Close

Presentation

Are They All Safe? Practical Fault Injection Attacks on FPGA Logic Synthesis Tools
DescriptionFPGAs are widely deployed in critical systems, but flaws in EDA toolchains can enable malicious HDL injection, leading to severe hardware vulnerabilities. We propose DefVul-Risk, an automated framework for assessing fault-injection risks in FPGA synthesis tools. It constructs a defect knowledge base, generates triggerable vulnerability samples via large language models, and fine-tunes risk-assessment models to prioritize high-risk defects. DefVul-Risk enhances toolchain security evaluation and vulnerability remediation efficiency. We submitted 26 CVE reports, with 9 officially confirmed.