Likhitha Mankali

dblp:336/7980 · also Lakshmi Likhitha Mankali · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
8since 2021 · last 2025
0000-0002-8459-1703ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 3 first-author · 5 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 RTL-Breaker: Assessing the Security of LLMs Against Backdoor Attacks on HDL Code Generation
abstract
Large language models (LLMs) have demonstrated remarkable potential with code generation/completion tasks for hardware design. However, the reliance on such automation introduces critical security risks. Notably, given that LLMs have to be trained on vast datasets of codes that are typically sourced from publicly available repositories, often without thorough validation, LLMs are susceptible to so-called data poisoning or backdoor attacks. Here, attackers inject malicious code for the training data, which can be carried over into the hardware description code (HDL) generated by LLMs. This threat vector can compromise the security and integrity of entire hardware systems. In this work, we propose RTL-Breaker, a novel backdoor attack framework on LLM-based HDL code generation. RTL-Breaker provides an indepth analysis of essential aspects of this novel problem: 1) various trigger mechanisms versus their effectiveness for inserting malicious modifications, and 2) side-effects by backdoor attacks on code generation in general, i.e., impact on code quality. RTL-Breaker emphasizes the urgent need for more robust measures to safeguard against such attacks. Toward that end, we open-source our framework and all data.
Likhitha Mankali, Jitendra Bhandari, Manaar Alam, Ramesh Karri, Michail Maniatakos, Ozgur Sinanoglu, Johann Knechtel
DATE1
2025 LiCSPA: Lightweight Countermeasure against Static Power Side-Channel Attacks
abstract
This paper presents LiCSPA, a novel defense strategy against a critical threat to cryptographic hardware in modern technology nodes: static power side-channel attacks. Our method is based on (1) carefully tuning high-Vth versus low-Vth cell selection as well as driver strengths during synthesis, accounting for both security and timing impact, and (2), at runtime, randomly switching the operation between these cells. By doing so, LiCSPA achieves to significantly obscures data-dependent static power patterns. Our experimental results on a commercial 28nm node show a drastic increase in the effort required for a successful attack, namely up to 96 times more traces. LiCSPA incurs little cost, namely only 6% in area, making it a lightweight and practical defense that excels prior art.
Jitendra Bhandari, Mohammed Nabeel Thari Moopan, Likhitha Mankali, Ozgur Sinanoglu, Ramesh Karri, Johann Knechtel
ISCAS3
2025 GlitchFHE: Attacking Fully Homomorphic Encryption Using Fault Injection
Likhitha Mankali, Mohammed Nabeel Thari Moopan, Faiq Raees, Michail Maniatakos, Ozgur Sinanoglu, Johann Knechtel
USENIX Security Symposium1
2025 SecureX: Strategically Securing Designs Against Oracle-Less Attacks Using GNN-Based Explainers
abstract
Logic locking is a promising design-for-trust solution that protects integrated circuits (ICs) from hardware security threats such as design intellectual property (IP) piracy and illegal overproduction of ICs. With the ubiquity of machine learning (ML), researchers have proposed various ML-based attacks against logic locking techniques in recent years. Since ML-based attacks operate as non-interpretable models, understanding the reasons behind the success/failure of such attacks is challenging. In this work, we propose SecureX, the first-of-its-kind technique that employs an explainable Graph Neural Network (GNN) to lock designs. The unique benefits of explainable GNN-based analysis include identifying the best locations in the design to lock, and the critical features (structural/functional) that make the designs vulnerable to ML-based attacks. Moreover, SecureX seamlessly integrates with state-of-the-art unbroken scan-chain protection techniques, thus thwarting oracle-guided attacks. We perform experiments on ITC-99 benchmarks and two types of locking techniques (X(N)OR/MUX-based locking) to demonstrate the efficacy of SecureX in locking designs resilient to ML/non-ML-based attacks. Our results confirm that the accuracy of the state-of-the-art ML/non-ML-based attacks drops to ≈50% while maintaining low area/power/delay overheads. Moreover, we perform a practical case study of locking an image-processing application.
Likhitha Mankali, Ozgur Sinanoglu, Satwik Patnaik
IEEE Trans. Circuits Syst. I Regul. Pap.1
2024 INSIGHT: Attacking Industry-Adopted Learning Resilient Logic Locking Techniques Using Explainable Graph Neural Network
Likhitha Mankali, Ozgur Sinanoglu, Satwik Patnaik
USENIX Security Symposium1
2024 Beware Your Standard Cells! On Their Role in Static Power Side-Channel Attacks
abstract
Static or leakage power, which is especially prominent in advanced technology nodes, enables so-called static power side-channel attacks (S-PSCAs). While countermeasures exist, they often incur considerable overheads. Besides, hardware Trojans represent another threat. Although the interplay between static power, down-scaling of technology nodes, and the vulnerability to S-PSCA is already established, an important detail was not covered yet: the role of the components at the heart of this sensitive interplay, the standard cells. Here, we study this intricate relationship for two commercial 28 and 65 nm technologies, using a commercial-grade integrated circuit design setup, and under realistic power consumption, performance, and area (PPA) objectives. Specifically, we study how threshold-voltage (VT) tuning of standard cells impacts the resilience of representative AES and PRESENT cipher hardware, including versions with established countermeasures. Our proposed CAD framework enables a security-versus-PPA-aware design-space exploration. Contrary to the belief that high-performance designs are generally more vulnerable to S-PSCA, we find that timing constraints and the distribution of different VT cells are more pivotal factors. Furthermore, we discover that attackers can deploy highly effective and stealthy S-PSCA-based Trojans, all without any gate overheads or any timing violations.
Jitendra Bhandari, Likhitha Mankali, Mohammed Nabeel Thari Moopan, Ozgur Sinanoglu, Ramesh Karri, Johann Knechtel
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2023 VIGILANT: Vulnerability Detection Tool Against Fault-Injection Attacks for Locking Techniques
abstract
Logic locking is a well-known solution that thwarts design intellectual property (IP) piracy and prevents illegal overproduction of integrated circuits (ICs) against adversaries in the globalized supply chain. The widespread prevalence of reverse-engineering tools, probing, and fault-injection equipment has given rise to physical attacks that can undermine the security of a locked design. Fault-injection attacks, in particular, can extract the secret key from an oracle, circumventing the defense offered by logic locking. When design IP is compromised through physical attacks, fixing corresponding vulnerabilities generally require a silicon respin, which is impractical under constrained time and resources. Thus, there is a requirement for a detection tool that can perform a presilicon evaluation of locked designs to notify the designer of any vulnerabilities that can be exploited using faults. In this work, we propose VIGILANT, a first-of-its-kind vulnerability detection tool against fault-injection attacks targeting the hardware implementation of locking techniques. More specifically, VIGILANT aids designers in identifying critical nets susceptible to fault-injection attacks. VIGILANT analyzes the underlying locked design and computes a list of candidate nets along with their fault values required for key leakage and consequently validates each candidate net as vulnerable or not, using a functional simulation model of the design (acting as an oracle). We showcase the efficacy of VIGILANT on different locked designs for four different locking techniques under various parameters, such as technology nodes, layout-generation commands, and key-sizes. The accuracy of VIGILANT in identifying and validating all the candidate nets that are vulnerable to fault-injection attacks is 100%.
Likhitha Mankali, Satwik Patnaik, Nimisha Limaye, Johann Knechtel, Ozgur Sinanoglu
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2023 Titan: Security Analysis of Large-Scale Hardware Obfuscation Using Graph Neural Networks
abstract
Hardware obfuscation is a prominent design-for-trust solution that thwarts intellectual property (IP) piracy and reverse-engineering of integrated circuits (ICs). Researchers have proposed several large-scale obfuscation techniques that achieve high output corruption—thus offering resilience against seminal attacks along with acceptable power, performance, and area overheads. However, the research community has primarily evaluated hardware obfuscation on relatively small scales of obfuscation (i.e., a fixed number of obfuscated components). Moreover, prior art caters toward specific schemes based either on gate obfuscation or interconnect obfuscation, i.e., two prominent types of hardware obfuscation. The former shortcoming suggests focusing on large-scale obfuscation schemes, and the latter suggests the need for a holistic assessment framework. In this work, we propose Titan, a holistic framework considering large-scale gate and interconnect obfuscation schemes. More specifically, we propose a graph neural network (GNN)-based attack framework that is trained to exploit structural and functional properties of any secured circuit to recover its obfuscated components. We evaluate Titan on various obfuscation schemes, considering selected ITC-99 benchmarks with up to 50% obfuscation scale, i.e., up to 21,326 obfuscated components. We observe a substantial information leakage through structural and functional properties of secured designs even for large-scale obfuscation. We quantify the information leakage in two ways: first, an average reduction of Hamming distance (HD, a well-established metric for attack evaluation) by 23.27 and 16.19 percentage points over the baseline of random guessing for gate and interconnect obfuscation, respectively; second, an average recovery of 63.40% and 77.94% of obfuscated components for gate and interconnect obfuscation, respectively. Importantly, these results are superior to six state-of-the-art attacks. We will open-source our framework and associated artifacts to enable reproducibility and foster future work.
Likhitha Mankali, Lilas Alrahis, Satwik Patnaik, Johann Knechtel, Ozgur Sinanoglu
IEEE Trans. Inf. Forensics Secur.1