MARC: Multi-agent Collaborative Approach for Early Detection of Hardware Security Vulnerabilities
Author:
Affiliation:

Clc Number:

TP311

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    With the rapid proliferation of the open-source RISC-V architecture, its openness and modular design foster a thriving hardware ecosystem while simultaneously posing significant challenges to hardware security assurance. Early detection of security vulnerabilities during the initial stages of the hardware design flow enables vulnerabilities to be eliminated at minimal cost before being permanently embedded into physical silicon. Although static analysis techniques are applied to early-stage hardware security vulnerability detection, existing methods suffer from high false negative rate (FNR) and false discovery rate (FDR) due to insufficient utilization of specification knowledge and an inadequate semantic understanding of code context. To address these challenges, this study proposes MARC, an early detection method for hardware security vulnerabilities based on collaborative multi-agent systems powered by large language models (LLMs). The proposed method constructs a collaborative framework consisting of four specialized agents: design dependency analysis, documentation analysis, security vulnerability detection, and security vulnerability confirmation. Through multi-dimensional collaboration, including cross-module context augmentation, structured utilization of module documentation knowledge, rapid preliminary screening of potential vulnerabilities, and deep reasoning-based risk analysis. Experiments conducted on an industrial-grade dataset demonstrate that the MARC framework achieves an FNR of 0.3829 and an FDR of 0.3695, representing reductions of approximately 18.2% and 19.1%, respectively, compared to the baseline method. The proposed framework effectively reduces false positives and improves detection accuracy in early-stage hardware design. Furthermore, its real-world effectiveness is validated by the discovery of a hardware vulnerability that has been assigned a CVE identifier. By its successful application, the authors’ team won the global championship in the HACK@DATE 2025 hardware security competition.

    Reference
    Related
    Cited by
Get Citation

芮志清,凌祥,曹方泽,罗天悦,吴敬征. MARC: 基于多智能体协同的硬件安全缺陷早期检测方法.软件学报,2026,37(6):2370-2389

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:September 08,2025
  • Revised:October 20,2025
  • Adopted:
  • Online: December 26,2025
  • Published: June 06,2026
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-4
Address:4# South Fourth Street, Zhong Guan Cun, Beijing 100190,Postal Code:100190
Phone:010-62562563 Fax:010-62562533 Email:jos@iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063