Can Agents Secure Hardware? Evaluating Agentic LLM-Driven Obfuscation for IP Protection

📅 2026-04-14
📈 Citations: 0
Influential: 0
📄 PDF

career value

215K/year
🤖 AI Summary
This work addresses the growing threat of reverse engineering and tampering in globalized IC supply chains by proposing the first agent-based, large language model (LLM)-driven framework for automated generation of secure and functionally correct obfuscated circuits. The approach decomposes the obfuscation task into distinct phases—circuit analysis, synthesis, verification, and attack evaluation—and integrates retrieval-augmented planning with structured logic locking to overcome the limitations of conventional single-step prompting. Evaluated on the ISCAS-85 benchmark suite, the method successfully produces functionally equivalent locked netlists that effectively corrupt outputs under incorrect keys. Although susceptibility to SAT attacks persists, the results demonstrate the feasibility and promise of end-to-end automated circuit obfuscation.

Technology Category

Application Category

📝 Abstract
The globalization of integrated circuit (IC) design and manufacturing has increased the exposure of hardware intellectual property (IP) to untrusted stages of the supply chain, raising concerns about reverse engineering, piracy, tampering, and overbuilding. Hardware netlist obfuscation is a promising countermeasure, but automating the generation of functionally correct and security-relevant obfuscated circuits remains challenging, particularly for benchmark-scale designs. This paper presents an agentic, large language model (LLM)-driven framework for automated hardware netlist obfuscation. The proposed framework combines retrieval-grounded planning, structured lock-plan generation, deterministic netlist compilation, functional verification, and SAT-based security evaluation. Rather than a single prompt-to-output generation step, the framework decomposes the task into specialized stages for circuit analysis, synthesis, verification, and attack evaluation. We evaluate the framework on ISCAS-85 benchmarks using functional equivalence checking and SAT-based attacks. Results show that the framework generates correct locked netlists while introducing measurable output corruption under incorrect keys, while SAT attacks remain effective. These findings highlight both the potential and current limitations of agentic LLM-driven obfuscation.
Problem

Research questions and friction points this paper is trying to address.

hardware intellectual property
netlist obfuscation
supply chain security
reverse engineering
IC design
Innovation

Methods, ideas, or system contributions that make the work stand out.

Agentic LLM
Hardware Obfuscation
Netlist Locking
SAT-based Security Evaluation
IP Protection
🔎 Similar Papers
S
Sujan Ghimire
Department of Electrical and Computer Engineering, University of Arizona, Tucson, AZ, USA
P
Parsa Mirfasihi
Department of Electrical and Computer Engineering, University of Arizona, Tucson, AZ, USA
M
Muhtasim Alam Chowdhury
Department of Electrical and Computer Engineering, University of Arizona, Tucson, AZ, USA
V
Veeramani Pugazhenthi
Department of Electrical and Computer Engineering, University of Arizona, Tucson, AZ, USA
H
Harish Kumar Dharavath
Department of Electrical and Computer Engineering, University of Arizona, Tucson, AZ, USA
Farshad Firouzi
Farshad Firouzi
Duke University
Artificial IntelligenceMicroelectronicsAI for Chip DesignAI of Things (AIoT)eHealth
Rozhin Yasaei
Rozhin Yasaei
Assistant Professor at University of Arizona
Machine LearningGraph Neural NetworkHardware SecurityEmbedded and Cyber-Physical Systems
Pratik Satam
Pratik Satam
Assistant Professor, University of Arizona
Smart ManufacturingCyber SecurityMachine Learning
Soheil Salehi
Soheil Salehi
Assistant Professor, ECE, University of Arizona
IoT Hardware SecurityAI-enabled SecurityReconfigurable ComputingSpintronicsNeuromorphic Hardware