Close

Presentation

Secure and Private System Design for Generative & Agentic AI
DescriptionWorkshop Website: https://www.qlou.org/SPGAI/

Generative and agentic AI systems are rapidly transforming the semiconductor, electronic design automation (EDA) ecosystem and beyond. Modern design workflows increasingly rely on large language models (LLMs), multimodal generators, and autonomous agentic systems for RTL generation, verification, debugging, documentation, and design-space exploration. As these AI systems interact directly with proprietary IP, sensitive design assets, and automated toolflows, ensuring security, privacy, trustworthiness, and verifiability becomes essential for both academia and industry. This workshop provides the first dedicated DAC forum on secure and private generative and agentic AI, uniting experts across AI security, hardware design, cryptography, and EDA to address the urgent risks and opportunities emerging in this evolving domain.

The workshop covers a broad set of topics central to DAC. We examine model watermarking, fingerprinting, and provenance tracking as mechanisms for protecting AI-generated design artifacts and enforcing model copyright. We highlight recent advances in verifiable computing—such as zero-knowledge proofs and trusted hardware—that provide integrity guarantees for AI-assisted design flows. We also survey major progress in privacy-preserving AI, including fully homomorphic encryption (FHE), secure multi-party computation (MPC), and confidential accelerators capable of supporting scalable execution of LLMs and agentic systems. These technologies are increasingly important for semiconductor companies working across distributed, international, or multi-tenant IP environments.

A key part of the workshop focuses on the expanding threat landscape associated with AI-driven design workflows. We analyze backdoors, jailbreaks, prompt manipulation, data poisoning, model extraction, adversarial evasion, and reconstruction attacks—threats that pose immediate risks to chip design pipelines enabled by generative AI. We further explore hardware-assisted defenses, secure enclaves, runtime monitors, and EDA-driven verification flows. Beyond model-level issues, we emphasize agentic AI risks, including unsafe tool usage, insecure function-calling, compromised memory components, rogue autonomous tasks, and cross-agent interference, especially when such agents interface with simulators, synthesis tools, or automated test frameworks.

This workshop differs from traditional hardware security, which typically focuses on supply-chain risks, microarchitectural attacks, or hardware Trojans. Instead, we address AI-native security challenges arising from the behavior, training, and deployment of generative and agentic models themselves. Topics such as LLM copyright protection, trust boundaries for autonomous agents, cryptographic acceleration for secure inference, and IP protection for AI-generated content represent a new frontier that spans AI, cryptography, architecture, and design automation. This cross-layer approach is essential for trustworthy, AI-enabled semiconductor innovation.

The workshop is highly relevant to DAC as semiconductor and EDA companies integrate AI into core design workflows. Ensuring these AI systems are secure, private, and verifiable is now a fundamental requirement. With its combination of academic rigor, practical insights, leading speakers, and direct relevance to emerging design practices, the workshop will attract a broad audience across AI, hardware, security, and EDA communities. By bringing these domains together, it establishes foundational principles for secure and scalable generative and agentic AI systems.