AI can detect malicious chip vulnerabilities with a 97% success rate - but will that be enough? (www.techradar.com)

🤖 AI Summary
Researchers at the University of Missouri announced PEARL, an LLM-driven system that detects hardware trojans in chip designs by analyzing Verilog code using in-context learning (zero-, one- and few-shot) rather than training models from scratch. PEARL combines enterprise and open-source models — including GPT-3.5 Turbo, Gemini 1.5 Pro, Llama 3.1 and DeepSeek-V2 — and was evaluated on benchmark suites such as Trust-Hub and ISCAS 85/89. Enterprise models reached up to 97% accuracy (GPT-3.5 Turbo), while some open-source models achieved around 91%. The system also produces human-readable explanations for flagged code and importantly operates without a “golden model” (a clean reference chip), improving practical applicability across diverse supply-chain scenarios. The work is significant because hardware trojans—malicious modifications introduced during distributed manufacturing—can remain dormant until activation and compromise critical infrastructure from data centers to defense systems. PEARL demonstrates that LLMs can be a fast, interpretable layer in the security toolbox for rooting out hidden logic-level threats, but the authors and experts caution that even a 3% miss rate can be catastrophic in high-stakes contexts. The paper underscores that AI-based detection is a major step forward but not a standalone solution; robust deployment will require multi-layered verification, manual review, and continued research to counter increasingly sophisticated trojans.
Loading comments...
loading comments...