🤖 AI Summary
This work addresses the vulnerability of federated learning to Byzantine data poisoning attacks in collaborative counterfeit integrated circuit (IC) detection by proposing a lightweight client authentication framework. The method introduces, for the first time, an embedding-level authentication mechanism based on a reference distribution, integrating outlier detection, mean shift analysis, and micro-cluster behavior profiling. Crucially, it identifies and filters malicious participants prior to model aggregation without accessing raw data or gradients. Experimental results demonstrate that, in a setting with 50 participants, the approach achieves a 100% detection rate for malicious clients, and the resulting model attains a classification accuracy of 94.17% on counterfeit ICs after filtering. This significantly enhances the security and trustworthiness of collaborative models in supply chain scenarios.
📝 Abstract
The widespread of counterfeit integrated circuits (ICs) poses severe risks to the security, reliability, and trustworthiness of modern electronic systems. Federated learning (FL) offers a privacy-preserving paradigm for collaborative counterfeit detection across the semiconductor supply chain, but its vulnerability to byzantine data poisoning attacks limits practical deployment. This paper presents Federated Embedding Distribution Authentication (FedEDAuth), a lightweight, embedding level client authentication framework that detects and filters malicious participants before model aggregation. FedEDAuth leverages reference embedding distributions derived from a golden dataset and evaluates clients using outlier analysis, mean shift measurements, and micro-cluster behavior without requiring access to raw data or gradients. Integrated into standard FL pipelines, FedEDAuth consistently identifies all poisoned clients in experimental settings with 50 distributed participants under the byzantine data poisoning attack, achieving a 100% malicious client detection rate. After filtering, the federated model achieved a high counterfeit IC classification performance of 94.17% accuracy. These results not only validate FedEDAuth's effectiveness but also underscore the broader potential of secure, trustworthy FL frameworks as a critical advancement for next generation hardware security solutions, enabling robust, collaborative intelligence across the semiconductor supply chain.