Presentation
Nothing Left to Learn: Isomorphic Graph Transformations for Hardware IP Protection
DescriptionLogic locking protects hardware designs across the global semicon-
ductor supply-chain. However, recent machine learning (ML)-based
attacks, especially graph learning-based ones, have undermined
its security by learning circuit structures and gate compositions to
reveal locked connections/gates. Although recent locking methods
use explainability tools and adversarial perturbations, they remain
vulnerable to ML attacks under robust training. Therefore, there is
still a need for truly learning-resilient locking solutions.
We propose IsoLock, a locking scheme that performs intercon-
nect obfuscation to secure the circuit's structure and functionality.
IsoLock models the gate-level netlist as a graph and introduces
MUXes for locking (through rewiring selected interconnects), gen-
erating isomorphic structures. These structures are indistinguish-
able to ML models and other structural attacks, effectively blocking
all learnable/predictable features and preventing key deciphering.
For evaluation, first, we prove IsoLock's security against modeling
attacks. Second, we lock standard ISCAS-85 and ITC-99 benchmarks
and evaluate them against state-of-the-art ML attacks (SCOPE and
MuxLink) and structural attacks (Redundancy and SAAM), all of
which can decipher only 0–6% of the correct key on average, con-
firming IsoLock's resilience also in practice.
ductor supply-chain. However, recent machine learning (ML)-based
attacks, especially graph learning-based ones, have undermined
its security by learning circuit structures and gate compositions to
reveal locked connections/gates. Although recent locking methods
use explainability tools and adversarial perturbations, they remain
vulnerable to ML attacks under robust training. Therefore, there is
still a need for truly learning-resilient locking solutions.
We propose IsoLock, a locking scheme that performs intercon-
nect obfuscation to secure the circuit's structure and functionality.
IsoLock models the gate-level netlist as a graph and introduces
MUXes for locking (through rewiring selected interconnects), gen-
erating isomorphic structures. These structures are indistinguish-
able to ML models and other structural attacks, effectively blocking
all learnable/predictable features and preventing key deciphering.
For evaluation, first, we prove IsoLock's security against modeling
attacks. Second, we lock standard ISCAS-85 and ITC-99 benchmarks
and evaluate them against state-of-the-art ML attacks (SCOPE and
MuxLink) and structural attacks (Redundancy and SAAM), all of
which can decipher only 0–6% of the correct key on average, con-
firming IsoLock's resilience also in practice.
Event Type
Research Manuscript
TimeTuesday, July 2811:36am - 11:50am PDT
LocationMtg Room 203C
