Publication Date

2024

Document Type

Thesis

Committee Members

Fathi Amsaad, Ph.D. (Advisor); Lingwei Chen, Ph.D. (Committee Member); Vincent Schmidt, Ph.D. (Committee Member); Temesgen Kebede, Ph.D. (Committee Member)

Degree Name

Master of Science in Cyber Security (M.S.C.S.)

Abstract

Semiconductor microelectronics Integrated Circuits (ICs) are increasingly integrated into critical life applications including medical, aerospace, and Internet of things. Their increasing importance as a technology gave rise to critical concerns regarding their security. This has led to the focus of the research community on hardware Trojans, which are malicious modifications to the ICs with undesirable outcomes. Their detection is becoming increasingly critical, with many researchers proposing methods to do so such as reverse engineering, logic testing, and side-channel analysis. Many of these proposals utilize machine learning methods to detect these malicious modifications with high accuracy and confidence. However, machine learning methods are still vulnerable to adversarial attacks, designed specifically to force machine learning models into providing false results. These attacks can be leveraged by interested parties to circumvent the detection of hardware Trojan detection machine learning models. This study tested a set of hardware Trojan detection machine-learning models under adversarial conditions and evaluated their resilience to adversarial attacks, comparing supervised and unsupervised algorithms, in addition to comparing models trained on low-dimensional data and models trained on high-dimensional data. Afterward, this study proposes Adversarial Training as a method to mitigate the model's vulnerability to adversarial attacks, also comparing the effects of the defense strategy between supervised and unsupervised algorithms in addition to models trained on low-dimensional and high-dimensional data. The study showed that all of the hardware Trojan detection models were vulnerable to adversarial attacks to varying degrees with an average success rate of 81%, with some models being highly affected by the attack and letting 96% of the adversarial samples circumvent detection and some models showed high resilience with an attack success rate as low as 20%. All models (supervised and unsupervised) trained on high-dimensional data showed high resilience to adversarial attacks with an average attack success rate of 32% and showed an average increased robustness of 21% after adversarial training. However, models trained on low-dimensional data showed varying degrees of resilience with unsupervised models showing low resilience to adversarial attacks with an average attack success rate of 47% as in some cases they let 96% of adversarial samples circumvent their detection. However, supervised hardware Trojan detection models also showed a high attack success rate compared to models trained on high-dimensional data with an average attack success rate of 61%, with the lowest success rate being 74%. Finally, adversarial training showed the effect of decreasing the resiliency of all unsupervised models and most supervised models with only 2 algorithms showing an increase in resilience with an average decrease of 12%.

Page Count

166

Department or Program

Department of Computer Science and Engineering

Year Degree Awarded

2024

ORCID ID

0009-0000-1337-4119X


Share

COinS