Publication Date
2024
Document Type
Thesis
Committee Members
Fathi Amsaad, Ph.D. (Advisor); Lingwei Chen, Ph.D. (Committee Member); Vincent Schmidt, Ph.D. (Committee Member); Temesgen Kebede, Ph.D. (Committee Member)
Degree Name
Master of Science in Cyber Security (M.S.C.S.)
Abstract
Semiconductor microelectronics Integrated Circuits (ICs) are increasingly integrated into critical life applications including medical, aerospace, and Internet of things. Their increasing importance as a technology gave rise to critical concerns regarding their security. This has led to the focus of the research community on hardware Trojans, which are malicious modifications to the ICs with undesirable outcomes. Their detection is becoming increasingly critical, with many researchers proposing methods to do so such as reverse engineering, logic testing, and side-channel analysis. Many of these proposals utilize machine learning methods to detect these malicious modifications with high accuracy and confidence. However, machine learning methods are still vulnerable to adversarial attacks, designed specifically to force machine learning models into providing false results. These attacks can be leveraged by interested parties to circumvent the detection of hardware Trojan detection machine learning models. This study tested a set of hardware Trojan detection machine-learning models under adversarial conditions and evaluated their resilience to adversarial attacks, comparing supervised and unsupervised algorithms, in addition to comparing models trained on low-dimensional data and models trained on high-dimensional data. Afterward, this study proposes Adversarial Training as a method to mitigate the model's vulnerability to adversarial attacks, also comparing the effects of the defense strategy between supervised and unsupervised algorithms in addition to models trained on low-dimensional and high-dimensional data. The study showed that all of the hardware Trojan detection models were vulnerable to adversarial attacks to varying degrees with an average success rate of 81%, with some models being highly affected by the attack and letting 96% of the adversarial samples circumvent detection and some models showed high resilience with an attack success rate as low as 20%. All models (supervised and unsupervised) trained on high-dimensional data showed high resilience to adversarial attacks with an average attack success rate of 32% and showed an average increased robustness of 21% after adversarial training. However, models trained on low-dimensional data showed varying degrees of resilience with unsupervised models showing low resilience to adversarial attacks with an average attack success rate of 47% as in some cases they let 96% of adversarial samples circumvent their detection. However, supervised hardware Trojan detection models also showed a high attack success rate compared to models trained on high-dimensional data with an average attack success rate of 61%, with the lowest success rate being 74%. Finally, adversarial training showed the effect of decreasing the resiliency of all unsupervised models and most supervised models with only 2 algorithms showing an increase in resilience with an average decrease of 12%.
Page Count
166
Department or Program
Department of Computer Science and Engineering
Year Degree Awarded
2024
Copyright
Copyright 2024, all rights reserved. My ETD will be available under the "Fair Use" terms of copyright law.
ORCID ID
0009-0000-1337-4119X
