A Novel Attack on Machine-Learning Resistant Physical Unclonable Functions

Daniel Canaday, Wendson A. S. Barbosa, Andrew Pomerance · 2022

Many of today's proposed designs for strong physical unclonable functions (PUFs) are constructed from strong PUF building blocks that are known to be themselves vulnerable to machine-learning (ML) attacks, such as the Arbiter PUF or Ring Oscillator PUF. These designs aim to make the global design ML-resistant by obscuring the true challenge and/or responses corresponding to the vulnerable building blocks, thereby making it more difficult for ML attacks to infer underlying model parameters. In this work, we propose a model-free ML attack, inspired by deep learning-based image imputation algorithms, that successfully breaks these popular countermeasures. Our attack is unique in that it uses not only the observed challenge-response pairs (CRPs) of the device being attacked but also uses CRPs collected from other PUFs of the same type, which results in improved bit-error rates (BERs). We show that our attack breaks several proposed ML-resistant PUF architectures based on obfuscation of vulnerable strong PUF building blocks.

Read the paper · More papers on PaperTik