EDBT 2026 Demo / reviewers in the wild / expert
Lilas Alrahis
dblp:214/6929 · also Lilas Al Rahis
· DBLP profile ↗
29ranked-venue papers
13as first author
27since 2021 · last 2026
0000-0001-9932-6833ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 24 · 12 first-author · 22 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: DeLink-Deceptive Link Generation for Circuit ObfuscationabstractLogic locking (LL) is a design-for-trust technique to thwart integrated circuit (IC) design piracy by inserting key-controlled Boolean gates into the gate-level netlist to hide circuit functionality and structure. However, recent machine learning (ML)-based attacks expose structural leakage in LL, recovering the correct connectivity and key. For example, the MuxLink attack transforms a locked circuit into a graph with missing connections and uses a graph neural network (GNN) to predict the true connections, breaking multiplexer (MUX)-based LL techniques previously assumed to be learning-resistant. We investigate traditional MUX-based LL and identify the conditions under which a GNN performs well, namely sub-circuit structures associated with correct key values. We then generate similar sub-circuits and associate them with incorrect key values, thereby reducing GNN performance. Our evaluation on the ISCAS-85 benchmarks shows a reduction in MuxLink attack accuracy of up to 57%, reaching 43% (lower than a random guess). Anania Temtim Cherkos, Praveen Karmakar, Lilas Alrahis |
AsiaCCS | 3 |
| 2026 | POSTER: Hector - An Agentic LLM Framework for Logic Locking
Prithwish Basu Roy, Akashdeep Saha, Lilas Alrahis, Johann Knechtel, Ozgur Sinanoglu, Ramesh Karri |
AsiaCCS | 3 |
| 2026 | Towards LLM-Based Reasoning for Gate-Level Netlist Tasks
Mueen Almasre, Lilas Alrahis |
VTS | 2 |
| 2025 | GLLaMoR: Graph-based Logic Locking by Large Language Models for Enhanced RobustnessabstractLogic locking protects integrated circuits (ICs) from design piracy. The idea is to insert key-controlled components, a.k.a. key-gates, to lock the IC’s functionality, where the correct key is the designer’s secret. The robustness of logic locking can be enhanced by carefully identifying best locations to insert key-gates, e.g., by analyzing the IC’s topology and lock parts with high impact on functional behaviour. Traditionally, the challenge of identifying critical locations relies on computationally-intensive graph traversal and design methods like fault analysis. The rise of large language models (LLMs), which have recently demonstrated proficiency also on complex graph data, presents an interesting opportunity to revisit this challenge. Here, we present GLLaMoR, a first-of-its-kind framework using LLMs on graph-based IC representations to identify critical locking locations. Through LLM performance evaluation and end-to-end case studies, we demonstrate that GLLaMoR paves the way for more effective and scalable logic locking. Akashdeep Saha, Prithwish Basu Roy, Johann Knechtel, Ramesh Karri, Ozgur Sinanoglu, Lilas Alrahis |
VTS | 6 |
| 2025 | On the Efficacy and Vulnerabilities of Logic Locking in Tree-Based Machine LearningabstractThe popularity and widespread usage of machine learning (ML) hardware have created challenges for its intellectual property (IP) protection. Logic locking is a widely used technique for IP protection but has received little attention in error-resilient applications such as ML hardware modules. This work investigates the effectiveness of logic locking when applied to tree-based ML circuits and reveals a critical vulnerability that undermines its effectiveness for single-label ML classifiers. We propose a logic locking scheme to eliminate the vulnerabilities in decision trees (DTs) and random forests (RFs) circuits. In our extensive simulation involving 16 DTs and 16 RFs, our solution consistently thwarts the vulnerability. We further evaluated the security of our approach by considering different obfuscation percentages and launching state-of-the-art oracle-less attacks on logic locking. Our method proves resilient, indicating that by fixing the identified vulnerability, we did not introduce new attack vectors. Further, our investigation indicates that DT/RF accelerators are significantly less vulnerable to oracle-less attacks compared to exact circuits. Overall, our work lays the foundation for future investigations into the effectiveness of logic locking for ML circuits. Brunno Abreu, Guilherme Paim, Lilas Alrahis, Paulo F. Flores, Ozgur Sinanoglu, Sergio Bampi, Hussam Amrouch |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2024 | HDCircuit: Brain-Inspired HyperDimensional Computing for Circuit RecognitionabstractCircuits possess a non-Euclidean representation, necessitating the encoding of their data structure (e.g., gate-level netlists) into fixed formats like vectors. This work is the first to propose brain-inspired hyperdimensional computing (HDC) for optimized circuit encoding. HDC does not require extensive training to encode a gate-level netlist into a hypervector and simplifies the similarity check between circuits from graph-based to the similarity between their hypervectors. We introduce a versatile HDC-based encoding method for circuit encoding. We demonstrate its effectiveness with the application of circuit recognition using ITC-99 and ISCAS-85 benchmarks. We maintain a 98.2% accuracy, even when the designs are obfuscated using logic locking. Paul R. Genssler, Lilas Alrahis, Ozgur Sinanoglu, Hussam Amrouch |
DATE | 2 |
| 2024 | Camo-DNN: Layer Camouflaging to Protect DNNs against Timing Side-Channel AttacksabstractExtracting the architecture of layers of a given deep neural network (DNN) through hardware-based side channels allows adversaries to steal its intellectual property and even launch powerful adversarial attacks on the target system. In this work, we propose Camo $D N N$, an obfuscation method for DNNs that forces all the layers in a given network to have similar execution traces, preventing attack models from differentiating between the layers. Towards this, Camo DNN performs various layer-obfuscation operations, e.g., layer branching layer deepening, etc., to alter the run-time traces while maintaining the functionality. Camo-DNN deploys an evolutionary algorithm to find the best combination of obfuscation operations in terms of maximizing the security level while maintaining a user-provided latency overhead budget Our experiments show that state-of-the-art side-channel architecture stealing attacks cannot extract the architecture of DNN protected by Camo-DNN accurately. Further, we highlight that the adversarial attack on our obfuscated DNNs are unsuccessful. Mahya Morid Ahmadi, Lilas Alrahis, Ozgur Sinanoglu, Muhammad Shafique 0001 |
IOLTS | 2 |
| 2024 | The Impact of Logic Synthesis and Technology Mapping on Logic Locking SecurityabstractLogic locking is a design-for-trust solution, safe-guarding the intellectual property of integrated circuits within the global semiconductor supply chain. Traditionally, logic syn-thesis has been relied upon to enhance the security of logic locking. However, recent research has unveiled vulnerabilities inherent in this approach, as logic synthesis is not security-aware by design. On the other hand, state-of-the-art logic-locking techniques leveraging specific locking structures, such as routing networks, were initially presumed secure by design. However, the optimization capabilities of logic synthesis have been shown to compromise these structures, diminishing their security assurances and rendering logic locking vulnerable to attacks. This ongoing interplay between logic locking and logic synthesis necessitates thorough reevaluation. This paper discusses the vulnerabilities and challenges that have emerged at the intersection of logic locking and logic synthesis, offering insights into future research directions aimed at mitigating these issues. Lilas Alrahis, Mohammed Nabeel Thari Moopan, Johann Knechtel, Ozgur Sinanoglu |
VLSI-SoC | 1 |
| 2024 | Graph Attention Networks to Identify the Impact of Transistor Degradation on Circuit ReliabilityabstractReliability is one of the key concerns in circuit design. The circuit must be able to tolerate transistor degradation to sustain reliability against timing failure. Whether a transistor is degraded due to noise, aging, or poor manufacturing, a circuit must uphold a timing error-free functionality over its entire projected lifetime. Transistors are hardened (designed stronger than necessary) to tolerate these degradations. However, hardening (e.g., widening the transistors) comes at the cost of additional area and power. Hence, it is necessary to identify and selectively harden specific transistors within a circuit. In this work, transistors that prolong a circuit’s delay when they are degraded are termed “susceptible”, and thus, are to be hardened. Identifying the susceptible transistors within a circuit is a complex task, for example, Monte Carlo circuit simulations require days to identify susceptible transistors in a single circuit. Consequently, current solutions are costly in terms of time and limited in their application. Instead, machine learning (ML) can offer a fast (inference in seconds) and universal (applicable to unseen circuits) alternative. However, traditional ML techniques struggle with inference on topology-based problems, while recent graph neural networks (GNNs) excel in these applications. Therefore, this work presents the first ML to classify susceptible transistors with GNNs. We use GNNs, specifically Graph Attention Networks (GAT), because the topology of the cell strongly affects how each transistor degradation affects performance. For instance, series-connected transistors amplify their impact, while parallel-connected ones can offset each other’s influence. Our GAT-based approach employs a heterogeneous graph in combination with GAT’s attention mechanism to capture the circuit’s topology and its impact on the analysis. Our evaluation demonstrates the capability of our approach to classifying transistors according to their impact within the ASAP7 standard cell library’s standard cells in mere 0.04 s (compared to days of Monte Carlo simulation time) while achieving 80.4% accuracy on unseen circuits. Tarek Mohamed, Victor M. van Santen, Lilas Alrahis, Ozgur Sinanoglu, Hussam Amrouch |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2023 | Graph Neural Networks: A Powerful and Versatile Tool for Advancing Design, Reliability, and Security of ICsabstractGraph neural networks (GNNs) have pushed the state-of-the-art (SOTA) for performance in learning and predicting on large-scale data present in social networks, biology, etc. Since integrated circuits (ICs) can naturally be represented as graphs, there has been a tremendous surge in employing GNNs for machine learning (ML)-based methods for various aspects of IC design. Given this trajectory, there is a timely need to review and discuss some powerful and versatile GNN approaches for advancing IC design. Lilas Alrahis, Johann Knechtel, Ozgur Sinanoglu |
ASP-DAC | 1 |
| 2023 | ALMOST: Adversarial Learning to Mitigate Oracle-less ML Attacks via Synthesis TuningabstractOracle-less machine learning (ML) attacks have broken various logic locking schemes. Regular synthesis, which is tailored for area-power-delay optimization, yields netlists where key-gate localities are vulnerable to learning. Thus, we call for security-aware logic synthesis. We propose ALMOST, a framework for adversarial learning to mitigate oracle-less ML attacks via synthesis tuning. ALMOST uses a simulated-annealing-based synthesis recipe generator, employing adversarially trained models that can predict state-of-the-art attacks’ accuracies over wide ranges of recipes and key-gate localities. Experiments on ISCAS benchmarks confirm the attacks’ accuracies drops to around 50% for ALMOST-synthesized circuits, all while not undermining design optimization. Animesh Basak Chowdhury, Lilas Alrahis, Luca Collini, Johann Knechtel, Ramesh Karri, Siddharth Garg, Ozgur Sinanoglu, Benjamin Tan 0001 |
DAC | 2 |
| 2023 | ShapeShifter: Protecting FPGAs from Side-Channel Attacks with Isofunctional Heterogeneous ModulesabstractCloud service providers are interested in deploying multi-tenant Field-Programmable Gate Arrays (FPGAs) for virtualized computation platforms. A primary concern towards such shared FPGA platforms is ensuring the security of critical applications (such as encryption cores) against hardware-based attacks, such as remote power Side-Channel Attacks (SCAs) intended to steal secret assets like encryption keys. To address this issue, we propose ShapeShifter, a novel defense methodology based on design diversity that generates isofunctional variants of the target application at the design stage using different synthesis, placement, and routing procedures. ShapeShifter leverages the dynamic partial reconfiguration feature of modern FPGAs to exchange the variants at run-time, causing dynamic variations in the power trace (vertical obfuscation) and introducing misalignment in the time domain (horizontal obfuscation) to thwart SCAs. ShapeShifter successfully thwarts the Correlation Power Analysis (CPA) attack on an Advanced Encryption Standard (AES) implementation, ensuring unsuccessful key byte recovery for up to$10\times$more traces. It also decreases the CPA value by$0.69\times$, reducing the attacker's confidence in key recovery. Mahya Morid Ahmadi, Lilas Alrahis, Ozgur Sinanoglu, Muhammad Shafique 0001 |
IOLTS | 2 |
| 2023 | TrojanSAINT: Gate-Level Netlist Sampling-Based Inductive Learning for Hardware Trojan DetectionabstractWe propose TrojanSAINT, a graph neural network (GNN)-based hardware Trojan (HT) detection scheme working at the gate level. Unlike prior GNN-based art, TrojanSAINT enables both pre-/post-silicon HT detection. TrojanSAINT leverages a sampling-based GNN framework to detect and also localize HTs. For practical validation, TrojanSAINT achieves on average (oa) 78% true positive rate (TPR) and 85% true negative rate (TNR), respectively, on various TrustHub HT benchmarks. For best-case validation, TrojanSAINT even achieves 98% TPR and 96% TNR oa. TrojanSAINT outperforms related prior works and baseline classifiers. We release our source codes and result artifacts. Hazem Lashen, Lilas Alrahis, Johann Knechtel, Ozgur Sinanoglu |
ISCAS | 2 |
| 2023 | FPGA-Patch: Mitigating Remote Side-Channel Attacks on FPGAs using Dynamic Patch GenerationabstractWe propose FPGA-Patch, the first-of-its-kind defense that leverages automated program repair concepts to thwart power side-channel attacks on cloud FPGAs. FPGA-Patch generates isofunctional variants of the target hardware by injecting faults and finding transformations that eliminate failure. The obtained variants display different hardware characteristics, ensuring a maximal diversity in power traces once dynamically swapped at run-time. Yet, FPGA-Patch forces the variants to have enough similarity, enabling bitstream compression and minimizing dynamic exchange costs. Considering AES running on AMD/Xilinx FPGA, FPGA-Patch increases the attacker's effort by three orders of magnitude, while preserving the performance of AES and a minimal area overhead of 14.2%. Mahya Morid Ahmadi, Lilas Alrahis, Ozgur Sinanoglu, Muhammad Shafique 0001 |
ISLPED | 2 |
| 2023 | Security Closure of IC Layouts Against Hardware TrojansabstractDue to cost benefits, supply chains of integrated circuits (ICs) are largely outsourced nowadays. However, passing ICs through various third-party providers gives rise to many threats, like piracy of IC intellectual property or insertion of hardware Trojans, i.e., malicious circuit modifications. Qijing Wang, Bangqi Fu, Shui Jiang, Xiaopeng Zhang 0009, Lilas Alrahis, Ozgur Sinanoglu, Johann Knechtel, Tsung-Yi Ho, Evangeline F. Y. Young |
ISPD | 6 |
| 2023 | Graph Neural Networks for Hardware Vulnerability Analysis - Can you Trust your GNN?abstractThe participation of third-party entities in the globalized semiconductor supply chain introduces potential security vulnerabilities, such as intellectual property piracy and hardware Trojan (HT) insertion. Graph neural networks (GNNs) have been employed to address various hardware security threats, owing to their superior performance on graph-structured data, such as circuits. However, GNNs are also susceptible to attacks.This work examines the use of GNNs for detecting hardware threats like HTs and their vulnerability to attacks. We present BadGNN, a backdoor attack on GNNs that can hide HTs and evade detection with a 100% success rate through minor circuit perturbations. Our findings highlight the need for further investigation into the security and robustness of GNNs before they can be safely used in security-critical applications. Lilas Alrahis, Ozgur Sinanoglu |
VTS | 1 |
| 2023 | $\tt{PoisonedGNN}$: Backdoor Attack on Graph Neural Networks-Based Hardware Security SystemsabstractGraph neural networks (GNNs) have shown great success in detecting intellectual property (IP) piracy and hardware Trojans (HTs). However, the machine learning community has demonstrated that GNNs are susceptible to data poisoning attacks, which result in GNNs performing abnormally on graphs with pre-defined backdoor triggers (realized using crafted subgraphs). Thus, it is imperative to ensure that the adoption of GNNs should not introduce security vulnerabilities in critical security frameworks. Existing backdoor attacks on GNNs generate random subgraphs with specific sizes/densities to act as backdoor triggers. However, for Boolean circuits, backdoor triggers cannot be randomized since the added structures should not affect the functionality of a design. We explore this threat and developPoisonedGNNas the first backdoor attack on GNNs in the context of hardware design. We design and inject backdoor triggers into the register-transfer- or the gate-level representation of a given design without affecting the functionality to evade some GNN-based detection procedures. To demonstrate the effectiveness of PoisonedGNN, we consider two case studies: (i) Hiding HTs and (ii) IP piracy. Our experiments on TrustHub datasets demonstrate that PoisonedGNN can hide HTs and IP piracy from advanced GNN-based detection platforms with an attack success rate of up to 100%. Lilas Alrahis, Satwik Patnaik, Muhammad Abdullah Hanif, Muhammad Shafique 0001, Ozgur Sinanoglu |
IEEE Trans. Computers | 1 |
| 2023 | Titan: Security Analysis of Large-Scale Hardware Obfuscation Using Graph Neural NetworksabstractHardware obfuscation is a prominent design-for-trust solution that thwarts intellectual property (IP) piracy and reverse-engineering of integrated circuits (ICs). Researchers have proposed several large-scale obfuscation techniques that achieve high output corruption—thus offering resilience against seminal attacks along with acceptable power, performance, and area overheads. However, the research community has primarily evaluated hardware obfuscation on relatively small scales of obfuscation (i.e., a fixed number of obfuscated components). Moreover, prior art caters toward specific schemes based either on gate obfuscation or interconnect obfuscation, i.e., two prominent types of hardware obfuscation. The former shortcoming suggests focusing on large-scale obfuscation schemes, and the latter suggests the need for a holistic assessment framework. In this work, we propose Titan, a holistic framework considering large-scale gate and interconnect obfuscation schemes. More specifically, we propose a graph neural network (GNN)-based attack framework that is trained to exploit structural and functional properties of any secured circuit to recover its obfuscated components. We evaluate Titan on various obfuscation schemes, considering selected ITC-99 benchmarks with up to 50% obfuscation scale, i.e., up to 21,326 obfuscated components. We observe a substantial information leakage through structural and functional properties of secured designs even for large-scale obfuscation. We quantify the information leakage in two ways: first, an average reduction of Hamming distance (HD, a well-established metric for attack evaluation) by 23.27 and 16.19 percentage points over the baseline of random guessing for gate and interconnect obfuscation, respectively; second, an average recovery of 63.40% and 77.94% of obfuscated components for gate and interconnect obfuscation, respectively. Importantly, these results are superior to six state-of-the-art attacks. We will open-source our framework and associated artifacts to enable reproducibility and foster future work. Likhitha Mankali, Lilas Alrahis, Satwik Patnaik, Johann Knechtel, Ozgur Sinanoglu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | MuxLink: Circumventing Learning-Resilient MUX-Locking Using Graph Neural Network-based Link PredictionabstractLogic locking has received considerable interest as a prominent technique for protecting the design intellectual property from untrusted entities, especially the foundry. Recently, machine learning (ML)-based attacks have questioned the security guarantees of logic locking, and have demonstrated considerable success in deciphering the secret key without relying on an oracle, hence, proving to be very useful for an adversary in the fab. Such ML-based attacks have triggered the development of learning-resilient locking techniques. The most advanced state-of-the-art deceptive MUX-based locking (D-MUX) and the symmetric MUX-based locking techniques have recently demonstrated resilience against existing ML-based attacks. Both defense techniques obfuscate the design by inserting key-controlled MUX logic, ensuring that all the secret inputs to the MUXes are equiprobable. In this work, we show that these techniques primarily introduce local and limited changes to the circuit without altering the global structure of the design. By leveraging this observation, we propose a novel graph neural network (GNN)-based link prediction attack, MuxLink, that successfully breaks both the D-MUX and symmetric MUX-locking techniques, relying only on the underlying structure of the locked design, i.e., in an oracle-less setting. Our trained GNN model learns the structure of the given circuit and the composition of gates around the non-obfuscated wires, thereby generating meaningful link embeddings that help decipher the secret inputs to the MUXes. The proposed MuxLink achieves key prediction accuracy and precision up to 100% on D-MUX and symmetric MUX-locked ISCAS-85 and ITC-99 benchmarks, fully unlocking the designs. We open-source MuxLink [1]. Lilas Alrahis, Satwik Patnaik, Muhammad Shafique 0001, Ozgur Sinanoglu |
DATE | 1 |
| 2022 | Embracing Graph Neural Networks for Hardware SecurityabstractGraph neural networks (GNNs) have attracted increasing attention due to their superior performance in deep learning on graph-structured data. GNNs have succeeded across various domains such as social networks, chemistry, and electronic design automation (EDA). Electronic circuits have a long history of being represented as graphs, and to no surprise, GNNs have demonstrated state-of-the-art performance in solving various EDA tasks. More importantly, GNNs are now employed to address several hardware security problems, such as detecting intellectual property (IP) piracy and hardware Trojans (HTs), to name a few. Lilas Alrahis, Satwik Patnaik, Muhammad Shafique 0001, Ozgur Sinanoglu |
ICCAD | 1 |
| 2022 | AppGNN: Approximation-Aware Functional Reverse Engineering Using Graph Neural NetworksabstractThe globalization of the Integrated Circuit (IC) market is attracting an ever-growing number of partners, while remarkably lengthening the supply chain. Thereby, security concerns, such as those imposed by functional Reverse Engineering (RE), have become quintessential. RE leads to disclosure of confidential information to competitors, potentially enabling the theft of intellectual property. Traditional functional RE methods analyze a given gate-level netlist through employing pattern matching towards reconstructing the underlying basic blocks, and hence, reverse engineer the circuit's function. Tim Bücher, Lilas Alrahis, Guilherme Paim, Sergio Bampi, Ozgur Sinanoglu, Hussam Amrouch |
ICCAD | 2 |
| 2022 | NeuroUnlock: Unlocking the Architecture of Obfuscated Deep Neural NetworksabstractThe advancements of deep neural networks (DNNs) have led to their deployment in diverse settings, including safety and security-critical applications. As a result, the characteristics of these models (e.g., the architecture of layers and weight values/distributions) have become sensitive intellectual properties that require protection from malicious users. Extracting the architecture of a DNN through leaky side-channels (e.g., memory access) allows adversaries to (i) clone the model (i.e., build proxy models with similar accuracy profiles), and (ii) craft adversarial attacks. DNN obfuscation thwarts side-channel-based architecture stealing (SCAS) attacks by altering the run-time traces of a given DNN while preserving its functionality. In this work, we expose the vulnerability of state-of-the-art DNN obfuscation methods (based on predictable and reversible modifications employed in a given DNN architecture) to these attacks. We present NeuroUnlock, a novel SCAS attack against obfuscated DNNs. Our NeuroUnlock employs a sequence-to-sequence model that learns the obfuscation procedure and automatically reverts it, thereby recovering the original DNN architecture. We demonstrate the effectiveness of NeuroUnlock by recovering the architecture of 200 randomly generated and obfuscated DNNs running on the Nvidia RTX 2080 TI graphics processing unit (GPU). Moreover, NeuroUnlock recovers the architecture of various other obfuscated (and publicly available) DNNs, such as the VGG-11, VGG-13, ResNet-20, and ResNet-32 networks. After recovering the architecture, NeuroUnlock automatically builds a near-equivalent DNN with only a 1.4% drop in the testing accuracy. We further show that launching a subsequent adversarial attack on the recovered DNNs boosts the success rate of the adversarial attack by 51.7% in average compared to launching it on the obfuscated versions. Additionally, we propose a novel methodology for DNN obfuscation, ReDLock, which eradicates the deterministic nature of the obfuscation and achieves 2.16 x more resilience to the NeuroUnlock attack. We release the NeuroUnlock and the ReDLock as open-source frameworks 1 1 https://github.com/Mahya-Ahmadi/NeuroUnlock. Mahya Morid Ahmadi, Lilas Alrahis, Alessio Colucci, Ozgur Sinanoglu, Muhammad Shafique 0001 |
IJCNN | 2 |
| 2022 | GNN4REL: Graph Neural Networks for Predicting Circuit Reliability DegradationabstractProcess variations and device aging impose profound challenges for circuit designers. Without a precise understanding of the impact of variations on the delay of circuit paths, guardbands, which keep timing violations at bay, cannot be correctly estimated. This problem is exacerbated for advanced technology nodes, where transistor dimensions reach atomic levels and established margins are severely constrained. Hence, traditional worst-case analysis becomes impractical, resulting in intolerable performance overheads. Contrarily, process-variation/aging-aware static timing analysis (STA) equips designers with accurate statistical delay distributions. Timing guardbands that are small, yet sufficient, can then be effectively estimated. However, such analysis is costly as it requires intensive Monte-Carlo simulations. Further, it necessitates access to confidential physics-based aging models to generate the standard-cell libraries required for STA. In this work, we employ graph neural networks (GNNs) to accurately estimate the impact of process variations and device aging on the delay of any path within a circuit. Our proposed GNN4REL framework empowers designers to perform rapid and accurate reliability estimations without accessing transistor models, standard-cell libraries, or even STA; these components are all incorporated into the GNN model via training by the foundry. Specifically, GNN4REL is trained on a FinFET technology model that is calibrated against industrial 14-nm measurement data. Through our extensive experiments on EPFL and ITC-99 benchmarks, as well as RISC-V processors, we successfully estimate delay degradations of all paths—notably within seconds—with a mean absolute error down to 0.01 percentage points. Lilas Alrahis, Johann Knechtel, Florian Klemme, Hussam Amrouch, Ozgur Sinanoglu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2022 | GNN-RE: Graph Neural Networks for Reverse Engineering of Gate-Level NetlistsabstractThis work introduces a generic, machine learning (ML)-based platform for functional reverse engineering (RE) of circuits. Our proposed platformGNN-REleverages the notion of graph neural networks (GNNs) to: 1) represent and analyze flattened/unstructured gate-level netlists; 2) automatically identify the boundaries between the modules or subcircuits implemented in such netlists; and 3) classify the subcircuits based on their functionalities. For GNNs in general, each graph node is tailored to learn about its own features and its neighboring nodes, which is a powerful approach for the detection of any kind of subgraphs of interest. ForGNN-RE, in particular, each node represents a gate and is initialized with a feature vector that reflects on the functional and structural properties of its neighboring gates.GNN-REalso learns the global structure of the circuit, which facilitates identifying the boundaries between subcircuits in a flattened netlist. Initially, to provide high-quality data for training ofGNN-RE, we deploy a comprehensive dataset of foundational designs/components with differing functionalities, implementation styles, bit widths, and interconnections.GNN-REis then tested on the unseen shares of this custom dataset, as well as the EPFL benchmarks, the ISCAS-85 benchmarks, and the 74X series benchmarks.GNN-REachieves an average accuracy of 98.82% in terms of mapping individual gates to modules, all without any manual intervention or postprocessing. We also release our code and source data. Lilas Alrahis, Abhrajit Sengupta, Johann Knechtel, Satwik Patnaik, Hani Saleh, Baker Mohammad, Mahmoud Al-Qutayri, Ozgur Sinanoglu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | GNNUnlock: Graph Neural Networks-based Oracle-less Unlocking Scheme for Provably Secure Logic LockingabstractLogic locking is a holistic design-for-trust technique that aims to protect the design intellectual property (IP) from untrustworthy entities throughout the supply chain. Functional and structural analysis-based attacks successfully circumvent state-of-the-art, provably secure logic locking (PSLL) techniques. However, such attacks are not holistic and target specific implementations of PSLL. Automating the detection and subsequent removal of protection logic added by PSLL while accounting for all possible variations is an open research problem. In this paper, we propose GNNUnlock, the first-of-its-kind oracle-less machine learning-based attack on PSLL that can identify any desired protection logic without focusing on a specific syntactic topology. The key is to leverage a well-trained graph neural network (GNN) to identify all the gates in a given locked netlist that belong to the targeted protection logic, without requiring an oracle. This approach fits perfectly with the targeted problem since a circuit is a graph with an inherent structure and the protection logic is a sub-graph of nodes (gates) with specific and common characteristics. GNNs are powerful in capturing the nodes' neighborhood properties, facilitating the detection of the protection logic. To rectify any misclassifications induced by the GNN, we additionally propose a connectivity analysis-based post-processing algorithm to successfully remove the predicted protection logic, thereby retrieving the original design. Our extensive experimental evaluation demonstrates that GNNUnlock is 99.24% - 100% successful in breaking various benchmarks locked using stripped-functionality logic locking [1], tenacious and traceless logic locking [2], and Anti-SAT [3]. Our proposed post-processing enhances the detection accuracy, reaching 100% for all of our tested locked benchmarks. Analysis of the results corroborates that GNNUnlock is powerful enough to break the considered schemes under different parameters, synthesis settings, and technology nodes. The evaluation further shows that GNNUnlock successfully breaks corner cases where even the most advanced state-of-the-art attacks [4], [5] fail. We also open source our attack framework [6]. Lilas Alrahis, Satwik Patnaik, Faiq Khalid, Muhammad Abdullah Hanif, Hani Saleh, Muhammad Shafique 0001, Ozgur Sinanoglu |
DATE | 1 |
| 2021 | UNTANGLE: Unlocking Routing and Logic Obfuscation Using Graph Neural Networks-based Link PredictionabstractLogic locking aims to prevent intellectual property (IP) piracy and unauthorized overproduction of integrated circuits (ICs). However, initial logic locking techniques were vulnerable to the Boolean satisfiability (SAT)-based attacks. In response, researchers proposed various SAT-resistant locking techniques such as point function-based locking and symmetric interconnection (SAT-hard) obfuscation. We focus on the latter since point function-based locking suffers from various structural vulnerabilities. The SAT-hard logic locking technique, InterLock [1], achieves a unified logic and routing obfuscation that thwarts state-of-the-art attacks on logic locking. In this work, we propose a novel link prediction-based attack, UNTANGLE, that successfully breaks InterLock in an oracle-less setting without having access to an activated IC (oracle). Since InterLock hides selected timing paths in key-controlled routing blocks, UNTANGLE reveals the gates and interconnections hidden in the routing blocks upon formulating this task as a link prediction problem. The intuition behind our approach is that ICs contain a large amount of repetition and reuse cores. Hence, UNTANGLE can infer the hidden timing paths by learning the composition of gates in the observed locked netlist or a circuit library leveraging graph neural networks. We show that circuits withstanding SAT-based and other attacks can be unlocked in seconds with 100% precision using UNTANGLE in an oracle-less setting. UNTANGLE is a generic attack platform (which we also open source [2]) that applies to multiplexer (MUX)-based obfuscation, as demonstrated through our experiments on ISCAS-85 and ITC-99 benchmarks locked using InterLock and random MUX-based locking. Lilas Alrahis, Satwik Patnaik, Muhammad Abdullah Hanif, Muhammad Shafique 0001, Ozgur Sinanoglu |
ICCAD | 1 |
| 2021 | UNSAIL: Thwarting Oracle-Less Machine Learning Attacks on Logic LockingabstractLogic locking aims to protect the intellectual property (IP) of integrated circuit (IC) designs throughout the globalized supply chain. The SAIL attack, based on tailored machine learning (ML) models, circumvents combinational logic locking with high accuracy and is amongst the most potent attacks as it does not require a functional IC acting as an oracle. In this work, we propose UNSAIL, a logic locking technique that inserts key-gate structures with the specific aim to confuse ML models like those used in SAIL. More specifically, UNSAIL serves to prevent attacks seeking to resolve the structural transformations of synthesis-induced obfuscation, which is an essential step for logic locking. Our approach is generic; it can protect any local structure of key-gates against such ML-based attacks in an oracle-less setting. We develop a reference implementation for the SAIL attack and launch it on both traditionally locked and UNSAIL-locked designs. For SAIL, two ML models have been proposed (which we implement accordingly), namely a change-prediction model and a reconstruction model; the change-prediction model is used to determine which key-gate structures to restore using the reconstruction model. Our study on benchmarks ranging from the ISCAS-85 and ITC-99 suites to the OpenRISC Reference Platform System-on-Chip (ORPSoC) confirms that UNSAIL degrades the accuracy of the change-prediction model and the reconstruction model by an average of 20.13 and 17 percentage points (pp), respectively. When the aforementioned models are combined, which is the most powerful scenario for SAIL, UNSAIL reduces the attack accuracy of SAIL by an average of 11pp. We further demonstrate that UNSAIL thwarts other oracle-less attacks, i.e., SWEEP and the redundancy attack, indicating the generic nature and strength of our approach. Detailed layout-level evaluations illustrate that UNSAIL incurs minimal area and power overheads of 0.26% and 0.61%, respectively, on the million-gate ORPSoC design. Lilas Alrahis, Satwik Patnaik, Johann Knechtel, Hani Saleh, Baker Mohammad, Mahmoud Al-Qutayri, Ozgur Sinanoglu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | ScanSAT: unlocking obfuscated scan chainsabstractWhile financially advantageous, outsourcing key steps such as testing to potentially untrusted Outsourced Semiconductor Assembly and Test (OSAT) companies may pose a risk of compromising on-chip assets. Obfuscation of scan chains is a technique that hides the actual scan data from the untrusted testers; logic inserted between the scan cells, driven by a secret key, hide the transformation functions between the scan-in stimulus (scan-out response) and the delivered scan pattern (captured response). In this paper, we propose ScanSAT: an attack that transforms a scan obfuscated circuit to its logic-locked version and applies a variant of the Boolean satisfiability (SAT) based attack, thereby extracting the secret key. Our empirical results demonstrate that ScanSAT can easily break naive scan obfuscation techniques using only three or fewer attack iterations even for large key sizes and in the presence of scan compression. Lilas Alrahis, Muhammad Yasin, Hani Saleh, Baker Mohammad, Mahmoud Al-Qutayri, Ozgur Sinanoglu |
ASP-DAC | 1 |
| 2019 | Functional Reverse Engineering on SAT-Attack Resilient Logic LockingabstractLogic locking is a solution that mitigates hardware security threats, such as Trojan insertion, piracy and counterfeiting. Research in this area has led to, in an iterative fashion, a series of logic locking defenses as well as attacks that circumvent these defenses by extracting the logic locking key. The most powerful attacks rely on a full access to a working chip/oracle that can be used to produce the input-output pairs utilized in recovering the secret key. A recently proposed technique Stripped Functionality Logic Locking (SFLL) provides resilience to all known attacks on combinational logic locking. In this paper, we propose a functional reverse engineering attack on SFLL: an attack that can detect the protection logic of SFLL which results in obtaining the original unlocked design with a high success rate. The restore and perturb blocks utilized by SFLL were detected with average coverage percentages of 93.95% and 85.42% respectively, proving that our attack is capable of breaking the state of the art logic locking technique. Lilas Alrahis, Muhammad Yasin, Hani Saleh, Baker Mohammad, Mahmoud Al-Qutayri |
ISCAS | 1 |