TroPUF: Evaluating Hardware Trojan Insertion in Delay-Based Physical Unclonable Functions
This work addresses the vulnerability of delay-based physically unclonable functions (PUFs) to stealthy hardware Trojan insertion, which exploits process-induced timing uncertainties—a threat inadequately mitigated by existing security verification methods. For the first time, the study integrates PUF security and hardware Trojan risks into a unified circuit-level simulation framework to systematically evaluate multiple delay-based PUF architectures in terms of functional reliability, hardware overhead, and resistance to machine learning modeling, both before and after Trojan implantation. Experimental results demonstrate that dormant Trojans can preserve normal PUF behavior and modeling resilience, revealing critical blind spots in current PUF validation approaches that fail to detect such threats prior to Trojan activation.