FPGA-Based Hardware Redaction Bitstream Fuzzing Attack
Chaitali G. Sathe, Daksith Chandrasekera, Yiorgos Makris, Benjamin Carrión Schäfer · 2025
In this current era of global semiconductor industries, threats to hardware intellectual property (IP) become more prevalent. The attacks on IP such as piracy, reverse engineering, over production, etc. are diverse and spread over various VLSI design stages or the fab. Numerous hardware security measures such as split manufacturing, IC camouflaging, logic locking, and design obfuscation techniques were introduced in past. A recent technique of hardware redaction, where critical components of the digital design are redacted and mapped on an embedded FPGA (eFPGA) seems promising. Here, the part of design is hidden in the form of the bitstream of an eFPGA. Since then, there has been a constant work going on finding a highly efficient way to redact a part of a circuit such that it will ensure both security and area, performance efficiency. However, hardware redaction is not 100 % secure, and a variety of attacks have already been proposed [1] to recover the hidden design. In this work, we propose a new attack to recover a correct bitstream for an eFPGA-based hardware redacted circuit. For this, we introduce a simulation-based framework based on bitstream fuzzing that aims at finding an eFPGA bitstream that leads to a functionally correct design. This simulation framework will also help IP vendors to evaluate how secure their redacted designs are.