ALMOST: Adversarial Learning to Mitigate Oracle-less ML Attacks via Synthesis Tuning. Chowdhury, A. B., Alrahis, L., Collini, L., Knechtel, J., Karri, R., Garg, S., Sinanoglu, O., & Tan, B. March, 2023. arXiv:2303.03372 [cs]
ALMOST: Adversarial Learning to Mitigate Oracle-less ML Attacks via Synthesis Tuning [link]Paper  abstract   bibtex   
Oracle-less machine learning (ML) attacks have broken various logic locking schemes. Regular synthesis, which is tailored for area-power-delay optimization, yields netlists where key-gate localities are vulnerable to learning. Thus, we call for security-aware logic synthesis. We propose ALMOST, a framework for adversarial learning to mitigate oracle-less ML attacks via synthesis tuning. ALMOST uses a simulated-annealing-based synthesis recipe generator, employing adversarially trained models that can predict state-of-the-art attacks' accuracies over wide ranges of recipes and key-gate localities. Experiments on ISCAS benchmarks confirm the attacks' accuracies drops to around 50\% for ALMOST-synthesized circuits, all while not undermining design optimization.
@misc{chowdhury_almost_2023-1,
	title = {{ALMOST}: {Adversarial} {Learning} to {Mitigate} {Oracle}-less {ML} {Attacks} via {Synthesis} {Tuning}},
	shorttitle = {{ALMOST}},
	url = {http://arxiv.org/abs/2303.03372},
	abstract = {Oracle-less machine learning (ML) attacks have broken various logic locking schemes. Regular synthesis, which is tailored for area-power-delay optimization, yields netlists where key-gate localities are vulnerable to learning. Thus, we call for security-aware logic synthesis. We propose ALMOST, a framework for adversarial learning to mitigate oracle-less ML attacks via synthesis tuning. ALMOST uses a simulated-annealing-based synthesis recipe generator, employing adversarially trained models that can predict state-of-the-art attacks' accuracies over wide ranges of recipes and key-gate localities. Experiments on ISCAS benchmarks confirm the attacks' accuracies drops to around 50{\textbackslash}\% for ALMOST-synthesized circuits, all while not undermining design optimization.},
	urldate = {2023-08-22},
	publisher = {arXiv},
	author = {Chowdhury, Animesh Basak and Alrahis, Lilas and Collini, Luca and Knechtel, Johann and Karri, Ramesh and Garg, Siddharth and Sinanoglu, Ozgur and Tan, Benjamin},
	month = mar,
	year = {2023},
	note = {arXiv:2303.03372 [cs]},
	keywords = {\#broken, Computer Science - Cryptography and Security, Computer Science - Machine Learning, Jab/\#Pre},
}

Downloads: 0