Final year Project for Research - Hardware Trojan Detection and Attribution Framework Using Multi-Modal Side-Channel Analysis, Formal Verification, and Machine Learning
Current hardware Trojan detection approaches suffer from:
- High false positives
- Difficulty detecting stealth Trojans
- Poor scalability
- Limited explain ability
The research objective is to create a framework capable of:
- Detecting Hardware Trojans
- Classifying Trojan families
- Identifying trigger mechanisms
- Estimating attack severity
- Producing explainable evidence
Q1 - Can side-channel signals identify Hardware Trojans before activation? Q2 - Can machine learning classify Trojan types? Q3 - Can explainable AI identify malicious logic regions? Q4 - Which side-channel feature contributes most to detection accuracy?
Trojan Inserted
↓
Multi-Domain Measurements
↓
Feature Extraction
↓
ML Classification
↓
Explainability Engine
↓
Forensic Attribution
↓
Risk Assessment
┌─────────────┐
│ FPGA Device │
└──────┬──────┘
│
┌─────────────────┼─────────────────┐
│ │ │
▼ ▼ ▼
Power Trace Timing Trace EM Trace
│ │ │
└────────────┬────┴────┬────────────┘
▼
Feature Extraction
▼
Machine Learning Engine
▼
Explainability Layer
▼
Forensic Dashboard
- AES Encryption Core
- UART Controller
- Traffic Light Controller
- Memory Controller
- ALU Design
- RISC-V Processor Core
PicoRV32 is an excellent processor core for a Hardware Trojan Detection Homelab because it is a compact, open-source RISC-V CPU that is easy to understand, modify, simulate, and deploy on an FPGA. Its simplicity makes it ideal for experimenting with Trojan insertion and evaluating detection techniques without the complexity of a large commercial processor.
Create several Trojan families.
Information Leakage Trojan
Secret Key
↓
Hidden Register
↓
Leak Channel
Denial of Service Trojan
Trigger
↓
Infinite Loop
↓
System Halt
Data Manipulation Trojan
Input
↓
Modify Output
↓
Corrupt Data
Time Bomb Trojan
Counter
↓
100000 Cycles
↓
Activate
Rare Trigger Trojan
Trigger:
1010110010110011
It's difficult to detect.
This project includes:
Compare:
Golden RTL vs Trojan RTL
Example:
assert(output_data == expected_data);
Verify:
- State transitions
- Trigger conditions
- Reachability
Research angle:
Can formal verification discover hidden states?
Measure:
Voltage Current Power
Sampling:
10 kHz 100 kHz 1 MHz
Features:
- Critical path delay
- Slack
- Clock skew
Extract:
Toggle Rate Transition Density
Advanced track: Use inexpensive SDR.
Possible devices: * RTL-SDR * HackRF (if available)
Capture emissions from FPGA.
Create feature vectors.
Example:
Mean Power
Peak Power
Variance
Standard Deviation
Skewness
Kurtosis
Entropy
Transition Count
Trojan Present Trojan Absent
- Random Forest
- XGBoost
- Support Vector Machine
- Isolation Forest
- One-Class SVM
- Autoencoder
Use:
Input: Power Trace Image
Input: Time Series Signals
Use:
Outputs: Feature Importance
Most Suspicious Signal
Detection Confidence
Treat Hardware Trojan as a cybercrime scene.
Evidence Sources FPGA Bitstream Power Traces EM Traces Timing Reports Waveforms Logic Analyzer Data Simulation Results
Evidence Collection
↓
Hashing
↓
Storage
↓
Analysis
↓
Reporting
Use:
Example: sha256sum trojan.bit
Determine:
- Trojan Type
- Trigger Type
- Payload Type
- Severity
Example:
Family Data Leakage Trigger Rare Input Confidence 96.2% Severity High
TP+TN
-------
Total
TP
-----
TP+FP
TP
-----
TP+FN
Above 90%
Generate:
50 Golden Designs
Insert:
100 Trojan Variants
Collect:
1000+ Traces
Train ML Models
Evaluate Detection
Use: ANOVA T-Test Mann-Whitney U Test
Demonstrate significance.
Create web dashboard. Stack: * Python * Flask * SQLite * Plotly
Features:
Live Detection
Trojan Score
Evidence Viewer
Power Graphs
Threat Alerts
1000+ Power Traces
Verilog Python ML Models Dashboard
TrojanDetector.py
HardwareForensicsSuite