🤖 AI Summary
This study addresses the high cost of manual RTL analysis, vulnerability localization, and stealthy payload generation in hardware Trojan construction by proposing the first Data Flow Graph (DFG)-augmented Large Language Model framework. The method leverages structured CWE semantics to guide LLMs in automatically identifying vulnerabilities and performing intent-driven RTL modifications, thereby enabling the automated synthesis of minimal, interface-compatible, and stealthy Trojans with ultra-rare trigger conditions. Experimental results demonstrate that the generated Trojans achieve a 100% syntactic correctness rate, remain undetectable under large-scale random simulations while triggering precisely, and exhibit strong scalability.
📝 Abstract
The increasing sophistication of Hardware Trojans (HTs) and system-level vulnerabilities poses significant risks to modern integrated circuits. However, constructing realistic HT scenarios, remains a substantial burden: researchers must manually analyze complex RTL structures, identify plausible weaknesses, and craft stealthy, synthesizable insertions that preserve functional correctness. This paper introduces CITADEL CWE-Guided Insertion of Trojans via Analysis of DFG-Enabled LLMs, a framework that leverages Large Language Models (LLMs) and Data Flow Graphs (DFGs) to automate CWE-grounded HT synthesis. CITADEL uses structured CWE semantics together with DFG-derived structural context to assist the user in identifying relevant vulnerabilities, localize the module surrounding the chosen insertion point, and perform intent-conditioned RTL modification. The framework produces minimal, synthesizable, and interface-preserving HTs with ultra-rare triggers. Experimental evaluation across diverse RTL designs demonstrates that all generated HTs are 100% syntactically correct, remain undetectable under large-scale random simulation, and are functionally triggerable under their intended activation conditions. These results highlight CITADEL as a scalable and principled method for generating realistic HT benchmarks.