EDBT 2026 Demo / reviewers in the wild / expert
Hassan Salmani
dblp:82/2503
· DBLP profile ↗
15ranked-venue papers
10as first author
4since 2021 · last 2024
0000-0002-4863-2934ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 6 first-author · 4 since 2021Security and privacy · 4 · 4 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Detecting Hardware Trojans in Manufactured Chips without Reference: A GMM-Based ApproachabstractThe horizontal IC design and manufacturing flow creates ample opportunities for unauthorized tampering at various stages, yet there is limited research dedicated to detecting hardware Trojans (HTs) in manufactured ICs. Practical applications are hindered by substantial challenges, including the presence of trusted ICs. This paper introduces a novel method for reference-free HT detection in manufactured ICs, leveraging Gaussian mixture models (GMMs) with power side-channel signals. Experimental results, conducted on AES-128 with various hardware Trojans, demonstrate an accuracy exceeding 95.52%. To be introduced for the first time, to the best of our knowledge, our proposed GMM-based HT detection method also provides a probabilistic framework, attributing evolving probability values to individual side-channel measurements to indicate potential HT activation. Consequently, it becomes feasible to ascertain with a high level of confidence whether a manufactured design has been tampered with an HT. Mahsa Tahghigh, Hassan Salmani |
ICCAD | 2 |
| 2022 | The Improved COTD Technique for Hardware Trojan Detection in Gate-level NetlistabstractHardware Trojans (HTs) have introduced serious security concerns into the integrated circuit design flow as they can undermine circuit operations by leaking sensitive information, causing malfunction, or similar attacks. An earlier-introduced HT detection technique in gate-level netlist, the Controllability and Observability for hardware Trojan Detection (COTD) technique detects HTs based on controllability and observability signals in a circuit and presents a static analysis based on an unsupervised machine learning model to identify HT signals in the circuit. While COTD detects the existence of HTs in a circuit, some work has highlighted the shortcoming of COTD in detecting some HT signals that present similar features as genuine signals. To address this shortcoming, this paper presents an improved COTD technique. The improved COTD technique introduces an iterative unsupervised machine-learning technique to isolate HT signals. Furthermore, the improved COTD is equipped with the Gradual-N-Justification (GNJ) technique to reduce false-positive rates in detecting HT signals. The improved COTD technique is applied to several different combinations of full-scan and partial scan circuits tampered with hard-to-detect sequential HTs. To realize valid and hard-to-detect HTs, a configurable HT insertion platform is utilized. The comprehensive results have shown that the improved COTD is highly scalable. Furthermore, the improved COTD technique does not miss a HT circuit if exists and it offers a false-positive rate as low as 3.4%, on average. Hassan Salmani |
ACM Great Lakes Symposium on VLSI | 1 |
| 2022 | Session details: Session 6B: Special Session - 2: Application-oriented Hardware Security Challenges and SolutionsabstractNo abstract available. Hassan Salmani |
ACM Great Lakes Symposium on VLSI | 1 |
| 2022 | Gradual-N-Justification (GNJ) to Reduce False-Positive Hardware Trojan Detection in Gate-Level NetlistabstractThe integrated circuit design flow is highly susceptible to hardware Trojan (HT) insertion. While there have been significant efforts to detect HTs, techniques usually demand a golden model, suffer limited scalability, or experience high false positives. This article introduced a new technique called gradual-N-justification (GNJ) to reduce false-positives HT detection in the gate-level netlist. The GNJ technique combines the signal justification and unsupervised K-means machine learning (ML) algorithm. The GNJ technique is a general technique that can be applied to a set of reported suspicious signals (SSs) in order to identify the most SSs and reduce false-positive rates (FPRs) in detecting HTs. The GNJ technique is applied to 60 different combinations of full-scan and partial-scan circuits and hard-to-detect combinational HTs. To realize valid and hard-to-detect HTs, a configurable HT insertion platform is developed. Furthermore, to the best of our knowledge, it is for the first time that an extensive evaluation of partial-scan circuits for HT detection at the gate level is being performed. The comprehensive results on both full- and partial-scan circuits have shown that the GNJ technique is highly scalable as it presents a linear relationship between the number of SSs and the execution time of GNJ. Furthermore, the GNJ technique does not miss an HT circuit if exists. The GNJ technique offers an FPR as low as 3.89% for full-scan circuits and 3.31% for partial-scan circuits on average. Hassan Salmani |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2019 | Special Session: Countering IP Security threats in Supply chainabstractThe continuing decrease in feature size of integrated circuits, and the increase of the complexity and cost of design and fabrication has led to outsourcing the design and fabrication of integrated circuits to third parties across the globe, and in turn has introduced several security vulnerabilities. The adversaries in the supply chain can pirate integrated circuits, overproduce these circuits, perform reverse engineering, and/or insert hardware Trojans in these circuits. Developing countermeasures against such security threats is highly crucial. Accordingly, this paper first develops a learning-based trust verification framework to detect hardware Trojans. To tackle Trojan insertion, IP piracy and overproduction, logic locking schemes and in particular stripped functionality logic locking is discussed and its resiliency against the state-of-the-art attacks is investigated. Hassan Salmani, Tamzidul Hoque, Swarup Bhunia, Muhammad Yasin, Jeyavijayan Rajendran, Naghmeh Karimi |
VTS | 1 |
| 2018 | Programmable Gates Using Hybrid CMOS-STT Design to Prevent IC Reverse EngineeringabstractThis article presents a rigorous step towards design-for-assurance by introducing a new class of logically reconfigurable design resilient to design reverse engineering. Based on the non-volatile spin transfer torque (STT) magnetic technology, we introduce a basic set of non-volatile reconfigurable Look-Up-Table (LUT) logic components (NV-STT-based LUTs). An STT-based LUT with a significantly different set of characteristics compared to CMOS provides new opportunities to enhance design security yet makes it challenging to remain highly competitive with custom CMOS or even SRAM-based LUT in terms of power, performance, and area. To address these challenges, we propose several algorithms to select and replace custom CMOS gates with reconfigurable STT-based LUTs during design implementation such that the functionality of STT-based components and therefore the entire design cannot be determined in any manageable time, rendering any design reverse engineering attack ineffective. Our study, conducted on a large number of standard circuit benchmarks, concludes significant resiliency of hybrid STT-CMOS circuits against various types of attacks. Furthermore, the selection algorithms on average have a small impact on the performance of the circuit. We also tested these techniques against satisfiability attacks developed recently and show that these techniques also render more advanced reverse-engineering techniques computationally infeasible. Theodore Winograd, Gaurav Shenoy, Hassan Salmani, Hamid Mahmoodi, Setareh Rafatirad, Houman Homayoun |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2017 | COTD: Reference-Free Hardware Trojan Detection and Recovery Based on Controllability and Observability in Gate-Level NetlistabstractThis paper presents a novel hardware Trojan detection technique in gate-level netlist based on the controllability and observability analyses. Using an unsupervised clustering analysis, the paper shows that the controllability and observability characteristics of Trojan gates present significant inter-cluster distance from those of genuine gates in a Trojan-inserted circuit, such that Trojan gates are easily distinguishable. The proposed technique does not require any golden model and can be easily integrated into the current integrated circuit design flow. Furthermore, it performs a static analysis and does not require any test pattern application for Trojan activation either partially or fully. In addition, the timing complexity of the proposed technique is an order of the number of signals in a circuit. Moreover, the proposed technique makes it possible to fully restore an inserted Trojan and to isolate its trigger and payload circuits. The technique has been applied on various types of Trojans, and all Trojans are successfully detected with 0 false positive and negative rates in less than 14 s in the worst case. Hassan Salmani |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Hybrid STT-CMOS designs for reverse-engineering preventionabstractThis paper presents a rigorous step towards design-for-assurance by introducing a new class of logically reconfigurable design resilient to design reverse engineering. Based on the non-volatile spin transfer torque (STT) magnetic technology, we introduce a basic set of non-volatile reconfigurable Look-Up-Table (LUT) logic components (NV-STT-based LUTs). STT-based LUT with significantly different set of characteristics compared to CMOS provides new opportunities to enhance design security yet makes it challenging to remain highly competitive with custom CMOS or even SRAM-based LUT in terms of power, performance and area. To address these challenges, we propose several algorithms to select and replace custom CMOS gates with reconfigurable STT-based LUTs during design implementation such that the functionality of STT-based components and therefore the entire design cannot be determined in any manageable time, rendering any design reverse engineering attack ineffective. Our study conducted on a large number of standard circuit benchmarks concludes significant resiliency of hybrid STT-CMOS circuits against various types of attacks. Furthermore, the selection algorithms on average have a small impact of less than 3%, 8%, and 3% on design parametric constraints including performance, power and area, respectively. Theodore Winograd, Hassan Salmani, Hamid Mahmoodi, Kris Gaj, Houman Homayoun |
DAC | 2 |
| 2016 | Dynamic single and Dual Rail spin transfer torque look up tables with enhanced robustness under CMOS and MTJ process variationsabstractIn this paper, we investigate the limitation of existing STT-LUT designs and propose two new circuit styles of designing STT-LUTs that offer higher performance and robustness compared to the conventional STT-LUT design. The proposed styles include a Dynamic Single Rail (DSR) and a Dynamic Dual Rail (DDR) STT-LUT. The simulation results in a 16nm bulk CMOS technology shows that the proposed designs exhibits up to 3.3× read delay reduction, 2.4× active power reduction, and 441× sensing failure rate reduction compared to the best conventional STT-LUT design. The proposed DDR scheme offers the best overall performance even when considering the state of the art Separated Precharge Sensing Amplifier and Separated Decoding schemes. Aliyar Attaran, Hassan Salmani, Houman Homayoun, Hamid Mahmoodi |
ICCD | 2 |
| 2016 | Comparative analysis of robustness of spin transfer torque based look up tables under process variationsabstractSpin Transfer Torque (STT) switching realized using a Magnetic Tunnel Junction (MTJ) device has shown great potential for low power and non-volatile storage. A prime application of MTJs is in building non-volatile Look Up Tables (LUT) used in reconfigurable logic. Such LUTs use a hybrid integration of CMOS transistors and MTJ devices. This paper discusses the reliability of STT based LUTs under transistor and MTJ variations in nano-scale. The sources of process variations include both the CMOS device related variations and the MTJ variations. A key part of the STT based LUTs is the sense amplifier needed for reading out the MTJ state. We compare the voltage and current based sensing schemes in terms of the power, performance, and reliability metrics. Based on our simulation results in a 16nm CMOS, for the same total device area, the voltage mode sensing scheme offers 75% lower failure rates under threshold voltage (Vth) variations, 4.9X higher tolerance to MTJ resistance variations, 19% less delay, and 64% lower active power compared to the current sensing scheme. Ragh Kuttappa, Houman Homayoun, Hassan Salmani, Hamid Mahmoodi |
ISCAS | 3 |
| 2016 | Vulnerability Analysis of a Circuit Layout to Hardware Trojan InsertionabstractWhile the horizontal integrated circuit design process is extensively practiced, untrusted foundries can impose significant threats on the security of final products. A carefully inserted extra circuitry as a hardware trojan in a circuit layout can interfere with circuit functionality under very rare circumstances with inconsiderable footprints. In this paper, we introduce a novel layout-level vulnerability analysis flow to evaluate the susceptibility of a circuit layout's regions to hardware Trojan insertion. We also present several metrics based on a circuit layout to quantify the possibility of hardware Trojan insertion in a specific region of layout. Results of applying our flow to several benchmarks have revealed considerably high vulnerability of circuit layouts to hardware Trojan insertion. Furthermore, several Trojans are implemented and inserted in layout regions with different vulnerabilities to evaluate the effectiveness of our new metrics. Our novel layout-level vulnerability analysis flow makes it possible to quantitatively determine the vulnerability of different implementations of a circuit and analyze the susceptibility of each corner of circuit layout to different types of functional Trojans. Hassan Salmani, Mark Tehranipoor |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | On design vulnerability analysis and trust benchmarks developmentabstractThe areas of hardware security and trust have experienced major growth over the past several years. However, research in Trojan detection and prevention lacks standard benchmarks and measurements, resulting in inconsistent research outcomes, and ambiguity in analyzing strengths and weaknesses in the techniques developed by different research teams and their advancements to the state-of-the-art. We have developed innovative methodologies that, for the first time, more effectively address the problem. We have developed a vulnerability analysis flow. The flow determines hard-to-detect areas in a circuit that would most probably be used for Trojan implementation to ensure a Trojan goes undetected during production test and extensive functional test analysis. Furthermore, we introduce the Trojan detectability metric to quantify Trojan activation and effect. This metric offers a fair comparison for analyzing weaknesses and strengths of Trojan detection techniques. Using these methodologies, we have developed a large number of trust benchmarks that are available for use by the public, as well as researchers and practitioners in the field. Hassan Salmani, Mark Tehranipoor, Ramesh Karri |
ICCD | 1 |
| 2012 | Layout-Aware Switching Activity Localization to Enhance Hardware Trojan DetectionabstractGovernment agencies and the semiconductor industry have raised serious concerns about malicious modifications to the integrated circuits. The added functionality known as hardware Trojan poses major detection and isolation challenges. This paper presents a new hardware trust architecture to magnify functional Trojans activity. Trojan detection resolution depends on Trojan activity directly and circuit activity reversely. The proposed architecture reorders scan cells based on their placement during physical design to reduce circuit switching activity by limiting it into a specific region. This helps magnify Trojan contribution to the total circuit transient power by increasing Trojan-to-circuit switching activity (TCA) and Trojan-to-circuit power consumption (TCP). The proposed technique aims to improve the efficiency of power-based side-channel signal analysis techniques for detecting hardware Trojans. Our simulation results demonstrate the efficiency of the method in significantly increasing TCA and TCP. Hassan Salmani, Mark Tehranipoor |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | A Novel Technique for Improving Hardware Trojan Detection and Reducing Trojan Activation TimeabstractFabless semiconductor industry and government agencies have raised serious concerns about tampering with inserting hardware Trojans in an integrated circuit supply chain in recent years. Most of the recently proposed Trojan detection methods are based on Trojan activation to observe either a faulty output or measurable abnormality on side-channel signals. Time to activate a hardware Trojan circuit is a major concern from the authentication standpoint. This paper analyzes time to generate a transition in functional Trojans. Transition is modeled by geometric distribution and the number of clock cycles required to generate a transition is estimated. Furthermore, a dummy scan flip-flop insertion procedure is proposed aiming at decreasing transition generation time. The procedure increases transition probabilities of nets beyond a specific threshold. The relation between circuit topology, authentication time, and the threshold is carefully studied. The simulation results on s38417 benchmark circuit demonstrate that, with a negligible area overhead, our proposed method can significantly increase Trojan activity and reduce Trojan activation time. Hassan Salmani, Mark Tehranipoor, James F. Plusquellic |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2005 | Contribution of Controller Area Networks Controllers to Masquerade FailuresabstractThis paper scrutinizes faults in a CAN controller that may result in masquerade failures, and suggests an even parity mechanism to detect them with minimum hardware overhead. To do this, a CAN controller is modeled by VHDL at behavioral level and is exploited to setup a CAN-based network composed of two nodes. A total of 5,500 faults are injected into essential parts of one of the controllers. The results show that about 3.44% of faults terminate in masquerade failures. The results, also, show that register bank in the CAN controller are the most sensitive portions in which 92.10% of faults occurring in the register bank result in masquerade failures. The even parity mechanism detects about 96.31% of all masquerade failures. Hassan Salmani, Seyed Ghassem Miremadi |
PRDC | 1 |