Abstract
The risk of hardware Trojans (HTs) in integrated circuits has grown with the globalized economy and increased reliance on third-party services. To counter this threat, Machine Learning (ML)-based detectors are widely used. However, recent studies show that adversaries can exploit ML vulnerabilities to create evasive HTs. These prior approaches, however, often require high circuit overheads, limiting their practicality. In this paper, we propose a novel method to generate evasive HTs with minimal or no circuit overhead, under realistic black-box assumptions. By relaxing the requirement for strict payload correctness from the attacker's perspective, we define a new approximate adversarial design space. Our gradient-free framework leverages approximate gate replacements and uses a multi-objective evolutionary algorithm to balance HT evasiveness and approximation error. Unlike prior work assuming white-box access to detection models, we focus on the more practical black-box scenario, aligning with real-world constraints and enabling a more robust evaluation of detection strategies. Experiments show our attack reduces Trojan detector accuracy by an average of 91.6%, while maintaining functionality with only 35% approximation error.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 2025 Asian Hardware Oriented Security and Trust Symposium (AsianHOST 2025) |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Number of pages | 4 |
| ISBN (Electronic) | 9798331589240 |
| ISBN (Print) | 9798331589257 |
| DOIs | |
| Publication status | Published - 09 Feb 2026 |
| Event | 2025 Asian Hardware Oriented Security and Trust Symposium, AsianHOST 2025 - Nanjing, China Duration: 19 Dec 2025 → 21 Dec 2025 |
Publication series
| Name | Proceedings of the 2025 Asian Hardware Oriented Security and Trust Symposium, AsianHOST 2025 |
|---|
Conference
| Conference | 2025 Asian Hardware Oriented Security and Trust Symposium, AsianHOST 2025 |
|---|---|
| Country/Territory | China |
| City | Nanjing |
| Period | 19/12/2025 → 21/12/2025 |
Bibliographical note
Publisher Copyright:© 2025 IEEE.
Keywords
- approximate computing
- evasion attacks
- Hardware Trojan
ASJC Scopus subject areas
- Artificial Intelligence
- Hardware and Architecture
- Safety, Risk, Reliability and Quality
Fingerprint
Dive into the research topics of 'Adversarially evasive hardware trojans through approximate designs'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver