A cross-layer threat model for automated AI accelerator design platforms: leveraging hardware Trojans and bit-level parameter attacks
摘要
Automated AI-accelerator generators deliver rapid, low-cost deployments but open a new attack surface that spans software, exploration heuristics, and RTL synthesis. We propose a cross-layer threat model in which a malicious insider injects hardware Trojans (HTs) and bit-level parameter faults during the design-time optimisation loop. A lightweight Cross-layer Sensitive Filter Exploration (C-SFE) algorithm pinpoints a single kernel per layer and flips fewer than