Online Monitoring and Source Tracing Method for Hardware Trojans in AI Accelerators Based on Heterogeneous Side-Channel Awareness

By collecting multi-dimensional side-channel features in an FPGA AI accelerator and using a deep learning model for spatiotemporal correlation modeling, the problems of insufficient coverage of rare triggers and difficulty in locating hardware Trojans are solved, enabling real-time monitoring and accurate source tracing, and improving the robustness and detection accuracy of the system.

CN122133143APending Publication Date: 2026-06-02ZHEJIANG UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG UNIV OF TECH
Filing Date
2026-01-26
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively detect hardware trojans in FPGA AI accelerators, especially with insufficient coverage under rare triggering conditions and a lack of precise location capabilities for trojan logic regions, failing to meet the needs of real-time monitoring and security assessment.

Method used

By coordinating the scheduling of multi-source native monitoring resources on the FPGA chip, collecting multi-dimensional side-channel feature fingerprints, and using deep learning models for spatiotemporal correlation modeling and adaptive compensation strategies, real-time monitoring and physical area tracing of hardware Trojans can be achieved.

Benefits of technology

Without affecting accelerator performance, it significantly improves the robustness and accuracy of hardware Trojan detection, reduces the false alarm rate, and achieves highly sensitive identification and accurate location of unknown triggering mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133143A_ABST
    Figure CN122133143A_ABST
Patent Text Reader

Abstract

A method for online monitoring and tracing of hardware Trojans implanted in AI accelerators based on heterogeneous side-channel perception is proposed. This method collaboratively schedules heterogeneous native monitoring resources on FPGAs to capture multi-dimensional side-channel feature fingerprints in situ. It utilizes deep neural networks for spatiotemporal joint modeling and behavior reconstruction, and integrates adaptive compensation strategies to resist thermal drift interference. This enables autonomous monitoring of hardware Trojan behavior and precise physical region tracing within the AI ​​accelerator. This method significantly improves the robustness of hardware Trojan detection under complex conditions without requiring external audit intervention or significantly impacting accelerator inference performance. It also demonstrates good detection generalization ability for various unknown triggering mechanisms, providing a key technical path for the security assessment and risk hardening of convolutional neural network accelerators.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of AI accelerator hardware security, specifically relating to a hardware Trojan detection and localization method based on multi-source on-chip sensor fingerprints and deep learning models. This method achieves real-time in-situ monitoring and abnormal physical region tracing of AI accelerator hardware Trojans by coordinating on-chip bus monitoring, environmental perception, and side-channel acquisition arrays to extract heterogeneous features, and by combining a spatiotemporal correlation autoencoder network. Background Technology

[0002] In the development of FPGA (Field-Programmable Gate Array)-based AI accelerators, integrating third-party intellectual property (3PIP) kernels has become the mainstream approach in the industry. These kernels cover key types such as neural network computation operator kernels (e.g., convolution, pooling, and fully connected operators), on-chip interconnect control kernels, and memory control kernels, effectively shortening the development cycle and lowering the threshold for operator implementation. However, due to the lack of transparency of the internal logic of 3PIP kernels to the design integrator, they provide opportunities for the covert implantation of malicious hardware Trojans (HTs), becoming a core vulnerability in the hardware security of FPGA AI accelerators. Hardware Trojans typically consist of triggering logic and malicious payloads. The triggering logic is often related to specific operating states of the neural network, such as specific operator configuration parameters, input data characteristics, and on-chip resource utilization. Malicious payloads include behaviors such as tampering with operator computation logic, stealing model weights, and blocking on-chip interconnect links. Their scope can cover key modules such as the core operator control logic of the neural network accelerator (e.g., ReLU layers, convolution computation units) and on-chip interconnect resources. Once a Trojan horse is triggered and activated, it will cause a series of fatal systemic crises. It will not only tamper with model predictions leading to misclassification and abnormal fluctuations in confidence levels, but may also steal sensitive model weight parameters through covert channels, posing a serious threat to the operational security and data confidentiality of AI systems. Traditional pre-silicon verification and simulation testing only focus on functional correctness verification, making it difficult to cover all rare activation modes in the vast neural network input space. This makes it impossible to effectively activate and detect malicious circuits designed based on such modes, and thus difficult to achieve comprehensive security control. Therefore, to ensure that FPGA AI accelerators eliminate hardware security risks before formal industrial application, and to guarantee hardware integrity during their operation after deployment, building an online in-situ monitoring system for the 3PIP core, thereby achieving real-time capture and early warning of Trojan horse triggering behavior, has become a core requirement and necessary prerequisite for the current security research and development of FPGA AI accelerators.

[0003] Currently, the detection of hardware Trojans in AI accelerators mainly follows three technical paths: logic simulation testing, offline power side-channel analysis, and formal verification. However, their application in FPGA AI accelerator scenarios has significant limitations and cannot meet actual security requirements. Logic simulation testing relies on manually constructing test vectors for detection. Due to the extremely high input dimension of neural networks, covering rare triggering conditions is extremely difficult, making it impossible to construct test vectors that cover all potential Trojan triggering scenarios. This results in a high false negative rate for Trojans and prevents comprehensive detection. Offline power side-channel analysis technology based on external oscilloscopes requires sophisticated and expensive external testing equipment. It can only perform static or offline security assessments of 3PIP cores and cannot be integrated into the FPGA system. It is difficult to deal with dynamic Trojan attacks that occur in real time, limiting its practicality. Although formal verification can verify the consistency of hardware logic based on mathematical logic, it has poor adaptability to the complex neural network operator logic and on-chip interconnect resources in FPGA AI accelerators and cannot cope with physical fingerprint interference caused by environmental drift and fluctuations in internal resource toggle rates. Furthermore, existing machine learning-based detection schemes lack effective adaptive anti-interference algorithms, and the false alarm rate increases significantly under the influence of the aforementioned environmental interference and resource fluctuations. More importantly, existing methods can only output a binary judgment result of "whether a Trojan exists," lacking the ability to accurately locate the logic area where the Trojan is located and trace the source of anomalies in the complex wiring layout of FPGAs, thus failing to provide effective support for subsequent repair and protection. Summary of the Invention

[0004] To overcome the shortcomings of existing technologies in detecting hardware Trojans in AI accelerators, such as difficulty in covering rare triggers, high dependence on external offline devices, and poor environmental adaptability, this invention provides a hardware Trojan detection and localization method based on multi-source on-chip sensor fingerprints and deep learning models. This invention achieves autonomous monitoring and precise physical region tracing of hardware Trojan behavior implanted in AI accelerators by collaboratively scheduling heterogeneous native monitoring resources on FPGAs to capture multi-dimensional side-channel feature fingerprints in situ. It utilizes deep neural networks for spatiotemporal joint modeling and behavior reconstruction, and integrates adaptive compensation strategies to resist thermal drift interference. This enables autonomous monitoring of hardware Trojan behavior and precise physical region tracing. This method significantly improves the robustness of hardware Trojan detection under complex conditions without requiring external audit intervention or significantly affecting accelerator inference performance. It also exhibits good detection generalization ability for various unknown triggering mechanisms, providing a key technical path for the security assessment and risk hardening of convolutional neural network accelerators.

[0005] The technical solution adopted by this invention to solve its technical problem is: A method for online monitoring and tracing of hardware Trojans in AI accelerators based on heterogeneous side-channel sensing, the method comprising the following steps: Step 1: Based on the on-chip multi-source native monitoring resources of the FPGA, collaboratively collect multi-dimensional side-channel raw sequences reflecting system performance transaction characteristics, physical environment stress characteristics, and circuit activity characteristics during the accelerator's execution of computing tasks; Step 2: Based on the multidimensional side channel original sequence obtained in Step 1, perform differential and standardization preprocessing on the side channel original sequence to eliminate the counting accumulation effect and dimensional difference, and construct a standardized side channel feature fingerprint space that characterizes the real-time operating status of the hardware through feature splicing. Step 3: Based on the deep reconstruction model with the ability to model time-dependent features and correlate multi-dimensional features, the collected side-channel feature fingerprints are jointly modeled. By learning the hardware behavior patterns under normal operating conditions, a quantitative representation of the hardware behavior benchmark is constructed. Step 4: Based on the moving average algorithm, the dynamic offset of the reconstruction error caused by environmental stress is perceived, and the detection benchmark is corrected online and the identification threshold is updated in real time. This filters out chip thermal drift and power supply noise interference to improve the detection robustness of the system under complex working conditions. Step 5: Determine the hardware Trojan triggering behavior based on the comparison results of the real-time reconstruction residual and the dynamic threshold; when an anomaly is detected, further analyze the contribution deviation of each side channel feature source to the reconstruction error, and combine the topological mapping relationship between on-chip sensors and logic resources to achieve accurate positioning of the abnormal logic region.

[0006] Furthermore, the process of step 1 is as follows: based on the multi-source native monitoring resources on the FPGA chip, during the accelerator's execution of computing tasks, the original multi-dimensional side channel sequence reflecting the system's operating behavior characteristics is captured in situ synchronously. The original side channel sequence includes at least the performance transaction characteristics extracted by the performance monitoring unit, the physical environment stress characteristics extracted by the environmental sensors, and the circuit activity frequency characteristics extracted by the distributed oscillator array.

[0007] Furthermore, step 2 includes: 2.1. The original frequency count values ​​of the circuit activity collected in step 1 are processed by first-order differential processing using formula (1) to eliminate the physical characteristics of frequency count values ​​accumulating over time, and to extract the frequency change characteristics reflecting the instantaneous fluctuations of logic path delay: (1); in, and These represent the original frequency count values ​​obtained at adjacent sampling times. Indicates time The frequency differential characteristics are used to characterize the instantaneous changes in the intensity of circuit activity; 2.2. The performance transaction characteristics, physical environment stress characteristics and differential frequency characteristics are standardized by formula (2) to eliminate the deviation interference caused by the inconsistency of dimensions and numerical scale of multi-source characteristics on the consistency of subsequent characteristic representation. (2); in, Indicates the first Side-channel characteristics at time The original value, and These represent the mean and standard deviation of this feature under baseline operating conditions, respectively. For the standardized version of the first Dimensional channel eigenvalues; 2.3. The standardized eigenvalues ​​obtained in step 2.2 are concatenated into vectors according to formula (3) to construct a representation of the hardware at time t. The side-channel feature fingerprint vectors of the running state form the standardized feature space required for subsequent behavior modeling, which is expressed as follows: (3); in, The total dimension of the features. Indicates at time Constructed standardized side-channel feature fingerprint vector.

[0008] Furthermore, the process of step 3 is as follows: 3.1. Input the standardized feature fingerprint space described in step 2 into the encoder network, use multi-layer long short-term memory units to nonlinearly compress the temporal evolution characteristics of the side-channel fingerprint, update the state of the internal memory units according to formula (4), and combine the output gate signal to obtain a low-dimensional hidden behavioral feature vector through formula (5). ; (4); (5); in, and Representing time respectively With time The state of the memory unit, , , These represent the gate control signals for the forget gate, input gate, and output gate, respectively. Candidate memory cell state, This represents element-wise multiplication. The hyperbolic tangent activation function is used; the encoder network models the temporal characteristics of the side-channel fingerprint through gating mechanism and nonlinear mapping, realizing a stable mapping from the high-dimensional original fingerprint sequence to the low-dimensional behavioral feature space; 3.2. Utilize spatial attention mechanism to process the latent behavioral feature vector output in step 3.1 Physical feature recalibration is performed, and the extreme values ​​of the feature distribution are extracted by global average pooling and global max pooling operators. Then, a weight matrix reflecting spatial saliency is generated by convolution operation according to formula (6). ; (6); in, For activation function, This represents a convolution operation with a kernel size of . and These represent global average pooling and global max pooling operations, respectively; through the weight matrix Enhance the perception weight of local feature dimensions affected by abnormal logic triggers; 3.3. The attention-weighted behavioral feature vector is predicted and reconstructed using a decoder network, and the reconstructed fingerprint is obtained according to formula (7). Furthermore, formula (8) is used to calculate the L2 norm residual between the original feature fingerprint described in step 1, and the reconstruction error score is obtained to quantify the degree to which the current hardware operation behavior deviates from the normal behavior benchmark. ; (7); (8); in, This represents the decoding mapping function. For the first in the reconstructed vector 1D feature components.

[0009] Furthermore, the process of step 4 is as follows: 4.1. The real-time reconstruction error score output from 3.3. The input environment perception module uses a moving average update algorithm to track the environmental background benchmark in real time, and calculates the time using formula (9). Environmental offset reference value To sense and extract the slow drift of reconstruction error caused by non-malicious environmental stresses such as chip thermal drift and power supply ripple; (9); in, This is a preset smoothing factor used to adjust the sensitivity of the benchmark update to the rate of environmental change. 4.2. Environmental offset baseline values ​​obtained from 4.1 Dynamic correction of the detection threshold is carried out. The real-time detection threshold under the current working condition is calculated by combining the historical statistical characteristics of the reconstruction error with formula (10). This enables online filtering of background noise interference and maintains robustness in anomaly detection. (10); in, As the confidence factor, The historical standard deviation of the reconstruction error score under normal operating conditions; 4.3. Calculate the real-time reconstruction error score output from step 3.3. The real-time detection threshold calculated in step 4.2 The comparison is performed to obtain the corrected hardware behavior anomaly representation value, which is then used as the decision input for determining the Trojan triggering behavior and performing regional tracing in step 5.

[0010] The process of step 5 is as follows: 5.1. Real-time reconstruction error score based on the output of 3.3 The real-time detection threshold calculated in section 4.2 Perform logical comparison and generate an anomaly detection signal according to formula (11). When the real-time reconstruction error exceeds the adaptive threshold boundary under the current operating conditions, the system determines that the hardware Trojan behavior has been activated and triggers an abnormal alarm signal, thereby achieving autonomous Trojan identification without the need for external gold model auditing intervention. (11); 5.2. After detecting a hardware anomaly alarm signal, the contribution ratio of each feature dimension in the multi-source side channel feature space to the deviation of the current reconstruction error is quantified by formula (12) to identify the core physical feature source that causes the behavior reconstruction failure; the standardized original fingerprint of each dimension is calculated. With the corresponding reconstructed fingerprint The proportion of the absolute deviation between the two residuals to the total residuals is used to determine the feature dimension index that contributes the most to the overall anomaly score. (12); in, Indicates the first Each side channel feature dimension at time... Contribution weight; 5.3. Using formula (13) and combined with the preset topological mapping table between the on-chip sensor physical layout and the accelerator logic operator level, the highest contribution feature identified in step 4.2 is indexed. Mapped to specific physical logic regions or operator functional modules of FPGA chips; through spatial tracing of abnormal dimensions, the precise physical location of hardware Trojan implantation in the contaminated third-party IP kernel can be achieved.

[0011] (13); in, The function is used to extract the feature index with the highest contribution weight. This is a predefined topological mapping function between feature indices and physical logical regions. This is the final physical location information of the Trojan horse.

[0012] In this invention, addressing the complexity and spatiotemporal correlation of the physical behavior of FPGA AI accelerators during operation, a standardized feature fingerprint space reflecting the real-time operating status of the hardware is constructed by in-situ capturing multi-dimensional side-channel fingerprints using on-chip heterogeneous native monitoring resources. Furthermore, a spatiotemporally correlated behavior reconstruction model is built by combining long short-term memory networks and spatial attention mechanisms. By learning the hardware behavior benchmark under normal operating conditions, the model's sensitivity and feature representation to unknown malicious triggering behaviors are improved. To address the interference of chip thermal effects and power supply noise on detection accuracy under dynamic operating environments, an environmental adaptive compensation strategy is constructed based on the moving average algorithm. By real-time correction of the detection benchmark and dynamic adjustment of the threshold, the robustness of the system under complex operating conditions is effectively enhanced. Based on the above methods, this invention can effectively achieve real-time autonomous monitoring and precise physical region tracing of hardware Trojans integrated into the 3PIP core of an AI accelerator without the need for external auditing equipment and without significantly affecting the accelerator's inference performance.

[0013] In this invention, firstly, a multidimensional physical fingerprint sequence is captured in situ by coordinating the scheduling of heterogeneous native resources of FPGA; then, a spatiotemporal correlation reconstruction model is used to extract the deep features of the fingerprint in terms of temporal evolution and spatial distribution, generating a reconstruction error that can quantify the degree of behavioral deviation; next, an environmental adaptive compensation strategy is introduced to perform benchmark correction and threshold update on the reconstruction error to eliminate the influence of non-malicious environmental interference on the detection results; finally, based on reconstruction residual analysis and topological mapping relationship, the hardware Trojan triggering behavior is determined and the abnormal logic region is accurately located.

[0014] The beneficial effects of this invention are mainly reflected in the following aspects: It constructs a behavior reconstruction model based on long short-term memory networks and spatial attention mechanisms, utilizes unsupervised learning to deeply characterize the operating benchmark of normal hardware, and achieves high-sensitivity identification and strong generalization monitoring of unknown hardware Trojans with various triggering mechanisms and payload types without relying on specific Trojan samples. Furthermore, by integrating an environmental adaptive compensation strategy, this invention can perceive and effectively filter physical fingerprint noise caused by chip thermal drift, power supply ripple, and logic flipping in real time, significantly reducing the false alarm rate under dynamic operating conditions and ensuring the system has extremely strong environmental robustness and stability. In addition, this method is entirely based on native on-chip resources of the FPGA and does not interfere with the original inference logic of the accelerator. While ensuring low-overhead, non-intrusive autonomous monitoring, it effectively overcomes the limitation of traditional solutions that can only provide binary judgment results by analyzing the dimensional contribution of the reconstruction residuals and combining them with physical topology mapping. This achieves accurate tracing and positioning of the physical logic region of contaminated third-party IP kernels, providing a key technical path for the security audit and accurate risk remediation of hardware systems. Attached Figure Description

[0015] Figure 1 This is a flowchart of an online monitoring and tracing method for hardware Trojans in AI accelerators based on heterogeneous side-channel sensing.

[0016] Figure 2 The results of this invention are experimental results on a typical ten-layer convolutional neural network (CNV) accelerator architecture, targeting hardware Trojan benchmark scenarios with various triggering mechanisms and attack payloads. Detailed Implementation

[0017] The present invention will now be further described with reference to the accompanying drawings.

[0018] Reference Figure 1 and Figure 2 A method for online monitoring and tracing of hardware Trojans in AI accelerators based on heterogeneous side-channel sensing, the method comprising the following steps: Step 1: In-situ acquisition of side-channel raw sequences based on multi-source native monitoring resources. During the accelerator's computational tasks, various heterogeneous native monitoring resources are coordinated and scheduled through on-chip control logic to synchronously acquire heterogeneous feature sequences reflecting system operation behavior. The side-channel raw sequences include at least: bus transaction characteristics obtained by the performance monitoring module; physical environmental stress characteristics obtained by the environmental sensing module; and circuit activity count values ​​obtained by the distributed frequency monitoring module. The specific implementation of the aforementioned monitoring resources is not limited to the example described, and may also be other on-chip monitoring units with equivalent performance capabilities for sensing transactions, environmental stress, or circuit activity.

[0019] Step 2: Constructing a feature fingerprint space based on differential and normalization processing. The multidimensional side channel raw sequences acquired in Step 1 are preprocessed by differential and normalization to eliminate the counting accumulation effect and dimensional differences, and a normalized feature fingerprint space representing the real-time operating status of the hardware is constructed. The process is as follows: 2.1. For the circuit activity characteristics with count value accumulation in step 1, the original value of the circuit frequency at the current sampling time is obtained by formula (1). Compared with the previous time value Perform differential operations to extract instantaneous features that reflect logical path delay fluctuations. : (1); 2.2. Based on pre-obtained baseline statistics for normal operating conditions and The frequency fluctuation features obtained in step 2.1 and the remaining heterogeneous features collected in step 1 are subjected to standardized mapping processing by formula (2) to eliminate the adverse effects of differences in the dimensions and numerical scales of multi-source features on the consistency of feature representation: (2); in, Indicates the first Side-channel characteristics at time The original value, For the standardized first 3D eigenvalues; 2.3. Using formula (3), the standardized multidimensional features are concatenated into vectors according to their index order in the chip's physical or logical topology to construct a standardized side-channel feature fingerprint space for subsequent behavior modeling. : (3); in, The total dimension of the features. This constitutes a standardized feature fingerprint space for subsequent hardware behavior modeling and anomaly detection; Step 3: Based on the spatiotemporal reconstruction model with the ability to model temporal dependencies and correlate multidimensional features, jointly model the standardized feature fingerprint space constructed in Step 2 to quantify the degree of deviation of hardware operating behavior from the normal behavior benchmark. The process is as follows: 3.1. Convert the feature fingerprint vector output in step 2... The input encoder network utilizes multi-layer long short-term memory units to perform nonlinear compression of temporal evolution characteristics, where the time window length... Based on the temporal correlation of the side-channel characteristics, this example is configured with 64 sampling points. The system updates the internal memory unit state according to formula (4). The timing-implicit behavior feature vector representing the hardware's operational logic state is obtained by mapping the output gate signal using formula (5). : (4); (5); in, , , These represent the gate control signals for the forget gate, input gate, and output gate, respectively. Candidate memory cell state, This represents element-wise multiplication. It is the hyperbolic tangent activation function; 3.2. Utilize spatial attention mechanism to process the latent feature vector output in step 3.1 Physical feature recalibration is performed using global average pooling ( ) and global max pooling ( The operator extracts the extreme values ​​of the feature distribution and generates a weight matrix reflecting the significance of the distribution of physical monitoring points through convolution operation according to formula (6). : (6); in, For activation function, This represents a convolution operation with a kernel size of . 3.3. Through decoder network Reconstruct the fingerprint according to formula (7) Furthermore, formula (8) is used to calculate the L2 residual between the original fingerprint described in step 2, and the reconstruction error score is obtained to quantify the degree to which the current hardware operation behavior deviates from the normal behavior benchmark. : (7); (8); in, For the first in the reconstructed vector 1D feature components.

[0020] Step 4: Based on the moving average algorithm, detect the dynamic shift of the reconstruction error calculated in Step 3 caused by environmental stress, and correct the detection benchmark and update the recognition threshold online in real time. The process is as follows: 4.1. The moving average module continuously receives the real-time reconstruction error score output from 3.3. The environmental offset baseline value in memory is updated in real time using formula (9). To detect the amount of slow error drift caused by non-malicious environmental stresses such as chip thermal drift: (9); In this embodiment, the smoothing factor Set to 0.05; this parameter determines the environmental offset baseline value. For updating sensitivity to error fluctuations, a smaller value is beneficial for filtering out high-frequency random noise and stably tracking the slow thermal drift caused by the rise in chip junction temperature; 4.2. Based on the environmental offset benchmark value obtained in 4.1, the detection threshold is dynamically corrected. The real-time detection threshold under the current working condition is calculated by combining the historical statistical characteristics of the reconstruction error with formula (10). To filter out background noise interference; (10); in, As the confidence factor, This represents the historical standard deviation. In this embodiment, The value is set to 4; this parameter is used to adjust the dynamic detection threshold. The boundary width is determined by setting a reasonable value. This value allows the system to effectively reduce the risk of false alarms caused by power supply ripple fluctuations while ensuring a high detection rate for abnormal behavior. 4.3. The real-time reconstruction error score output from 3.3. The detection threshold calculated in section 4.2 Store the data in the comparison register to generate the corrected anomaly representation value.

[0021] Step 5: Based on the comparison result between the reconstruction error and the dynamic threshold, perform Trojan trigger determination, and when an anomaly is detected, combine the logical-physical topology mapping relationship to locate the abnormal logical region. The process is as follows: 5.1. The logic comparison module performs threshold judgment according to formula (11). When the real-time reconstruction error output in step 3 exceeds the adaptive threshold boundary generated in step 4, the hardware Trojan triggers an alarm signal. : (11); 5.2. After detecting an abnormal alarm, the proportion of the deviation contribution of each feature dimension in the feature space described in step 2 to the current reconstruction error is quantified by formula (12). To identify the core physical feature source dimension index that leads to behavioral reconstruction failure: (12); 5.3 Using formula (13) and combining it with the preset topology mapping table between on-chip sensors and logic resources Index the highest contribution feature identified in 5.2 Mapped to specific physical logic region identifiers on the chip To achieve precise positioning: (13); This embodiment addresses the multi-source heterogeneity, temporal dependence, and spatial sensitivity characteristics of side-channel signals exhibited by FPGA AI accelerators during operation. It utilizes on-chip heterogeneous native monitoring resources to collect multi-dimensional physical side-channel fingerprints in situ, enhancing the comprehensive characterization of hardware operating status. Furthermore, combining the evolutionary characteristics of hardware behavior in the temporal dimension with its sensitivity to local anomalies in the spatial dimension, a behavior reconstruction modeling method based on a temporal encoder-decoder structure is constructed. A spatial attention mechanism is introduced to recalibrate side-channel features, improving the detectability of abnormal hardware behavior disturbances. Simultaneously, considering the impact of environmental stress on detection results under complex operating conditions, an environmental adaptive compensation mechanism based on the moving average algorithm is designed to correct the detection benchmark online and suppress non-malicious offsets caused by chip thermal drift and power supply noise. Based on the above technical solutions, without introducing external auditing equipment or interfering with the accelerator's original inference logic, real-time autonomous monitoring of unknown hardware trojans integrated in third-party IP kernels can be achieved, and the physical location of abnormal logic regions can be completed.

[0022] In this embodiment, Figure 2 The experimental results of the proposed method on a typical ten-layer convolutional neural network (CNV) accelerator architecture are shown, targeting hardware Trojan benchmark scenarios with various triggering mechanisms and attack payloads. The experimental results demonstrate that the proposed method exhibits similar detection performance when facing various heterogeneous Trojan variants, including spatial pixel triggering, temporal sequence triggering, and physical signal injection. It achieves good results in terms of detection success rate and false alarm rate, with an average detection success rate of approximately 97.8% and an average false alarm rate of approximately 8.4%. Furthermore, the method also demonstrates good overall performance in terms of anomaly localization accuracy and real-time processing latency. Compared with side-channel analysis methods based on logic testing or relying on external measurement equipment, this invention utilizes in-situ native resource collaborative sensing to overcome the high sensitivity of side-channel features to external environmental fluctuations. While ensuring extremely low logic resource overhead, it significantly enhances the system's environmental robustness and decision stability under complex operating conditions. This fully verifies the practical application value and technical effectiveness of this invention in ensuring the security of third-party IP cores and real-time online Trojan defense.

[0023] The embodiments described in this specification are only for illustrating the technical concept and implementation of the present invention, and do not constitute a limitation on the scope of protection of the present invention. All equivalent modifications or substitutions made by those skilled in the art without departing from the technical concept of the present invention should fall within the scope of protection of the present invention.

Claims

1. A method for online monitoring and tracing of hardware Trojans in AI accelerators based on heterogeneous side-channel sensing, characterized in that, The method includes the following steps: Step 1: Based on the on-chip multi-source native monitoring resources of the FPGA, collaboratively collect multi-dimensional side-channel raw sequences reflecting system performance transaction characteristics, physical environment stress characteristics, and circuit activity characteristics during the accelerator's execution of computing tasks; Step 2: Based on the multidimensional side channel original sequence obtained in Step 1, perform differential and standardization preprocessing on the side channel original sequence to eliminate the counting accumulation effect and dimensional difference, and construct a standardized side channel feature fingerprint space that characterizes the real-time operating status of the hardware through feature splicing. Step 3: Based on the deep reconstruction model with the ability to model time-dependent features and correlate multi-dimensional features, the collected side-channel feature fingerprints are jointly modeled. By learning the hardware behavior patterns under normal operating conditions, a quantitative representation of the hardware behavior benchmark is constructed. Step 4: Based on the moving average algorithm, the dynamic offset of the reconstruction error caused by environmental stress is perceived, and the detection benchmark is corrected online and the identification threshold is updated in real time. This filters out chip thermal drift and power supply noise interference to improve the detection robustness of the system under complex working conditions. Step 5: Determine the hardware Trojan triggering behavior based on the comparison results of the real-time reconstruction residual and the dynamic threshold; when an anomaly is detected, further analyze the contribution deviation of each side channel feature source to the reconstruction error, and combine the topological mapping relationship between on-chip sensors and logic resources to achieve accurate positioning of the abnormal logic region.

2. The method for online monitoring and tracing of AI accelerator hardware Trojans based on heterogeneous side-channel perception as described in claim 1, characterized in that, The process of step 1 is as follows: Based on the multi-source native monitoring resources on the FPGA chip, during the accelerator's execution of computing tasks, the original multi-dimensional side channel sequence reflecting the system's operating behavior characteristics is captured in situ synchronously. The original side channel sequence includes at least the performance transaction characteristics extracted by the performance monitoring unit, the physical environment stress characteristics extracted by the environmental sensors, and the circuit activity frequency characteristics extracted by the distributed oscillator array.

3. The method for online monitoring and tracing of AI accelerator hardware Trojans based on heterogeneous side-channel perception as described in claim 1 or 2, characterized in that, Step 2 includes: 2.

1. The original frequency count values ​​of the circuit activity collected in step 1 are processed by first-order differential processing using formula (1) to eliminate the physical characteristics of frequency count values ​​accumulating over time, and to extract the frequency change characteristics reflecting the instantaneous fluctuations of logic path delay: (1); in, and These represent the original frequency count values ​​obtained at adjacent sampling times. Indicates time The frequency differential characteristics are used to characterize the instantaneous changes in the intensity of circuit activity; 2.

2. The performance transaction characteristics, physical environment stress characteristics and differential frequency characteristics are standardized by formula (2) to eliminate the deviation interference caused by the inconsistency of dimensions and numerical scale of multi-source characteristics on the consistency of subsequent characteristic representation. (2); in, Indicates the first Side-channel characteristics at time The original value, and These represent the mean and standard deviation of this feature under baseline operating conditions, respectively. For the standardized version of the first Dimensional channel eigenvalues; 2.

3. The standardized eigenvalues ​​obtained in step 2.2 are concatenated into vectors according to formula (3) to construct a representation of the hardware at time t. The side-channel feature fingerprint vectors of the running state form the standardized feature space required for subsequent behavior modeling, which is expressed as follows: (3); in, The total dimension of the features. Indicates at time Constructed standardized side-channel feature fingerprint vector.

4. The method for online monitoring and tracing of AI accelerator hardware Trojans based on heterogeneous side-channel perception as described in claim 1 or 2, characterized in that, The process of step 3 is as follows: 3.

1. Input the standardized feature fingerprint space described in step 2 into the encoder network, use multi-layer long short-term memory units to nonlinearly compress the temporal evolution characteristics of the side-channel fingerprint, update the state of the internal memory units according to formula (4), and combine the output gate signal to obtain a low-dimensional hidden behavioral feature vector through formula (5). ; (4); (5); in, and Representing time respectively With time The state of the memory unit, , , These represent the gate control signals for the forget gate, input gate, and output gate, respectively. Candidate memory cell state, This represents element-wise multiplication. The hyperbolic tangent activation function is used; the encoder network models the temporal characteristics of the side-channel fingerprint through gating mechanism and nonlinear mapping, realizing a stable mapping from the high-dimensional original fingerprint sequence to the low-dimensional behavioral feature space; 3.

2. Utilize spatial attention mechanism to process the latent behavioral feature vector output in step 3.1 Physical feature recalibration is performed, and the extreme values ​​of the feature distribution are extracted by global average pooling and global max pooling operators. Then, a weight matrix reflecting spatial saliency is generated by convolution operation according to formula (6). ; (6); in, For activation function, This represents a convolution operation with a kernel size of . and These represent global average pooling and global max pooling operations, respectively; through the weight matrix Enhance the perception weight of local feature dimensions affected by abnormal logic triggers; 3.

3. The attention-weighted behavioral feature vector is predicted and reconstructed using a decoder network, and the reconstructed fingerprint is obtained according to formula (7). Furthermore, formula (8) is used to calculate the L2 norm residual between the original feature fingerprint described in step 1, and the reconstruction error score is obtained to quantify the degree to which the current hardware operation behavior deviates from the normal behavior benchmark. ; (7); (8); in, This represents the decoding mapping function. For the first in the reconstructed vector 1D feature components.

5. The method for online monitoring and tracing of AI accelerator hardware Trojans based on heterogeneous side-channel perception as described in claim 4, characterized in that, The process of step 4 is as follows: 4.

1. The real-time reconstruction error score output from 3.

3. The input environment perception module uses a moving average update algorithm to track the environmental background benchmark in real time, and calculates the time using formula (9). Environmental offset reference value To sense and extract the slow drift of reconstruction error caused by non-malicious environmental stresses such as chip thermal drift and power supply ripple; (9); in, This is a preset smoothing factor used to adjust the sensitivity of the benchmark update to the rate of environmental change. 4.

2. Environmental offset baseline values ​​obtained from 4.1 Dynamic correction of the detection threshold is carried out. The real-time detection threshold under the current working condition is calculated by combining the historical statistical characteristics of the reconstruction error with formula (10). This enables online filtering of background noise interference and maintains robustness in anomaly detection. (10); in, As the confidence factor, The historical standard deviation of the reconstruction error score under normal operating conditions; 4.

3. Calculate the real-time reconstruction error score output from step 3.

3. The real-time detection threshold calculated in step 4.2 The comparison is performed to obtain the corrected hardware behavior anomaly representation value, which is then used as the decision input for determining the Trojan triggering behavior and performing regional tracing in step 5.

6. The method for online monitoring and tracing of AI accelerator hardware Trojans based on heterogeneous side-channel perception as described in claim 5, characterized in that, The process of step 5 is as follows: 5.

1. Real-time reconstruction error score based on the output of 3.3 The real-time detection threshold calculated in section 4.2 Perform logical comparison and generate an anomaly detection signal according to formula (11). ; When the real-time reconstruction error exceeds the adaptive threshold boundary under the current operating conditions, the system determines that the hardware Trojan behavior has been activated and triggers an abnormal alarm signal, thereby achieving autonomous Trojan identification without the need for external gold model auditing intervention. (11); 5.

2. After detecting a hardware anomaly alarm signal, the proportion of the deviation contribution of each feature dimension in the multi-source side channel feature space to the current reconstruction error is quantified by formula (12) in order to identify the core physical feature source that causes the behavior reconstruction failure; Standardize the original fingerprint by calculating each dimension. With the corresponding reconstructed fingerprint The proportion of the absolute deviation between the two residuals to the total residuals is used to determine the feature dimension index that contributes the most to the overall anomaly score. (12); in, Indicates the first Each side channel feature dimension at time... Contribution weight; 5.

3. Using formula (13) and combined with the preset topological mapping table between the on-chip sensor physical layout and the accelerator logic operator level, the highest contribution feature identified in step 4.2 is indexed. Mapped to specific physical logic regions or operator functional modules of FPGA chips; through spatial tracing of abnormal dimensions, the precise physical location of hardware Trojan implantation in the contaminated third-party IP kernel can be achieved; (13); in, The function is used to extract the feature index with the highest contribution weight. This is a predefined topological mapping function between feature indices and physical logical regions. This is the final physical location information of the Trojan horse.