The participation of third-party entities in the globalized semiconductor supply chain introduces potential security vulnerabilities, such as intellectual property piracy and hardware Trojan (HT) insertion. Graph neural networks (GNNs) have been employed to address various hardware security threats, owing to their superior performance on graph-structured data, such as circuits. However, GNNs are also susceptible to attacks. This work examines the use of GNNs for detecting hardware threats like HTs and their vulnerability to attacks. We present BadGNN, a backdoor attack on GNNs that can hide HTs and evade detection with a 100% success rate through minor circuit perturbations. Our findings highlight the need for further investigation into the security and robustness of GNNs before they can be safely used in security-critical applications.
翻译:第三方参与全球化半导体供应链引入了潜在的安全漏洞,例如知识产权盗窃和硬件木马植入。图神经网络因其在电路等图结构数据上的卓越性能,已被用于应对多种硬件安全威胁。然而,图神经网络同样易受攻击。本文研究了利用图神经网络检测硬件木马等硬件威胁的能力及其面临攻击的脆弱性。我们提出了BadGNN——一种针对图神经网络的后门攻击方法,通过微小的电路扰动即可隐藏硬件木马并以100%的成功率规避检测。我们的研究结果警示,在将图神经网络安全应用于安全关键型应用之前,需进一步探究其安全性和鲁棒性。