Low-power-consumption on-chip network hardware Trojan horse detection method oriented to various flows
By directly collecting Flits data in an on-chip network, constructing feature vectors and dynamically activate the machine learning model, the problems of high detection error rate, high computational complexity and high power consumption in the prior art are solved, and low-power and efficient hardware Trojan detection is achieved.
Patent Information
- Application Number
- CN202510334606.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-08
AI Technical Summary
When detecting on-chip network hardware Trojans, the prior art has problems such as high misjudgment rate, high computational complexity, long detection time and high power consumption, especially in complex traffic modes, which are difficult to effectively adapt.
By directly collecting Flits data in the on-chip network, constructing feature vectors, dynamically activate machine learning models using traffic-sensitive algorithms and improved Bully algorithms, combining XGBoost algorithms and collective decision strategies, reducing power consumption and improving detection accuracy.
It significantly reduces detection power consumption, improves detection accuracy and robustness in multiple traffic modes, and is suitable for on-chip network environments with resource-constrained.
Smart Images

Figure CN120277665A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of hardware security, and particularly to a low-power on-chip network hardware Trojan detection method for multiple traffic types. Background Art
[0002] With the rapid development of multi-core processors and system-on-chip (SoC), on-chip networks have become a core component of modern integrated circuit systems. However, with the continuous expansion of the scale of on-chip networks and the increasing complexity of application scenarios, their security issues have gradually emerged, especially the threats posed by hardware Trojans are becoming increasingly serious. Against this background, how to effectively detect hardware Trojans in on-chip networks during runtime has become one of the key technologies to ensure the efficient and reliable operation of on-chip networks.
[0003] A hardware Trojan refers to a hidden circuit maliciously implanted during the design, manufacturing, or testing stage of a chip. They are usually activated under specific triggering conditions, which may lead to data leakage, performance degradation, or even system crashes. Due to the highly dynamic traffic characteristics of on-chip networks, hardware Trojans can launch attacks by forging communication patterns, tampering with data packets, hijacking traffic, etc., posing a serious threat to system security. Therefore, how to efficiently and accurately detect hardware Trojans in on-chip networks has become an important topic in on-chip network security research.
[0004] Machine learning performs excellently in anomaly detection. Currently, there are studies using machine learning for gate-level hardware Trojan detection, achieving good detection results, but there are still deficiencies; for example, the detection method based on NoC runtime engineering features and machine learning may have a high false positive rate in complex traffic patterns, limiting its application in complex scenarios; the detection method based on the change point model and random forest algorithm has a high computational complexity, and the detection accuracy decreases to a certain extent in a reasonable large traffic pattern; the detection method based on data packet information and machine learning algorithms needs to collect data packets for each router, and each router requires an independent machine learning model to detect the collected data packets. Therefore, in practical applications, it may face long detection times and high power consumption problems.
[0005] Therefore, how to design a detection method that can adapt to multiple traffic patterns and reduce the power consumption of detection is a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0006] In view of the above problems, the present invention provides a low-power on-chip network hardware Trojan detection method for multiple traffic types, aiming to significantly improve the performance of the machine learning-based on-chip network hardware Trojan detection method in multiple traffic patterns, while reducing the detection power consumption and expanding its applicable range, thereby comprehensively improving the overall performance of the detection system.
[0007] To achieve the above object, the technical solution adopted by the present invention is as follows:
[0008] A low-power on-chip network hardware Trojan detection method for multiple types of traffic, comprising the following steps:
[0009] S1. Capture the packet header information passing through the router;
[0010] S2. Locate the most likely affected adjacent nodes through traffic transmission rate analysis;
[0011] S3. Perform real-time analysis on the network traffic data of the suspicious nodes, judge whether there is an abnormality through a machine learning algorithm, and calculate the probability value of the occurrence of the abnormality;
[0012] S4. Comprehensively evaluate the detection results of the suspicious nodes to obtain the overall probability of the NoC being attacked by a hardware Trojan within a specific time window.
[0013] Preferably, in S1, traffic data passing through the router is collected within a set time range, and these data are transmitted to the decision-making unit.
[0014] Preferably, using the on-chip network feature data as the training set, the best feature set is extracted through the XGBoost algorithm and the model is trained and optimized; after the training is completed, the optimized XGBoost model is used to perform real-time online detection on the on-chip network data.
[0015] Preferably, in S2, the traffic-sensitive algorithm module in the decision-making unit analyzes the received traffic data, dynamically selects a machine learning model to detect the traffic data, and obtains the speculation results of these models.
[0016] More preferably, the specific algorithm steps of the traffic-sensitive algorithm module are as follows:
[0017] When the trigger condition of a certain node is satisfied, the trigger mechanism combines with the improved Bully algorithm to locate the most suspicious node and its adjacent nodes, and only activates the XGBoost models corresponding to these nodes.
[0018] More preferably, in S3, according to the speculation results of the model, a collective decision-making strategy is adopted to calculate the probability of the NoC being attacked by a Trojan within this time range.
[0019] More preferably, the calculation formula of the collective decision-making strategy is as follows:
[0020]
[0021] Among them, AP tDenotes the probability that the entire NoC is attacked within a time window, F a Denotes the router R a The eigenvector collected in a Denotes R a The corresponding machine learning model, AP a Denotes the router R a The probability that the Flit in is attacked, FT k Denotes within the same time window TF k The total number of Flits transmitted within.
[0022] Preferably, in S4, the final comprehensive evaluation result is generated by aggregating the model decision results of multiple router nodes.
[0023] Compared with the prior art, the beneficial effects of the present invention include:
[0024] (1) Applicable to multiple traffic patterns
[0025] The present invention directly collects the Flits transmitted in the on-chip network and constructs eigenvectors using the bit information in the Flits, rather than relying on runtime characteristics such as link utilization, average delay, and injection rate that are greatly affected by traffic patterns. Since the bit information of Flits can more directly reflect the original state of data packets, this detection method is less affected by traffic patterns, can adapt to a variety of complex traffic patterns, and significantly improves the versatility and robustness of the detection platform.
[0026] (2) Less affected by the environment
[0027] The present invention directly collects Flit information, which is less affected by external environmental factors (such as temperature, voltage frequency, etc.) and has high stability. Compared with traditional detection methods, the present invention can still maintain high detection accuracy under changing external environments, thereby reducing the interference of environmental factors on detection results and enhancing the reliability of the system.
[0028] (3) Significantly reduce detection power consumption
[0029] The present invention introduces a traffic-sensitive algorithm (TSA). Through a dynamic trigger mechanism combined with an improved Bully algorithm, only the machine learning models corresponding to the most suspicious nodes and their neighbor nodes are activated, rather than blindly activating the models of all routing nodes. This selective activation mechanism greatly reduces unnecessary model calculation overhead, thereby significantly reducing the overall detection power consumption. Compared with the prior art, the present invention achieves lower energy consumption while ensuring detection efficiency, and is particularly suitable for resource-constrained on-chip network environments. Description of the Drawings
[0030] Figure 1 It is a flowchart of a method for detecting hardware Trojans in a low-power NoC (Network-on-Chip) facing multiple types of traffic according to the present invention.
[0031] Figure 2 It is a diagram of a hardware Trojan detection framework based on ML according to the present invention.
[0032] Figure 3 It is a design flowchart of the detection framework according to the present invention. Specific embodiments
[0033] Please refer to Figure 1-2 As shown, the present invention relates to a method for detecting hardware Trojans in a low-power NoC facing multiple types of traffic, including the following steps:
[0034] S1. Capture the packet header information passing through the router;
[0035] As Figure 3 shown, it is a design flowchart of the method of the present invention. First, it is necessary to deeply analyze and extract the NoC traffic characteristics. NoC traffic analysis involves extracting a large amount of characteristic data from packets / flits. Although there is abundant available data, the selection of features and the design of new features are the keys to building a reliable detection mechanism.
[0036] Therefore, it is necessary to carefully select features according to the possible types of hardware Trojans and their impacts on the NoC runtime. During the design stage, features that can reflect the behavior of hardware Trojans should be identified as much as possible to avoid a decline in detection effectiveness due to missing important features. In addition, considering that the number of application programs executed by different routing nodes may be different, different feature vectors can be selected for extraction according to specific circumstances.
[0037] Secondly, it is necessary to design router probes to collect data. The probe consists of a sniffer, an event generator, and a network interface. When the sniffer in the probe detects the arrival of a Flit, the probe starts to trigger. The sniffer extracts features from the arriving Flit and sends them to the event generator to create timestamp messages. Subsequently, the network interface encapsulates and sends the messages to the decision unit.
[0038] When designing the probe, it is necessary to fully consider its power consumption and the degree of interference with the normal communication of the NoC, and ensure that while the probe efficiently collects data, the impact on the system hardware is minimized.
[0039] The present invention directly collects Flits data in the NoC using a probe, rather than relying on traditional runtime engineering characteristics such as injection rate, average latency, and link utilization. The probe extracts Flits to construct feature vectors and sends this traffic data to the decision-making unit. In particular, the probe is embedded in the NoC in a non-intrusive manner to ensure that it does not affect the normal communication of the network. By directly collecting Flits to construct feature vectors, it can effectively avoid the interference of complex traffic patterns on the detection platform and significantly improve the applicability and robustness of the detection platform under various traffic patterns.
[0040] By using a probe to directly pass through the traffic data of the router within a set time range and transmitting this data to the decision-making unit.
[0041] S2. Locate the most likely affected adjacent nodes through traffic transmission rate analysis;
[0042] The present invention also designs a traffic-sensitive algorithm module (TSA). Since the operation of all XGBoost trojan detection modules will bring additional performance overhead, a strategy combining a modified Bully algorithm and a trigger mechanism is adopted to select routing nodes that actively contribute to the machine learning model within a specific time range. This mechanism is called the traffic-sensitive algorithm (TSA), as Figure 3 shown in the trigger mechanism: a packet transmission rate greater than 1 is used as the trigger mechanism. When the data transmission rate of a certain router exceeds 1, the TSA trigger will be activated, thereby marking this router as a potential malicious router.
[0043] Subsequently, the modified Bully algorithm is used to analyze the packet transmission rate of this router and the transmission rates of its adjacent routers. If the packet transmission rate of an adjacent router is also high, it is selected as a new potential malicious router, and this process is repeated until the router with the highest transmission rate is found. Finally, the system will use the traffic data of this router and its adjacent routers as the dataset to activate the machine learning models of these nodes.
[0044] Using the on-chip network feature data as the training set, the best feature set is extracted and the model is trained and optimized through the XGBoost algorithm; after training, the optimized XGBoost model is used to perform real-time online detection on the on-chip network data, as follows:
[0045] The traffic-sensitive algorithm module in the decision-making unit analyzes the received traffic data, dynamically selects a machine learning model to detect the traffic data, and obtains the speculation results of these models.
[0046] The specific algorithm steps of the traffic-sensitive algorithm module are as follows:
[0047] When the trigger condition of a certain node is met, the triggering mechanism combines with the improved Bully algorithm to locate the most suspicious node and its adjacent nodes, and only activates the XGBoost models corresponding to these nodes.
[0048] Only activate the machine learning models corresponding to the most suspicious node and its neighbor nodes, rather than blindly activating the models of all routing nodes. This selective activation mechanism significantly reduces the unnecessary model calculation overhead, thus significantly reducing the overall detection power consumption.
[0049] During the XGBoost model training stage, first, it is necessary to train the corresponding detection model for each NoC routing node. Specifically, it is necessary to obtain the traffic dataset of the NoC, including normal traffic and Trojan-infected traffic. In the case of no Trojan, collect the Flit data passing through each routing node, extract the feature vectors constructed in the design stage, and form the normal traffic dataset. Subsequently, according to the preset attack scenarios, simulate the attack behavior of the hardware Trojan on the NoC, collect the traffic data of each routing node under these scenarios, and generate the feature vectors in the case of Trojan infection. Integrate the normal traffic data and Trojan-infected data to construct a complete training dataset, ensuring that the dataset covers the features of both normal and abnormal states. Then, use the constructed training dataset to train the XGBoost model to ensure that the model can accurately distinguish normal traffic and Trojan-infected traffic. Since the feature vectors constructed in the design stage may be correlated, directly using all features will result in additional computational overhead. Therefore, the principal component regression (PCR) technique is used to reduce the dimensionality of the feature vectors and extract the most important features to reduce the model complexity and improve the detection efficiency.
[0050] Through the above steps, the training stage can generate an efficient and accurate detection model for each routing node, laying a foundation for subsequent real-time detection.
[0051] S3. Perform real-time analysis on the network traffic data of the suspicious node, determine whether there is an anomaly through machine learning algorithms, and calculate the probability value of the occurrence of the anomaly;
[0052] According to the speculation result of the model, adopt a collective decision-making strategy to calculate the probability that the NoC is attacked by a Trojan within this time range.
[0053] The calculation formula of the collective decision-making strategy is as follows:
[0054]
[0055] Among them, AP t represents the probability that the entire NoC is attacked in a time window, F a represents the feature vector collected in router R a and M a represents Ra The corresponding machine learning model, AP a represents the router R a The probability that the Flit in it is attacked, FT k represents within the same time window TF k The total number of Flits transmitted within.
[0056] AP t represents the probability that the entire NoC is attacked in a time window, which is the inference result of the model.
[0057] S4. Comprehensively evaluate the detection results of suspicious nodes to obtain the overall probability that the NoC is attacked by hardware Trojans within a specific time window.
[0058] Generate the final comprehensive evaluation result by aggregating the model decision results of multiple router nodes.
[0059] The present invention adopts a collective decision-making strategy to evaluate the probability that the on-chip network is attacked within a specific time window. This strategy draws on the "Opinion Pooling" method in the field of probability theory and generates the final comprehensive evaluation result by aggregating the model decision results of multiple router nodes.
[0060] In probability theory, Opinion Pooling refers to the process of synthesizing multiple probability distributions or probability opinions into a unified probability distribution. It can synthesize different probability estimates given by multiple models for the same event. Specifically, this strategy can combine the detection results of different nodes, calculate the overall probability that the on-chip network is attacked within a specific time period, and thus provide a more comprehensive and reliable security evaluation.
[0061] In summary, through the innovative technical solution, the present invention is superior to the prior art in terms of applicability, environmental robustness, and power consumption optimization, providing an efficient, reliable, and low-overhead solution for hardware Trojan detection.
[0062] The above embodiments are only descriptions of the preferred embodiments of the present invention and do not limit the scope of the present invention. Without departing from the design spirit of the present invention, various deformations and improvements made by those of ordinary skill in the art to the technical solution of the present invention shall fall within the protection scope determined by the claims of the present invention.
Claims
1. A low-power on-chip network hardware Trojan detection method for multiple traffic types, characterized in that It includes the following steps: S1. Capture the packet header information passing through the router; S2. Locate the most likely affected adjacent nodes through traffic transmission rate analysis; S3. Conduct real-time analysis on the network traffic data of the suspicious nodes, judge whether there is an abnormality through machine learning algorithms, and calculate the probability value of the occurrence of the abnormality; S4. Comprehensively evaluate the detection results of the suspicious nodes to obtain the overall probability of the NoC being attacked by hardware Trojans within a specific time window.
2. The low-power on-chip network hardware Trojan detection method for multiple types of traffic according to claim 1, wherein In S1, collect the traffic data passing through the router within the set time range and transmit this data to the decision-making unit.
3. A hardware Trojan detection method for a low-power on-chip network for multiple traffic types according to claim 1, characterized in that Use the on-chip network feature data as the training set, extract the optimal feature set through the XGBoost algorithm and train the optimized model; after the training is completed, use the optimized XGBoost model to conduct real-time online detection on the on-chip network data.
4. A hardware Trojan detection method for a low-power on-chip network facing multiple traffic flows according to claim 1, characterized in that In S2, the traffic-sensitive algorithm module in the decision-making unit analyzes the received traffic data, dynamically selects machine learning models to detect the traffic data, and obtains the speculation results of these models.
5. A method for detecting hardware Trojans in a low-power on-chip network for multiple traffic types according to claim 4, characterized in that The specific algorithm steps of the traffic-sensitive algorithm module are as follows: When the trigger condition of a certain node is met, the trigger mechanism combines the improved Bully algorithm to locate the most suspicious node and its adjacent nodes, and only activates the XGBoost models corresponding to these nodes.
6. A hardware Trojan detection method for a low-power on-chip network facing multiple traffic flows according to claim 4, characterized in that In S3, according to the speculation results of the model, adopt a collective decision-making strategy to calculate the probability of the NoC being attacked by Trojans within this time range.
7. A hardware Trojan detection method for a low-power on-chip network for multiple traffic types according to claim 6, characterized in that The calculation formula of the collective decision-making strategy is shown as follows: Among them, AP t represents the probability that the entire NoC is attacked in a time window, F a represents the eigenvector collected in router R a , M a represents the machine learning model corresponding to R a , AP a represents the probability that the Flit in router R a is attacked, FT k represents the total number of Flits transmitted within the same time window TF k .
8. A hardware Trojan detection method for a low-power on-chip network facing multiple traffic flows according to claim 1, characterized in that In S4, generate the final comprehensive evaluation result by aggregating the model decision results of multiple router nodes.