Exploiting Software-level Abstractions To Support Practical Hardware Trojan Attacks

📅 2026-09-19
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
研究提出SURF类CPU木马,无需执行任意代码即可激活,利用高级语言整数操作映射到微架构副作用,实现对终端设备的长期威胁。
📝 Abstract
Hardware trojan (HT) attacks against CPUs typically assume threat scenarios where an attacker targeting a system with a trojanized CPU is able to execute arbitrary code (i.e. machine-level instructions) to reliably interact with the implanted trojan. On end-user devices (i.e., mobiles, laptops), achieving arbitrary code execution in practice requires software exploits tailored to each specific target. Such strong adversarial premises reduce the generality of existing threat models casting doubt on CPU trojan attacks as a pragmatic threat vector. To push the envelope on HT attacks against client devices, we introduce the SURF class of CPU-trojans that can be activated without arbitrary code execution. Our key insight is that integer operations expressed in a high-level language can be mapped to microarchitectural side-effects distinguishable by a SURF trigger circuit. This observation unlocks HT activation via runtime engines, constrained environments executing untrusted high-level code. We demonstrate a SURF trojan inside a RISC-V processor and exploit JavaScript-level memory indexing operations inside Google's V8 engine to perform a code injection attack. Importantly, we show that SURF trojans remain effective across multiple JavaScript engine versions, enabling long-term compromise of endpoint devices. To facilitate research, we opensource SURF's design and supporting software.
Problem

Research questions and friction points this paper is trying to address.

Hardware Trojan
Arbitrary Code Execution
Client Devices
Threat Models
Microarchitectural Side-Effects
Innovation

Methods, ideas, or system contributions that make the work stand out.

CPU Trojan
High-level Language Operations
Microarchitectural Side-effects
Runtime Engines
Code Injection
🔎 Similar Papers
No similar papers found.