MARC: 基于多智能体协同的硬件安全缺陷早期检测方法
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP311

基金项目:

国家自然科学基金(62202457); “源图”重大基础设施


MARC: Multi-agent Collaborative Approach for Early Detection of Hardware Security Vulnerabilities
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    随着开源RISC-V架构的迅猛发展, 其开放与模块化的特性在催生繁荣硬件生态的同时, 也给硬件电路的安全性保障带来巨大挑战. 在硬件设计流程的前期进行安全缺陷早期检测, 能够以最低成本在缺陷固化于物理芯片前将其消除. 尽管静态分析已用于硬件安全缺陷早期检测, 但由于规约知识未充分利用以及代码上下文语义理解不足, 现有检测方法存在高漏报率和高误报率的问题. 针对这些问题, 提出MARC, 一种基于大语言模型多智能体协同的硬件安全缺陷早期检测方法. 该方法通过构建设计依赖分析、文档分析、安全缺陷检测、安全缺陷确认这4类智能体及协同工作框架, 从补充跨模块上下文、结构化模块文档知识、快速初筛安全缺陷、深度推理安全缺陷风险分析等多维度协同作用, 有效降低硬件电路设计阶段早期安全缺陷检测的误报率, 提升检测准确性. 实验结果显示, MARC方法在工业级数据集上将早期缺陷检测的漏报率和误报率分别降低至0.3829和0.3695, 相较于基准方法分别降低了约18.2%和19.1%. 上述实验结果充分表明, MARC 有效缓解了硬件安全缺陷早期检测中的误报问题, 提升了安全缺陷检测的准确性与效率, 为硬件安全提供了更可靠的技术支撑. 另外, 还支撑作者团队夺得HACK@DATE 2025硬件漏洞挖掘竞赛全球冠军, 成功挖掘了1个获CVE编号的硬件漏洞, 在真实世界中验证了其有效性.

    Abstract:

    With the rapid proliferation of the open-source RISC-V architecture, its openness and modular design foster a thriving hardware ecosystem while simultaneously posing significant challenges to hardware security assurance. Early detection of security vulnerabilities during the initial stages of the hardware design flow enables vulnerabilities to be eliminated at minimal cost before being permanently embedded into physical silicon. Although static analysis techniques are applied to early-stage hardware security vulnerability detection, existing methods suffer from high false negative rate (FNR) and false discovery rate (FDR) due to insufficient utilization of specification knowledge and an inadequate semantic understanding of code context. To address these challenges, this study proposes MARC, an early detection method for hardware security vulnerabilities based on collaborative multi-agent systems powered by large language models (LLMs). The proposed method constructs a collaborative framework consisting of four specialized agents: design dependency analysis, documentation analysis, security vulnerability detection, and security vulnerability confirmation. Through multi-dimensional collaboration, including cross-module context augmentation, structured utilization of module documentation knowledge, rapid preliminary screening of potential vulnerabilities, and deep reasoning-based risk analysis. Experiments conducted on an industrial-grade dataset demonstrate that the MARC framework achieves an FNR of 0.3829 and an FDR of 0.3695, representing reductions of approximately 18.2% and 19.1%, respectively, compared to the baseline method. The proposed framework effectively reduces false positives and improves detection accuracy in early-stage hardware design. Furthermore, its real-world effectiveness is validated by the discovery of a hardware vulnerability that has been assigned a CVE identifier. By its successful application, the authors’ team won the global championship in the HACK@DATE 2025 hardware security competition.

    参考文献
    相似文献
    引证文献
引用本文

芮志清,凌祥,曹方泽,罗天悦,吴敬征. MARC: 基于多智能体协同的硬件安全缺陷早期检测方法.软件学报,2026,37(6):2370-2389

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-09-08
  • 最后修改日期:2025-10-20
  • 录用日期:
  • 在线发布日期: 2025-12-26
  • 出版日期: 2026-06-06
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号