Countermeasure using Physically Unclonable Function for Hardware Trojans in Edge AI Devices

Yusuke Nozaki, Shu Takemoto, 雅弥 吉川 · 2024

Artificial intelligence (AI) technologies are recently used in various fields such as image recognition and speech recognition. On the other hand, as issues in the AI application, safety and security risks and privacy issues in the use of AI have been reported. Therefore, it is important to ensure the security of edge AI and to realize the trusted AI. The hardware Trojan (HT) is a threat since it is a circuit that performs malicious behavior embedded into the LSI without the designer's knowledge and it is difficult to detect by general function tests. The HT targeting edge AI devices called AI-HT is oriented to FPGA and it is inserted focusing on LUT. Since AI-HT is inserted by rewriting the LUT table information, it is regarded as a threat due to the no circuit overhead of AI-HT, however, there are insufficient evaluations on the detection methods and countermeasure against AI-HT. Therefore, this study proposes a countermeasure method for AI-HT. The proposed method uses physically unclonable function (PUF) to identify the AI-HT. Experiments using FPGA showed that the proposed method authenticated genuine devices by using PUF circuits.

Read the paper · More papers on PaperTik