<p>Automated AI-accelerator generators deliver rapid, low-cost deployments but open a new attack surface that spans software, exploration heuristics, and RTL synthesis. We propose a cross-layer threat model in which a malicious insider injects <i>hardware Trojans (HTs)</i> and bit-level parameter faults during the design-time optimisation loop. A lightweight <i>Cross-layer Sensitive Filter Exploration (C-SFE)</i> algorithm pinpoints a single kernel per layer and flips fewer than <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="41870_2025_2855_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="33" /> </InlineMediaObject> <EquationSource Format="TEX">\(10^{-4}\)</EquationSource> </InlineEquation>&#xa0;% of all weights, yet forces <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="41870_2025_2855_Article_IEq2.gif" Format="GIF" Height="13" Rendition="HTML" Resolution="72" Type="Linedraw" Width="35" /> </InlineMediaObject> <EquationSource Format="TEX">\(&gt;97\)</EquationSource> </InlineEquation>% targeted misclassifications on VGG-16, ResNet-18, and YOLOv8m-cls FPGA prototypes with <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="41870_2025_2855_Article_IEq3.gif" Format="GIF" Height="13" Rendition="HTML" Resolution="72" Type="Linedraw" Width="48" /> </InlineMediaObject> <EquationSource Format="TEX">\(&lt;0.35\)</EquationSource> </InlineEquation>% LUT overhead. The study highlights an urgent need for security verification inside accelerator generators and provides an open benchmark suite for future defences.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A cross-layer threat model for automated AI accelerator design platforms: leveraging hardware Trojans and bit-level parameter attacks

  • Apeksha Bhuekar

摘要

Automated AI-accelerator generators deliver rapid, low-cost deployments but open a new attack surface that spans software, exploration heuristics, and RTL synthesis. We propose a cross-layer threat model in which a malicious insider injects hardware Trojans (HTs) and bit-level parameter faults during the design-time optimisation loop. A lightweight Cross-layer Sensitive Filter Exploration (C-SFE) algorithm pinpoints a single kernel per layer and flips fewer than \(10^{-4}\)  % of all weights, yet forces \(>97\) % targeted misclassifications on VGG-16, ResNet-18, and YOLOv8m-cls FPGA prototypes with \(<0.35\) % LUT overhead. The study highlights an urgent need for security verification inside accelerator generators and provides an open benchmark suite for future defences.