論文の概要: Kerckhoffs-Compliant Watermarking for Physical Design IP Protection: From Placement to Routing
- arxiv url: http://arxiv.org/abs/2608.05055v1
- Date: Wed, 05 Aug 2026 17:03:56 GMT
- ステータス: 翻訳完了
- システム内更新日: 2026-08-06 14:48:44.037205
- Title: Kerckhoffs-Compliant Watermarking for Physical Design IP Protection: From Placement to Routing
- Title(参考訳): Kerckhoffs-Compliant Watermarking for Physical Design IP Protection: from Placement to Routing
- Authors: Andrew B. Kahng, Yiting Liu,
- Abstract要約: PDツールへのアクセスが拡大するにつれて、配置および削除されたデータベースの不正な再利用が懸念される。
既存のPD透かし方式は、PDステージを1つだけ保護するか、隠された建設の詳細に依存する。
我々は秘密鍵のみに依存するKerckhoffs準拠の透かしフレームワークPDMarksを開発した。
- 参考スコア(独自算出の注目度): 6.5228159720498935
- License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
- Abstract: Physical design (PD) intellectual property (IP) is a valuable artifact of modern VLSI implementation. It includes optimized cell placement, clock distribution, and routing decisions produced by carefully tuned PD flows. As access to PD tools expands, unauthorized reuse of placed-and-routed databases becomes an increasing concern. Existing PD watermarking methods either protect only one PD stage or rely on hidden construction details, leaving them vulnerable to a white-box adversary. In this work, we develop PDMarks, a Kerckhoffs-compliant watermarking framework whose security depends only on a secret key. PDMarks embeds ownership evidence across multiple stages of the PD flow, including placement, clock tree synthesis (CTS), and routing. All watermark instances and target values are deterministically derived from a 32-byte secret key using HMAC-SHA256, enabling consistent embedding and verification. PDMarks has been integrated into OpenROAD-flow-scripts. Experiments on NanGate45 and ASAP7 designs show that PDMarks outperforms prior physical design watermarking methods by providing much stronger ownership evidence with comparable or smaller PPA overhead. The approximate joint all-stage coincidence probability is below 10^{-32} for every evaluated design. Wrong-key and attack evaluations further show that incorrect keys do not reproduce the complete ownership proof and that weakening the watermark requires broad perturbation of the protected implementation.
- Abstract(参考訳): 物理設計(PD)知的財産権(IP)は、現代のVLSI実装の貴重な成果である。
これには、最適化されたセル配置、クロック分布、注意深く調整されたPDフローによって生成されるルーティング決定が含まれる。
PDツールへのアクセスが拡大するにつれて、配置および削除されたデータベースの不正な再利用が懸念される。
既存のPD透かし方式は、PDステージを1つだけ保護するか、隠された建設の詳細に依存し、ホワイトボックスの敵に弱いままにしておく。
本研究では,秘密鍵のみに依存するKerckhoffs準拠の透かしフレームワークPDMarksを開発する。
PDMarksはPDフローの複数のステージに、配置、クロックツリー合成(CTS)、ルーティングを含むオーナシップエビデンスを埋め込んでいる。
すべてのウォーターマークインスタンスとターゲット値は、HMAC-SHA256を使用して32バイトのシークレットキーから決定的に派生し、一貫した埋め込みと検証を可能にする。
PDMarksはOpenROAD-flow-scriptsに統合されている。
NanGate45 と ASAP7 の設計実験により、PDMarks は PPA のオーバヘッドと同等またはより小さいオーバヘッドで、より強力なオーバヘッドの証拠を提供することにより、以前の物理設計の透かし法よりも優れた性能を示した。
ほぼ一致した全段階一致確率は、評価された設計ごとに10^{-32}未満である。
誤り鍵と攻撃評価は、不正鍵が完全な所有権証明を再現せず、透かしを弱めるためには保護された実装を広範囲に摂動する必要があることを示す。
関連論文リスト
- SWAP: Towards Copyright Auditing of Soft Prompts via Sequential Watermarking [58.475471437150674]
ソフトプロンプト(SWAP)のための逐次透かしを提案する。
SWAPは、特定のディフェンダー指定のアウト・オブ・ディストリビューション・クラスを通じて、透かしを符号化する。
11のデータセットの実験では、SWAPの有効性、無害性、および潜在的適応攻撃に対する堅牢性を示す。
論文 参考訳(メタデータ) (2025-11-05T13:48:48Z) - StableGuard: Towards Unified Copyright Protection and Tamper Localization in Latent Diffusion Models [55.05404953041403]
拡散生成プロセスにバイナリ透かしをシームレスに統合する新しいフレームワークを提案する。
画像の忠実さ、透かしの検証、ローカライゼーションの改ざんにおいて、StableGuardは一貫して最先端の手法より優れていることを示す。
論文 参考訳(メタデータ) (2025-09-22T16:35:19Z) - Your Semantic-Independent Watermark is Fragile: A Semantic Perturbation Attack against EaaS Watermark [5.2431999629987]
様々な研究が、Eサービスの著作権を保護するためのバックドアベースの透かし方式を提案している。
本稿では,従来の透かし方式が意味非依存の特徴を持つことを示すとともに,セマンティック摂動攻撃(SPA)を提案する。
我々の理論的および実験的分析は、この意味に依存しない性質が、現在の透かしスキームを適応攻撃に脆弱にし、セマンティック摂動テストを利用して透かし検証を回避していることを示している。
論文 参考訳(メタデータ) (2024-11-14T11:06:34Z) - A Resilient and Accessible Distribution-Preserving Watermark for Large Language Models [65.40460716619772]
本研究は,textbfDistribution-textbf Preserving (DiP)ウォーターマークの重要性に焦点をあてる。
現在の戦略とは対照的に,提案したDiPmarkは透かし中に元のトークン分布を同時に保存する。
言語モデルAPIにアクセスせずに検出可能で(アクセス可能)、トークンの適度な変更に対して確実に堅牢である。
論文 参考訳(メタデータ) (2023-10-11T17:57:35Z) - Safe and Robust Watermark Injection with a Single OoD Image [90.71804273115585]
高性能なディープニューラルネットワークをトレーニングするには、大量のデータと計算リソースが必要である。
安全で堅牢なバックドア型透かし注入法を提案する。
我々は,透かし注入時のモデルパラメータのランダムな摂動を誘導し,一般的な透かし除去攻撃に対する防御を行う。
論文 参考訳(メタデータ) (2023-09-04T19:58:35Z)
関連論文リストは本サイト内にある論文のタイトル・アブストラクトから自動的に作成しています。
指定された論文の情報です。
本サイトの運営者は本サイト(すべての情報・翻訳含む)の品質を保証せず、本サイト(すべての情報・翻訳含む)を使用して発生したあらゆる結果について一切の責任を負いません。