Aug 2026· Journal of electronic testing· Vol 42, pp. 469 - 485· 0 citations· 40 references
TL;DR
This paper evaluates the robustness of the Support Vector Machine (SVM) classifier, a leading algorithm in state-of-the-art HT detection frameworks, under gradient-based adversarial attacks, and highlights the need to reframe hardware security evaluations beyond nominal accuracy toward adversarial robustness.
Abstract
As semiconductor manufacturing becomes increasingly outsourced to untrusted entities, Hardware Trojan (HT) attacks pose a critical threat to the security and reliability of modern integrated circuits. Machine learning models have improved the effectiveness of HT detection using Ring Oscillator Network (RON) side-channel data, yet recent work shows that these models are highly vulnerable to adversarial attacks. This paper evaluates the robustness of the Support Vector Machine (SVM) classifier, a leading algorithm in state-of-the-art HT detection frameworks, under gradient-based adversarial attacks. The proposed work demonstrates that high nominal accuracy does not ensure security against these attacks, which can reduce recall to zero. To strengthen resilience, three data-augmentation methods are investigated: SMOTE, Conditional Tabular Generative Adversarial Network (CTGAN), and Tabular Variational Autoencoder (TVAE). TVAE produces high-fidelity synthetic samples and substantially improves robustness, maintaining over 91% accuracy for nominal performance and over 88% accuracy under strong adversarial perturbations that cause a 100% attack success rate for the surrogate model. The results highlight the need to reframe hardware security evaluations beyond nominal accuracy toward adversarial robustness.
A conditional generative adversarial networks method that integrates the machine learning with the deep learning to detect the hardware Trojans injected in Register-Transfer Level code and it contributes to enhancing the security and trustworthiness of ICs against hardware Trojan attacks.
Xiang Wang, Yan Li, Xiaobo Hu et al.· Tehnički Vjesnik· 0 citations
Results show that adversarial training improves robustness against input perturbations but increases sensitivity to stuck-at-zero weight faults, highlighting the need to jointly consider adversarial robustness and hardware reliability.
The study systematically compares two distinct adversarial training strategies: ‘pre-train’, where adversarial examples are generated beforehand, and ‘in-train’, where perturbations are introduced dynamically during the training process, to understand the advantages and limitations of each approach in enhancing model robustness.
José María Jorquera Valero, Ibon Bengoechea Cazorla, Manuel Gil Pérez· IEEE Access· 0 citations
Convolutional Neural Networks (CNNs) face a dual challenge: vulnerability to adversarial attacks and prohibitive training cost. Adversarial training is effective but expensive, a burden that grows as learning shifts to the energy-constrained edge. This paper addresses both through GPU undervolting during training. Reducing supply voltage introduces stochastic perturbations that act as implicit regularization, improving robustness while lowering power. We characterize undervolting-induced faults at the bit level, then train LeNet, VGG-6, and MobileNetV3 on MNIST and CIFAR-10 under two training regimes, standard and adversarial, each at nominal and undervolted voltage, and evaluate all models against adversarial attacks. In both regimes, the undervolted model consistently achieves higher adversarial accuracy than its nominal-voltage counterpart, showing that hardware-induced faults strengthen even adversarial training. Because dynamic power scales quadratically with supply voltage, these robustness gains arrive with substantial energy savings. GPU undervolting is therefore a readily deployable hardware-level defense requiring no algorithmic change, and opens a promising direction in which robustness and energy efficiency move together.
Behnam Omidi, Ahmad Tahmasivand, Husam Alsyouri et al.· 0 citations
This paper introduces DefendMal, a novel framework that synergistically combines Denoise Autoencoder with Sequence Squeezing, a Context-aware Adversarial Generator (CAG-AdvGAN), Projected Gradient Descent (PGD) adversarial training, and a Positive–Negative Detector with Variational Autoencoder (PNDetector-VAE) to enhance robustness against evolving adversarial threats.
Dennis Benedict Crasta, Vikash Kumar· Journal of Computer Virology...· 0 citations
Findings demonstrate that BGAN consistently enhances both class balance and adversarial robustness, while the proposed BGAN-TabTransformer framework provides an effective and adaptive intrusion detection solution for adversarial network environments.
Raihan Sultan Pasha Basuki, Aliyah Kurniasih· 0 citations