detection has achieved good classification performance, but the graph neural network model has problems of over-compression and over-smoothing, which leads to the fact that Payload diffusion type Trojans cannot be detected well. In addition, these models require more time and resource overhead for large-scale circuits. Most HT detection methods can only detect certain types of Trojan benchmarks in the existing Trusthub benchmark, and the detection range is limited. In addition, some HT detection methods limit the detection range to specific parts of HT based on the characteristics of Trojan composition. At the same time, GNN cannot extract global features, resulting in low accuracy and efficiency of existing detection methods.
[0005] In summary, there is still room for improvement in the existing hardware Trojan detection technology, and the existing methods are not sufficient to meet the needs of large-scale circuit hardware Trojan detection. Summary of the invention
[0006] In order to solve the problems of over-compression, over-smoothing and inability to be expanded to large-scale designs in existing GNN-based hardware Trojan detection methods and systems, the present invention provides a graph neural network hardware Trojan detection method and system that integrates an attention mechanism, which greatly improves the accuracy and efficiency of Trojan detection; it can be applied to actual hardware Trojan detection of large-scale integrated circuits.
[0007] To achieve the above object, the present invention provides the following solutions:
[0008] A method for detecting hardware Trojans using a graph neural network integrating an attention mechanism, the method comprising:
[0009] S1: Map the netlist circuit code carrying the hardware Trojan into a directed graph;
[0010] S2: Perform graph embedding, graph segmentation and graph sampling on the directed graph to obtain a training set;
[0011] S3: Extract the intrinsic features of the nodes in the training set through the encoder;
[0012] S4: Extract local features of nodes in the training set through graph neural network;
[0013] S5: Extract global features of nodes in the training set through the attention mechanism model;
[0014] S6: Intrinsic features, local features and global features are fused and the HT detection results are obtained through the classification model.
[0015] Preferably, in S1, mapping the netlist circuit code carrying the hardware Trojan into a directed graph includes:
[0016] The open source hardware design toolkit Pyverilog is used to parse and analyze the lexical and grammatical information of the gate-level netlist and generate the abstract syntax tree AST corresponding to the gate-level netlist;
[0017] The circuit gate unit objects in AST are regarded as the vertices of the graph, the connections between the gate units are regarded as the edges between the vertices of the graph, and the netlist design is modeled as the corresponding directed graph.
[0018] Preferably, in S2, the graph embedding, graph segmentation and graph sampling of the directed graph include:
[0019] Generate an adjacency matrix from a directed graph;
[0020] According to the adjacency matrix, the basic type of the gate unit is encoded using a one-hot vector to obtain the embedding matrix of the gate node;
[0021] A graph partitioning algorithm based on breadth-first search is used to divide the directed graph into subgraphs;
[0022] The graph sampling algorithm is used to sample the subgraph set to form the final training set.
[0023] Preferably, in S3, extracting the inherent features of the nodes in the training set by the encoder includes:
[0024] The graph embedding matrix is input into the autoencoder, which is mapped to a preset low-dimensional representation through the autoencoder to extract the inherent data features of the node;
[0025] Restore low-dimensional features through the decoder;
[0026] The mean squared error loss between the input of the autoencoder and the output of the decoder is used as part of the loss function of the entire model.
[0027] Preferably, in S4, extracting local features of nodes in the training set by using a graph neural network includes:
[0028] Process graph data through the forward graph convolutional network GCN layer;
[0029] Process the output of the forward graph convolutional network GCN layer through the reverse graph convolutional network GCN layer;
[0030] The outputs of the same bidirectional graph convolutional network GCN layer are first fused and then passed to the next bidirectional graph convolutional network GCN layer as input to form a bidirectional GCN convergence model;
[0031] The bidirectional GCN aggregation model is used to extract local structural features of graph nodes.
[0032] Preferably, in S5, extracting the global features of the nodes in the training set by the attention mechanism model includes:
[0033] The position encoding of the graph structure is obtained by an algorithm for obtaining position encoding of a directed graph;
[0034] A self-attention mechanism model is used to process graph embedding and position encoding to extract global features of graph nodes;
[0035] The position coding of the graph structure is obtained by using an algorithm for obtaining position coding of a directed graph, including:
[0036] Find the position code PE corresponding to the directed graph;
[0037] Find the positional encoding PE' of the directed graph transpose;
[0038] Connect PE and PE' as the final positional encoding BPE;
[0039] The global features of graph nodes are extracted by processing graph embedding and position encoding through a self-attention mechanism model, including:
[0040] The dependencies between distant nodes in the graph are captured through the self-attention mechanism. At the same time, the constraints of the graph structure are introduced into the self-attention mechanism, and the attention weights are limited to be allocated only to connected neighbor nodes.
[0041] Preferably, in S6, the inherent features, local features and global features are fused, and the HT detection results are obtained through the classification model, including:
[0042] Extract the inherent features of the data A through the encoder h , local structural features L extracted by graph neural network h And the global structural feature G extracted by the self-attention mechanism model h Perform feature fusion to obtain the final feature representation of the gate unit;
[0043] Input the fused features into the final classification model for classification;
[0044] Among them, the fusion is completed by splicing operations between tensors, and the formula for feature fusion is:
[0045] h G =Concat(G h ,L h ,A h )
[0046] Among them, h G It is the final feature representation of the graph node after feature fusion;
[0047] The processing process of the classification module is:
[0048]
[0049] in, is the final prediction output.
[0050] The present invention also provides a graph neural network hardware Trojan detection system integrating an attention mechanism, the system is used to implement any one of the methods described, the system comprising: a mapping module, a preprocessing module, an inherent feature extraction module, a local feature extraction module, a global feature extraction module and a classification module;
[0051] The mapping module is used to map the netlist circuit code carrying the hardware Trojan into a directed graph;
[0052] The preprocessing module is used to perform graph embedding, graph segmentation and graph sampling on the directed graph to obtain a training set;
[0053] The inherent feature extraction module is used to extract the inherent features of the nodes in the training set through the encoder;
[0054] The local feature extraction module is used to extract local features of nodes in the training set through a graph neural network;
[0055] The global feature extraction module is used to extract the global features of the nodes in the training set through the attention mechanism model;
[0056] The classification module is used to fuse the inherent features, local features and global features, and obtain the HT detection results through the classification model.
[0057] Compared with the prior art, the present invention has the following beneficial effects:
[0058] The present invention discloses a method and system for detecting hardware Trojans using a graph neural network with an integrated attention mechanism, including: S1. Mapping a netlist circuit code carrying a hardware Trojan to a directed graph; S2. Performing graph embedding, graph segmentation and graph sampling on the directed graph; S3. Extracting node intrinsic features through an encoder; S4. Extracting node local features through a graph neural network; S5. Extracting node global features through an attention mechanism model; S6. Fusing the data intrinsic features extracted by the self-encoder, the local structural features extracted by a bidirectional GCN convergence model and the global structural features extracted by the self-attention mechanism, and obtaining HT detection results through a classification model. The method and system for detecting hardware Trojans using a graph neural network with an integrated attention mechanism disclosed by the present invention can use an encoder to extract node data intrinsic features, use a graph neural network to extract local spatial structural features of graph nodes, and use an attention mechanism to extract global spatial structural features of graph nodes, thereby greatly improving the accuracy and efficiency of Trojan detection; hardware Trojan detection can be performed using a method without a golden reference model, which expands the detection range or type compared to existing methods, and can be applied to actual hardware Trojan detection of large-scale integrated circuits. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solution of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0060] Figure 1 A schematic diagram of the implementation process of a method for detecting hardware Trojans using a graph neural network that integrates an attention mechanism according to an embodiment of the present invention;
[0061] Figure 2 A schematic diagram of an implementation process of graph embedding and graph segmentation of a directed graph according to an embodiment of the present invention;
[0062] Figure 3 A schematic diagram of extracting intrinsic features of nodes through an encoder according to an embodiment of the present invention;
[0063] Figure 4 It is a schematic diagram of a specific implementation process of extracting local features of nodes through a graph neural network according to an embodiment of the present invention;
[0064] Figure 5 The present invention is a schematic diagram of a specific implementation process of extracting global features of nodes through a self-attention mechanism model. DETAILED DESCRIPTION
[0065] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0066] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0067] Embodiment 1
[0068] like Figure 1 As shown, the present invention provides a method for detecting hardware Trojans in a graph neural network integrating an attention mechanism, which mainly includes:
[0069] Mapping the netlist circuit code carrying the hardware Trojan into a directed graph;
[0070] Perform graph embedding, graph segmentation, and graph sampling on directed graphs;
[0071] Extract node intrinsic features through encoder;
[0072] Extract local features of nodes through graph neural network;
[0073] Extract the global features of nodes through the self-attention mechanism model;
[0074] The inherent features of the data, the local structural features and the global structural features are fused and classified to obtain the detection results.
[0075] More specifically, the following steps are included:
[0076] S1 maps the netlist circuit code carrying the hardware Trojan into a directed graph. The specific implementation method is to parse and analyze the lexical and grammatical information of the gate-level netlist through the open source hardware design toolkit Pyverilog to generate the abstract syntax tree AST corresponding to the gate-level netlist. Then, the circuit gate unit objects in the AST are regarded as the vertices of the graph, and the connections between the gate units are regarded as the edges between the vertices of the graph, so that the netlist design can be modeled as a corresponding directed graph.
[0077] S2 performs graph embedding, graph segmentation and graph sampling on directed graphs, such as Figure 2 As shown, the specific implementation steps are as follows:
[0078] S201 generates an adjacency matrix according to the directed graph. According to the generated directed graph, an adjacency matrix A of size N*N can be obtained, where N is the number of vertices in the directed graph. The adjacency matrix A represents the structural information of the graph.
[0079] S202 maps gates with the same logical functions to their basic types. Mapping gates with the same logical functions to their basic types can reduce the encoding feature dimension of the nodes and reduce the computational overhead of the subsequent hardware Trojan detection model.
[0080] S203 uses one-hot encoding to initialize the node feature vector, and can obtain the embedding matrix of the gate node, that is, the graph embedding matrix, which is N*K in size, where K is the number of basic node types. Each row in the embedding matrix represents the initial embedding representation of each node in the graph.
[0081] S204 uses a graph partitioning algorithm to divide the directed graph into subgraphs. Specifically, a graph partitioning algorithm based on breadth-first search is used to divide the directed graph into subgraphs, that is, all nodes of the entire graph are traversed by searching layer by layer, and the subgraph division method is determined according to the connection relationship. Graph partitioning can convert a large graph into a small graph, which is easy to be processed by the model. The specific implementation steps are to loop through each unvisited node: each time an unvisited node is selected from the unvisited nodes as the starting point, and a breadth-first search is performed; a queue is created and the current starting point node is put into the queue, and it is marked as visited; the nodes in the current subgraph are recorded and initialized to an empty set; a node is taken out of the queue and added to the queue; all neighbor nodes of the node are visited, and if the neighbor node has not been visited, it is added to the queue, marked as visited and removed from the unvisited; when the queue is empty, it means that all nodes of the current subgraph have been traversed and added to the subgraph set as a complete subgraph; the above process is repeated until the unvisited set is empty, indicating that all nodes have been divided into different subgraphs.
[0082] S205 uses a graph sampling algorithm to sample the subgraph set to form the final training set. The specific implementation method is to extract some subgraphs from the subgraph set as the final training set through a sampling algorithm without replacement to further reduce the cost of training. The specific implementation steps are: if the number of subgraphs corresponding to the benchmark n<=10, then all subgraphs corresponding to the benchmark are added to the training set; if n>10, select subgraphs are added to the training set; all subgraphs containing Trojans are added to the training set.
[0083] S3 extracts the intrinsic features of nodes through the encoder, embeds the graph into the autoencoder, maps it to a low-dimensional representation through the encoder, extracts the intrinsic features of the node data, and then restores the low-dimensional features through the decoder. The mean square error loss between the input of the autoencoder and the output of the decoder is used as part of the loss function of the entire model.
[0084] like Figure 3 As shown, the specific process is as follows:
[0085] S301 maps the graph embedding matrix to a low-dimensional representation to implement the encoding function. This step is used to extract node intrinsic features and reduce dimensionality. At the same time, the output of each layer in the encoder is passed to the same layer of the graph neural network as input for multi-dimensional feature fusion, which can alleviate the over-smoothing problem of the graph neural network to a certain extent. The number of layers of the encoder is set to the same as the number of layers of the graph neural network to facilitate feature transfer and fusion. At the same time, the encoder can be pre-trained first. The process of feature transfer and fusion between the encoder and the same layer of the graph neural network is as follows:
[0086] H′ (l) =H (l)+αZ (l+1)
[0087] Among them, H (l) is the input of the lth layer of the graph neural network, Z (l+1) is the output of the encoder layer l, and α is a configurable adjustment factor. H′ (l) It is the new input of the graph neural network layer l after feature transfer and fusion.
[0088] S302 maps the low-dimensional representation back to the input space to implement the decoder function, where the decoder and the encoder in the previous step are both composed of a three-layer fully connected network. The number of neurons in the three layers of the encoder are 128, 128, and 20 respectively. The encoding process is shown in the following formula:
[0089] A h =σ(W3σ(W2σ(W1X+b1)+b2)+b3)
[0090] The input X is the graph embedding matrix, W1, W2, W3 are the weight matrices of the encoder, b1, b2, b3 are the bias vectors, and σ is the activation function Relu. h is the extracted low-dimensional intermediate representation, that is, the inherent features of the node.
[0091] The structure of the decoder is a mirror image of the encoder. The decoding process is as follows:
[0092]
[0093] The input A h is the node intrinsic feature extracted by the encoder, W1 ′ 、W2 ′ 、W3 ′ is the weight matrix of the decoder, b1 ′ 、b2 ′ 、b3 ′ is the bias vector, and σ is the activation function Relu. is the output of the encoder, i.e., the reconstructed output.
[0094] S303 calculates the loss through the mean square error loss function and performs back propagation to update the model parameters, where the mean square error loss function MSE calculation formula is as follows:
[0095]
[0096] Where N is the total number of gate nodes, is the predicted output of the gate unit feature through the hardware Trojan gate classification model, x i is the raw input to the gate.
[0097] S4 extracts local features of nodes through graph neural networks, such as Figure 4 As shown, the specific process is as follows:
[0098] S401 processes graph data through a forward graph convolutional network (GCN) layer. The working principle of GCN is shown in the following formula:
[0099]
[0100] Where W (l) are the trainable weights used in the GCN layer. A is the adjacency matrix of G, which is used to aggregate the eigenvectors of adjacent nodes. I is the identity matrix. Is used for normalization The diagonal matrix of σ(.) is the activation function, and the present invention uses the ReLU activation function.
[0101] S402 processes the output of the forward GCN layer through a reverse GCN layer, with the aim of forming a bidirectional GCN layer with the forward graph convolutional network (GCN) layer of the previous step.
[0102] S403 The outputs of the same bidirectional GCN layer are first fused, and then passed to the next bidirectional GCN layer as input to form a bidirectional GCN convergence model. Specifically, the existing bidirectional GCN model can extract features in both the fan-in and fan-out directions of nodes in a directed graph, but the GCN layer in each direction is independent and can only extract features of unidirectional fan-in or fan-out, and cannot converge information on sibling nodes. By constructing a bidirectional GCN convergence model in the present invention, that is, splicing the outputs of each layer of the forward GCN and reverse GCN, and then passing them to the forward GCN and reverse GCN of the next layer as input, the node information convergence area of the target node can be expanded and more comprehensive local structural features of the graph nodes can be extracted.
[0103] The calculation process of forward GCN is as follows:
[0104]
[0105] Among them, H (l) is the input feature of the lth layer, is the weight matrix of the forward GCN layer, A is the adjacency matrix, and σ is the activation function Relu. is the output of the lth layer of the forward GCN.
[0106] The calculation process of reverse GCN is as follows:
[0107]
[0108] Among them, H (l) is the input feature of the lth layer, is the weight matrix of the reverse GCN layer, A Tis the transpose of the adjacency matrix, and σ is the activation function Relu. is the output of the lth layer of the reverse GCN.
[0109] The process of bidirectional GCN convergence is as follows:
[0110]
[0111] Concat represents the concatenation operation. (l+1) It is the output after the aggregation of the lth layer of the bidirectional GCN.
[0112] The output H after aggregation (l+1) As the input of the next layer, the above process is repeated to form a multi-layer bidirectional GCN convergence model. The output L of the third layer of the bidirectional GCN h It is the local structural feature of the node.
[0113] S5 extracts the global features of nodes through the self-attention mechanism model, such as Figure 5 As shown, the specific process is as follows:
[0114] S501 obtains the position coding of the graph structure through an algorithm for position coding of directed graphs. The specific implementation method is to use the eigenvector of the Laplacian matrix corresponding to the graph as the position coding to better capture the global structural information of the graph. However, because the Laplacian eigenvector is for undirected graphs, it is not applicable to directed graphs. Therefore, the present invention proposes an algorithm for position coding of directed graphs. First, the position coding PE corresponding to the directed graph is calculated, and then the position coding PE′ of the transposed directed graph is calculated, and finally PE and PE′ are connected as the final position coding BPE. The specific solution process of the position coding of the directed graph is as follows:
[0115] 1) First, the degree matrix D is calculated through the adjacency matrix A of the graph. The out-degree matrix D is a diagonal matrix, where the diagonal elements D[i][i] represent the out-degree of node i (that is, the sum of the weights of all edges starting from node i). The calculation formula is:
[0116]
[0117] 2) Construct the Laplacian matrix L. The Laplacian matrix of a directed graph is defined as follows:
[0118] L=DA
[0119] 3) Calculate the eigenvalues and eigenvectors of L. Use the relevant library functions in the Numpy library in Python to calculate the eigenvalues and eigenvectors of L. The specific code is expressed as: eigenvalues, eigenvectors = np.linalg.eig (L).
[0120] 4) Get the position code. If the eigenvector obtained in the previous step contains a complex number, only the real part is selected and the imaginary part is discarded. Then sort by eigenvalue and select the K smallest non-zero eigenvectors as the node's position code information PE.
[0121] Transpose A to get A T , and through the above steps consistent with the steps of finding the position vector of the adjacency matrix A, the position encoding information PE' of the reverse graph can be obtained. PE and PE' are concatenated as the final position encoding information, namely BPE, which is passed to the next model.
[0122] BPE=Concat(PE,PE′)
[0123] S502 extracts the global structural features of graph nodes through a self-attention mechanism model that can process graph data. The specific method is to train a self-attention mechanism model to process the graph embedding X and the position encoding BPE obtained in S501. The model is composed of multiple encoding layers stacked together, and each encoding layer includes two sublayers: a self-attention layer and a feedforward neural network layer. The self-attention mechanism model is as follows:
[0124] G h =FC(Attention(X+BPE;W Q ,W K ,W V ))
[0125] Where X is the graph embedding matrix, BPE is the position encoding of the directed graph, and W Q , W K and W V is the learnable parameter of the attention layer. Attention is the self-attention layer, and FC is the feedforward neural network. G h It is the global structural feature of the graph node extracted after the self-attention mechanism.
[0126] The self-attention mechanism model makes the positions of any two nodes in the sequence become adjacent, and the features can be better transferred, thereby better extracting global features to solve the over-compression problem of GNN.
[0127] S6 combines the inherent features of the data with the local structural features and the global structural features, and classifies them to obtain the detection results. The specific method is to extract the inherent features of the data A through the encoder h , local structural features L extracted by graph neural network h And the global structural feature G extracted by the self-attention mechanism model h The final feature representation of the gate unit is obtained by feature fusion. The fusion here is completed by splicing operations between tensors. The formula for feature fusion is as follows:
[0128] h G =Concat(G h ,L h ,A h )
[0129] Among them, h G It is the final feature representation of the graph node after feature fusion. Finally, the fused features are input into the final classification model for classification. The classification model is implemented by a multi-layer perceptron (MLP). Through the Softmax function, the output of the MLP can be converted into a probability distribution, thereby realizing the classification of circuit nodes. In the present invention, the MLP has 2 layers, the first layer has 60 nodes, and the second layer has 2 nodes. The output of the MLP is an N*2-dimensional matrix, where N is the number of directed graph nodes, and 2 represents the predicted probability of the two categories of normal circuit nodes and Trojan circuit nodes. The processing process of the classification model is shown in the following formula:
[0130]
[0131] where h G is the final feature representation of all gate nodes. For the final prediction output, the class with the higher prediction value is selected as the final prediction class of the node.
[0132] The present invention discloses a method and system for detecting hardware Trojans using a graph neural network that integrates an attention mechanism. First, the netlist circuit code carrying the hardware Trojan is mapped to a directed graph, and then the graph is embedded, and the graph embedding is obtained by using onehot encoding; the large graph is divided into small subgraphs using a graph partitioning algorithm. The inherent features of the node are extracted by an encoder, the local features of the node are extracted by a graph neural network, the global features of the node are extracted by a self-attention mechanism model, the inherent features of the data, the local structural features and the global structural features are feature fused, and the detection results are obtained by classification. The present invention solves the problem of excessive compression and excessive smoothing when the graph neural network is applied to hardware Trojan detection, so that Trojans such as Payload diffusion type can also be well detected. The graph neural network cannot extract global features, resulting in low accuracy and efficiency of the existing detection method. The present invention extracts the global features of the node through the attention mechanism model, and simultaneously fuses the inherent features of the data, the local structural features and the global structural features, thereby improving the accuracy of hardware Trojan detection. The large graph is divided into small subgraphs by a graph partitioning algorithm, which reduces the time and resource overhead of hardware Trojan detection, so that the system can be expanded to large-scale design.
[0133] Embodiment 2
[0134] The present invention also provides a graph neural network hardware Trojan detection system integrating an attention mechanism, the system is used to implement any one of the methods described, the system comprising: a mapping module, a preprocessing module, an inherent feature extraction module, a local feature extraction module, a global feature extraction module and a classification module;
[0135] The mapping module is used to map the netlist circuit code carrying the hardware Trojan into a directed graph;
[0136] The preprocessing module is used to perform graph embedding, graph segmentation and graph sampling on the directed graph to obtain a training set;
[0137] The intrinsic feature extraction module is used to extract the intrinsic features of the nodes in the training set through the encoder;
[0138] The local feature extraction module is used to extract local features of nodes in the training set through graph neural network;
[0139] The global feature extraction module is used to extract the global features of nodes in the training set through the attention mechanism model;
[0140] The classification module is used to fuse inherent features, local features and global features, and obtain HT detection results through the classification model.
[0141] The embodiments described above are only descriptions of the preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.
Claims
1. A hardware Trojan detection method based on a graph neural network integrating an attention mechanism, characterized in that: The method comprises: S1: Map the netlist circuit code carrying the hardware Trojan into a directed graph; S2: Perform graph embedding, graph segmentation and graph sampling on the directed graph to obtain a training set; S3: Extract the intrinsic features of the nodes in the training set through the encoder; S4: Extract local features of nodes in the training set through graph neural network; S5: Extract global features of nodes in the training set through the attention mechanism model; S6: Intrinsic features, local features and global features are fused and the HT detection results are obtained through the classification model.
2. The method according to claim 1, characterized in that In S1, mapping the netlist circuit code carrying the hardware Trojan into a directed graph includes: The open source hardware design toolkit Pyverilog is used to parse and analyze the lexical and grammatical information of the gate-level netlist and generate the abstract syntax tree AST corresponding to the gate-level netlist; The circuit gate unit objects in AST are regarded as the vertices of the graph, the connections between the gate units are regarded as the edges between the vertices of the graph, and the netlist design is modeled as the corresponding directed graph.
3. The method according to claim 2, characterized in that In S2, the graph embedding, graph segmentation and graph sampling of the directed graph include: Generate an adjacency matrix from a directed graph; According to the adjacency matrix, the basic type of the gate unit is encoded using a one-hot vector to obtain the embedding matrix of the gate node; A graph partitioning algorithm based on breadth-first search is used to divide the directed graph into subgraphs; The graph sampling algorithm is used to sample the subgraph set to form the final training set.
4. The method according to claim 3, characterized in that: In S3, the inherent features of the nodes in the training set are extracted by the encoder, including: The graph embedding matrix is input into the autoencoder, which is mapped to a preset low-dimensional representation through the autoencoder to extract the inherent data features of the node; Restore low-dimensional features through the decoder; The mean squared error loss between the input of the autoencoder and the output of the decoder is used as part of the loss function of the entire model.
5. The method according to claim 3, characterized in that: In S4, extracting local features of nodes in the training set by using the graph neural network includes: Process graph data through the forward graph convolutional network GCN layer; Process the output of the forward graph convolutional network GCN layer through the reverse graph convolutional network GCN layer; The outputs of the same bidirectional graph convolutional network GCN layer are first fused and then passed to the next bidirectional graph convolutional network GCN layer as input to form a bidirectional GCN convergence model; The bidirectional GCN aggregation model is used to extract local structural features of graph nodes.
6. The method according to claim 3, characterized in that In S5, extracting the global features of the nodes in the training set through the attention mechanism model includes: The position encoding of the graph structure is obtained by an algorithm for obtaining position encoding of a directed graph; A self-attention mechanism model is used to process graph embedding and position encoding to extract global features of graph nodes; The position coding of the graph structure is obtained by using an algorithm for obtaining position coding of a directed graph, including: Find the position code PE corresponding to the directed graph; Find the positional encoding PE' of the directed graph transpose; Connect PE and PE' as the final positional encoding BPE; The global features of graph nodes are extracted by processing graph embedding and position encoding through a self-attention mechanism model, including: The dependencies between distant nodes in the graph are captured through the self-attention mechanism. At the same time, the constraints of the graph structure are introduced into the self-attention mechanism, and the attention weights are limited to be allocated only to connected neighbor nodes.
7. The method according to claim 1, characterized in that In S6, the inherent features, local features and global features are fused, and the HT detection results obtained through the classification model include: Extract the inherent features of the data A through the encoder h , local structural features L extracted by graph neural network h And the global structural feature G extracted by the self-attention mechanism model h Perform feature fusion to obtain the final feature representation of the gate unit; Input the fused features into the final classification model for classification; Among them, the fusion is completed by splicing operations between tensors, and the formula for feature fusion is: h G =Concat(G h ,L h ,A h ) Among them, h G It is the final feature representation of the graph node after feature fusion; The processing process of the classification module is: in, is the final prediction output.
8. A graph neural network hardware Trojan detection system integrating an attention mechanism, the system being used to implement the method described in any one of claims 1 to 7, characterized in that: The system comprises: a mapping module, a preprocessing module, an inherent feature extraction module, a local feature extraction module, a global feature extraction module and a classification module; The mapping module is used to map the netlist circuit code carrying the hardware Trojan into a directed graph; The preprocessing module is used to perform graph embedding, graph segmentation and graph sampling on the directed graph to obtain a training set; The inherent feature extraction module is used to extract the inherent features of the nodes in the training set through the encoder; The local feature extraction module is used to extract local features of nodes in the training set through a graph neural network; The global feature extraction module is used to extract the global features of the nodes in the training set through the attention mechanism model; The classification module is used to fuse the inherent features, local features and global features, and obtain the HT detection results through the classification model.
Citation Information
Patent Citations
Graph neural network node classification method fusing local topological structure
CN115081528A
ResNeXt structure based on attention mechanism and image classification algorithm applying same
CN116503661A
Malicious code detection method and device, electronic equipment and storage medium
CN116975864A
Structural feature and data representation fused hardware Trojan horse detection method and device
CN117892368A
Hardware Trojan horse detection and positioning method based on graph convolutional neural network
CN119312415A
Cited By
Hardware Trojan horse detection method based on machine learning and hybrid sampling
CN114611103A
A hardware Trojan detection method based on machine learning and hybrid sampling
CN114611103B