
The dependability of AI models relies largely on the reliability of the underlying hardware. Hardware aging attacks can compromise the computing substrate and disrupt AI models over the long run. In this work, we present a new hardware aging attack that exploits commutative properties of addition to disrupt the multiply-and-add operation that forms the backbone of almost all AI models. By permuting the inputs of an adder, the attack preserves functional correctness while inducing unbalanced stress among transistors, accelerating delay degradation in the circuit. Unlike prior approaches that rely on input manipulation, additional trojan circuitry, etc., the proposed method incurs virtually no area or software overhead. Experimental results with two types of multipliers, different bit widths, a mix of AI models and datasets demonstrate that the proposed attack degrades inference accuracy by up to 64
With the increasing adoption of Fully Homomorphic Encryption (FHE) for privacy-preserving Machine Learning (ML) and Deep Learning (DL), the security of encrypted training and inference remains a critical yet underexplored challenge. While conventional ML models are known to be vulnerable to evasion and backdoor attacks, it is not well understood whether similar threats persist in the encrypted domain. This work investigates the feasibility of both evasion and backdoor attacks on FHE-enabled ML models, focusing on three prominent libraries: TenSEAL, Concrete ML, and UniHENN. Although prior research has demonstrated encrypted evasion attacks on simple datasets in both public-key and symmetric-key settings, our work implements the attack in a key-independent scenario and provides insights into the nuances of the attack, showing that while it is straightforward to conduct attacks in TenSEAL and UniHENN, a different strategy based on MLIR-level representation is required for Concrete ML. We also introduce, for the first time, a study of backdoor attacks in the encrypted domain. We particularly focus on patch level backdoor attacks. Furthermore, we analyze the feasibility of backdoor attacks in TenSEAL and Concrete ML (version 1.5), highlighting structural differences that influence their vulnerability. Our findings demonstrate that FHE-enabled models remain susceptible to both evasion and backdoor attacks, underscoring the need for stronger defenses in encrypted ML systems.
Data security is becoming a major issue with the rise of microgrids. Sensitive data on energy production and consumption must be protected. A high level of security is essential to ensuring the efficient operation of vital services supplied by renewable energies. Blockchain, through the smart contracts and consensus algorithms, offers an ideal security solution. However, this technology requires a lot of computing and energy resources. It is crucial to choose a consensus algorithm tailored to the specific needs of the microgrid in terms of security, performance and energy consumption. The high energy consumption of blockchain is seen by researchers as a major limitation to its use in many decentralized networks such as microgrids. This article proposes an optimal choice of consensus algorithm and type of blockchain, based on security, energy consumption and computing resources. To achieve this, a review of the consensus algorithms used in microgrids was carried out, and the data obtained was used to build a decision tree for their selection. The proposed model was evaluated for different sizes of local electricity networks, and this approach enabled a microgrid sizing workflow to be proposed that takes security requirements into account. The results will enable the design of microgrid architectures and components that are compatible with decentralized cybersecurity technologies without affecting their operation.
Autonomous systems in adversarial environments derive operational authority from sensor inputs whose integrity is itself contested. Binary sensor attestation fails under partial degradation multipath interference, calibration drift, transient denial of service forcing all-or-nothing lockout responses that are operationally inadequate. This article specifies SATA (Sensor Attestation and Trust Anchoring), a TPM-anchored protocol specification that computes a continuous trust scalar τ ∈ [0, 1] from a sliding window of cryptographically committed attestation records. SATA combines six replay-resistance barriers ECDSA P-256 signature, 256-bit CSPRNG nonce, TPM monotonic counter, PCR quote (TPM2_Quote), per-sensor sequence, and hardware tick-clock age yielding a signature-barrier unforgeability bound P_forge < 2− 128 under a formally specified A1/A2 adversary model, stated and proved as Theorem 1, with explicit degradation analysis under a physical (A3) adversary. A weighted Dempster Shafer fusion layer provides Byzantine fault tolerance f ≤ ⌊(n-1)/3⌋ and preserves the ignorance distrust distinction, anchored in a TPM 2.0 hardware root of trust. The state machine is checked by TLA+ bounded model checking across 18,892 reachable states with zero violations of eight safety invariants, and a 10,000-run Monte Carlo campaign provides implementation-conformance and parameter-sensitivity evidence, explicitly distinguished from the analytical guarantee of Theorem 1. SATA is presented as a complement to RATS/SGX/PSA attestation, addressing the intersection of continuous trust quantification, hardware anchoring, formal specification, and multi-sensor operation under adversarial pressure.
Today, embedded systems and Cyber-Physical Systems (CPS) are increasingly powered by Systems-on-Chip (SoCs) and Networks-on-Chip (NoCs). SoCs are specialized, often reconfigurable devices that integrate hardware components and software to increase performance, flexibility, and time-to-market. With increasing design complexity and heterogeneity, designers have begun incorporating third-party hardware and software components into their designs. Traditional SoC security methods rely on perimeter-based trust assumptions, which are inadequate in protecting against emerging Trojans, privilege escalation, and software attacks introduced via third-party IPs or post-deployment infection. The Zero-Trust Architecture (ZTA) promotes ’never trust, always verify,’ requiring continuous validation of every asset and transaction. Although intended to protect traditional networking security solutions, it is generalizable to SoC and NoC environments. This survey assesses the state-of-the-art security of SoC and NoC, their adherence to ZTA’s core tenets, and the applicability of existing ZTA mechanisms to vulnerabilities in SoC and NoC. Of 45 SoC and NoC security solutions reviewed, and three works in the overlap of SoC and ZTA, none fully adhered to the tenets of Zero-Trust. They lacked encryption, per-session authorization, fine-grained access controls, and continuous verification. The analysis of these works identified four key research areas: real-time trust calculations and machine learning methods for resource-constrained hardware, dynamic fine-grained access control policies, SoC-capable verification methods, and the implementation of existing ZTA methods in SoCs.
The increasing threats to semiconductor integrated circuits (ICs) from hardware Trojans create growing risks of data breaches, system malfunctions or even device destruction. Traditional detection methods use Golden IC comparisons together with destructive reverse engineering techniques. The research introduces a hybrid framework which unites on-chip localization with unsupervised machine learning clustering eliminating need of golden data for Trojan detection. The on-chip localization technique reduces the reverse-engineering scope from full-chip inspection to a smaller RO-neighborhood region associated with the highest Trojan-impact score. The validation process on Field Programmable Gate Arrays (FPGAs) demonstrates that the detection system achieves 95
In cybersecurity, malware remains a significant threat, capable of stealing data, corrupting systems, disrupting operations, etc. To mitigate these risks, researchers have developed machine learning-based detection systems, which have significantly improved malware detection. However, these models remain vulnerable to adversarial attacks, where small, carefully crafted modifications to malware samples can force the model to misclassify them as benign. To address this issue, we propose a novel framework specifically designed to identify adversarial malware. We have evaluated our framework on adversarial samples generated through adversarial machine learning attacks across multiple datasets, including MalGAN, SLIPNER, PE Imports, and Speakeasy. Our experimental results demonstrate that the proposed framework effectively detects and eliminates adversarial malware across different adversarial machine learning attacks and datasets, achieving an average detection accuracy of approximately 90
Vulnerabilities in the microelectronics supply chain warrant for a non-destructive counterfeit detection tool that enables authentication without expert intervention. Such tools must also be non-invertible (computationally hard to reverse engineer), and adaptable to different sub-applications and hardware setups. Convolutional Neural Networks (CNNs), which learn spatial characteristics, are commonly employed for such pattern recognition tasks. In this paper, we demonstrate the uniqueness of particle-filled polymeric composites for electronics assembly authentication. These composites, when embedded within or on a substrate, serve as physical taggants that reveal tampering or replacement. Physically valid synthetic microstructures mimicking particle-filled polymers are generated using a modified particle-packing algorithm and used to train neural networks. Our results show that networks, which train solely on classification, struggle with the open-set nature of the counterfeit data, often producing similar probability scores and are hard to classify. However, when reduced order representations of images are assumed gaussian and evaluated, the probability of authenticity can be precisely learned and used for robust classification, achieving accurate separation of true and counterfeit data. Networks which directly learn the probabilistic distribution of the true data and those that plot hyper sphere dimensionality reduction, similarly achieve near 100
For the past decades, covert and side channels have posed significant threats to user privacy in computing systems, targeting almost every component. In this paper, we present SideLink, an attack that exploits the NVLink bus for covert communication and information leakage. NVLink is a high-bandwidth interconnect in NVIDIA GPU systems that has become essential for AI workloads in data centers. Despite its high bandwidth, we show that NVLink exhibits measurable contention characteristics that enable both covert and side-channel attacks. We evaluate SideLink across NVIDIA’s Hopper (H200), Ampere (A100), and Volta (V100) architectures, achieving covert channel bandwidths of 8.29 Kbps, 9.90 Kbps, and 6.33 Kbps respectively with negligible error rates, demonstrating the attack’s viability across multiple GPU and NVLink generations. Furthermore, we implement an application fingerprinting side-channel attack, collecting a dataset of NVLink latency traces from dual-GPU applications including hashing and crypto-mining workloads. By evaluating multiple machine learning models, we achieve a maximum accuracy of 96.2
Modern high-performance processors rely on speculative execution to improve throughput, but this optimization has enabled microarchitectural side-channel attacks that can leak sensitive information, including cryptographic keys and confidential data. Although mitigations such as Indirect Branch Restricted Speculation (IBRS), Retpoline, and microcode updates have reduced exposure to classical Spectre (v1–v3) and Meltdown-style attacks, recent work has highlighted interleaved speculative-execution attacks in which malicious gadgets are injected at extremely low duty cycles into otherwise normal execution. The intermittent nature of such interleaving significantly degrades the sensitivity of Performance Monitoring Counter (PMC)-based detectors that rely on magnitude thresholds or short-window aggregate statistics, thereby complicating reliable detection. We present AISELF, an automated framework for detecting interleaved speculative-execution behaviour using PMC. Building on our prior feasibility study on PMC-based detection for known speculative-execution attacks, AISELF combines LLM-driven automation with statistically principled anomaly testing. Given the user’s workload and system configuration, AISELF recommends a ranked top-k set of architecture-valid PMU events (default k=5 ) to monitor on the target platform. The user collects raw PMC traces for these events while executing the workload, and AISELF then applies deterministic, Hartigan’s Dip Test with multiple-testing to identify multimodality indicative of rare interleaving. When the initial event set is not sufficiently discriminative, AISELF invokes an automated refinement loop that iteratively updates the monitored event set to improve detection sensitivity under the same measurement budget. Overall, AISELF provides a practical and reproducible workflow for identifying low-duty-cycle interleaved speculative-execution activity from PMC telemetry while minimizing manual PMU expertise requirements.
We formulate a non-intrusive model order reduction (MOR) framework, called PUF-ROMS, to accelerate and optimize the design and analysis of physical unclonable functions (PUFs). PUF-ROMS provides an environment for rapid estimation of entropy and temperature-voltage noise (TV-noise) of circuit structures used in the PUF’s design. This enables designers to explore different architectures with the goal of maximizing entropy and minimizing the adverse impact of TV-noise on accessing this entropy. PUF-ROMS starts with the development of reduced order models (ROMs) for the logic cell primitives used in the PUF circuit structure. These models are based on the canonical Hammerstein model architecture and are trained using SPICE transistor-level simulation data of the cell primitives collected offline. The cell primitive ROMs are then used in SPICE system-level Monte Carlo (MC) simulations to enable efficient exploration of the PUF design space. PUF-ROMS is developed and demonstrated using an IBM 90nm PDK, the standard cell library, and hardware data collected from a variant of the Arbiter PUF. Our evaluation shows that delay PUF designs can nearly double the level of entropy by using a specific subset of the standard cells, and by instantiating them with transistor options normally used in low-power design. The performance, memory requirements and effectiveness of the PUF-ROMS evaluation methodology is compared with an alternative SPICE-level strategy. The assessment accounts for the time taken to calibrate the standard cell ROM models to SPICE-level simulation results, where calibration utilizes Monte Carlo simulations of local device mismatch and simulations using process-voltage-temperature (PVT) corner models.
The rapid expansion of the Internet of Things (IoT) is transforming industries and society, while simultaneously exposing critical security vulnerabilities that are becoming increasingly urgent with the advent of quantum computing. Conventional cryptographic techniques currently used in IoT systems are expected to be inadequate against quantum-enabled adversaries. This study presents a comprehensive review of the emerging Quantum-IoT (Q-IoT) paradigm, focusing on the practical integration of quantum-resilient security mechanisms within resource-constrained IoT environments. Specifically, it analyzes hybrid cryptographic architectures that combine lightweight post-quantum cryptography (PQC) at the IoT device layer with quantum key distribution (QKD) in communication backbones. The paper further examines the role of artificial intelligence (AI) in enabling adaptive security orchestration, including context-aware cryptographic selection, resource optimization, and anomaly detection tailored to hybrid classical–quantum threat models. Through a critical comparison with recent literature, this review identifies key challenges related to computational overhead, protocol interoperability, deployment feasibility, and standardization. Overall, the paper provides structured insights and design guidance for developing scalable and deployable quantum-resilient IoT architectures, supporting the secure evolution of next-generation connected systems.
Due to cost benefits, supply chains of integrated circuits (ICs) are largely outsourced nowadays. However, passing ICs through various third-party providers gives rise to many security threats, like piracy of IC intellectual property or insertion of hardware Trojans, i.e., malicious circuit modifications. In this work, we proactively and systematically protect the physical layouts of ICs against post-design insertion of Trojans. Toward that end, we propose TroLLoc, a novel scheme for IC security closure that employs, in careful unison, logic locking and layout hardening, i.e., physical synthesis aimed toward highest possible utilization. TroLLoc is fully integrated into a commercial-grade design flow, and shown to be effective, efficient, and robust. Our work provides in-depth layout and security analysis considering the ISPD’22/23 benchmarks for security closure TroLLoc successfully renders layouts resilient, with reasonable overheads, against (i) general prospects for Trojan insertion as in the ISPD’22 contest, (ii) actual Trojan insertion as in the ISPD’23 contest, and (iii) second-order attacks where adversaries would first (before Trojan insertion) try to bypass the locking defense, mainly using advanced machine learning attacks. Finally, we release all our artifacts for independent verification [64].
Ensuring the authenticity and integrity of electronic assemblies is increasingly critical as hardware-based attacks and unauthorized component modifications become more sophisticated. Conventional inspection systems, whether rule-based AOI or traceability logs, offer limited protection against subtle or intentional tampering. This paper introduces a deep learning–based framework for secure hardware assurance that operates directly on AOI image data, enabling autonomous, full-coverage verification of every component on the board. The method is built on two previously patented systems: one for component authentication via visual fingerprinting, independent of top marking, and another for contextual decoding of top marking codes. These systems have been deployed across tens of SMT lines, generating over 5 billion production-grade inspections. By integrating and extending these capabilities, the system performs bottom-up part analysis and top-down layout validation, identifying substitutions, rework, and tampering, without requiring electrical probing, golden boards, or metadata. Results show > 99
We propose the analysis and dynamical system model for one-dimensional bistable Physically Unclonable Function (PUF). Our work is derived from the analysis of a broad range of analytical models and circuit topologies suitable for the design of bistable PUFs. Starting from circuit analysis, we discuss a theoretical model to evaluate the source of entropy from a mathematical point of view targeting optimized intrinsic hardware-based security mechanisms. The results develop an evaluation design tool to address the most crucial model parameters affecting the obtained system uniqueness. The analysis is authentic as it is generalized by a systematic standpoint framing the PUF design within a mathematical context. The paper presents a methodical approach aiming at defining a novel class of beneficial models exploiting the dynamics sensitivity to parametric perturbations extending the PUF design within a theoretical setting. Furthermore, the proposed analysis is potentially investigated to explore the impacts of environmental conditions on system parametric perturbation affecting PUF reliability.
This paper describes the design and implementation of a Fredkin-gate (FRG)-based arbiter physically unclonable function (PUF) with 2 × 2 switch blocks on an Artix-7 FPGA. The Fredkin gate is a three-input, three-output reversible gate, with two of its outputs functioning as 2:1 multiplexers. A classical arbiter PUF consists of multiplexer-based switch blocks through which a trigger signal propagates; therefore we propose a Fredkin-gate-based arbiter PUF architecture. The designed arbiter PUF is manually placed and routed on the Artix-7 200T FPGA. Challenges were generated using an LFSR, and the corresponding responses were analyzed to compute standard PUF performance metrics. The uniformity and uniqueness of the Fredkin gate-based arbiter PUF are 48.62
We present a protected hardware implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). ML-DSA is an extension of Dilithium 3.1, which is the winner of the Post Quantum Cryptography (PQC) competition in the digital signature category. The proposed design is based on the existing high-performance Dilithium 3.1 design. We implemented existing Dilithium masking gadgets in hardware, which were only implemented in software. The masking gadgets are integrated with the unprotected ML-DSA design, and functional verification of the complete design is verified using the Known Answer Tests(KATs) generated from ML-DSA reference software. We also present the practical power side-channel attack experimental results by implementing masking gadgets on the standard side-channel evaluation FPGA board and collecting power traces of up to 1 million. The proposed protected design has the overhead of 1.127 × LUT, 1.2 × Flip-Flop, and 378 × execution time compared to the unprotected design. The experimental results show that it resists side-channel attacks.
Microelectronics that make up modern-day devices need to be studied with greater scrutiny on security to mitigate emerging cyber threats. The growth of technology, such as the Internet of Things (IoT), fuels the need to build secure and trustworthy microelectronics that form these end devices. The wide applications of microelectronics broaden the cyber-attack range for adversaries to initiate security attacks. When compromised at a larger scale, impacts can lead to supply and service disruptions in the supply chain, and it must be contained, with risks being eliminated to avoid further impacts. Therefore, understanding the threat surfaces for microelectronics, associated endpoints, evolution, and future developments can help ongoing security research and industrial efforts to protect microelectronics, making them a trustworthy building block of modern electronic devices. This paper reviews the current prevailing security factors contributing to the major impacts of security issues in microelectronics involving hardware and manufacturing vulnerabilities. Furthermore, the exploration extends to various security attacks, including trojans, counterfeiting, and side-channel attacks, covering their attack vectors and associated strategies within the field of microelectronics. This review article also discusses mitigation strategies and security measures for eliminating risks to avoid further impacts. This article provides a comprehensive overview of trustworthy, state-of-the-art microelectronics. By understanding security issues and the current state of countermeasures, we can work towards creating more secure and reliable microelectronic devices across the global supply chain.
The fast evolution of resource-constrained Internet of Things (IoT) devices necessitates lightweight cryptographic solutions that balance robust security with minimal hardware demands. This paper presents a comprehensive benchmarking study of FPGA-based implementations of the SIMON 64/128 block cipher, a lightweight algorithm designed by the NSA for efficient hardware realization. Three architectural strategies are evaluated on an Artix-7 FPGA: an iterative design with a precomputed key schedule (Iter-PreK), an iterative design with an on-the-fly key schedule (Iter-OTFK), and a partially unrolled design (Unrollx2) processing two rounds per clock cycle. Experimental results reveal distinct trade-offs in resource utilization, latency, throughput, and power consumption. The Iter-OTFK design offers the smallest footprint, occupying only 82 slices and consuming 79 mW, while still achieving a throughput of 267.0 Mbps by overlapping encryption and key scheduling. Iter-PreK provides a balanced design, reaching 211.1 Mbps at a maximum frequency of 151.7 MHz with a moderate area. In contrast, the partially unrolled Unrollx2 architecture achieves a peak steady-state throughput of 5014.4 Mbps at 156.7 MHz, with significantly improved energy efficiency (0.017 nJ/bit), making it ideal for bandwidth-intensive applications. Compared to prior studies, this work presents the first systematic benchmarking of SIMON 64/128 across multiple architectures on a modern FPGA, offering practical design guidelines for lightweight cryptography in IoT deployments, from low-end sensor nodes to high-throughput gateways.
The proliferation of the Internet of Things (IoT) devices has increased security concerns, as these devices suffer from limited computational resources, restricting traditional encryption methods. Physically unclonable functions (PUFs) provide a lightweight and cost-effective alternative for secure authentication. This study presents an optimized resistor–capacitor (RC) PUF design for IoT security, focusing on the effects of input time delay and output bit selection on an analog-to-digital (ADC) converter for enhanced performance. We evaluate first-order (RC1) and second-order (RC2) PUF architectures, optimizing resistance (R), capacitance (C), bit delays, and ADC bit selection to improve uniqueness, uniformity, reliability, and bit aliasing. Experimental results indicate that the 5th ADC bit out of 12 bits provides optimal performance, balancing uniqueness ( 50