[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84961-en":3,"doc-seo-84961-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},84961,7971461740886,"Theodore","https://ap-avatar.wpscdn.com/davatar_3d24733baf745e90a7e4bdd5f77d97b2",8,"Research & Report","An Automated Framework for Generating Stealthy Cell-Embedded Hardware Trojans","Hardware Trojans (HTs) threaten integrated circuits across the IC design lifecycle, especially under a zero-trust model where untrusted entities can insert malicious logic at different stages. Traditional assessments model Trojans as explicit additions in RTL or gate-level netlists, but this misses attacks that hide behavior inside standard-cell implementations from a compromised library. This paper introduces an automated framework that analyzes mapped designs, selects cell instances with rare trigger conditions, and applies payload templates to corrupt outputs only when triggers activate.","An Automated Framework for Generating Stealthy Cell-Embedded Hardware Trojans  \nRaghul Saravanan∗ , Sudipta Paria†, Sai Manoj P D∗ and Swarup Bhunia†  \n∗ Department of Electrical and Computer Engineering, George Mason University, Fairfax, VA  \n†Department of Electrical and Computer Engineering, University of Florida, Gainesville, FL rsaravan@gmu.edu, sudiptaparia@ufl.edu, spudukot@gmu.edu, swarup@ece.ufl.edu  \narXiv :2607 .07049v 1 [ cs .CR] 8 Jul 2026  \nAbstract—Hardware Trojans (HTs) pose significant threats across the Integrated Circuit (IC) design lifecycle because they can be inserted by untrusted entities at different stages under the zero-trust model. When triggered under rare conditions, HTs can compromise the functionality, reliability, or security of the fabricated chip. HT assessment is typically performed by modeling realistic Trojan insertion scenarios in RTL implementation or gatelevel netlists. While this model is useful for evaluating detection methods, it does not capture attacks where malicious behavior is hidden inside standard-cell implementations from a compromised library supplied by an untrusted vendor. This paper presentsa novel framework for automatically generating cell-embedded hardware Trojans using compromised standard-cell implementations. Our proposed framework analyzes a mapped design, identifies candidate cell instances with rare input conditions, and applies payload templates that corrupt the selected cell output only when the trigger condition is satisfied. Experiments on opensource combinational and sequential benchmark designs show that our proposed framework can generate valid and stealthy Trojan instances across different cell types and design sizes. The results highlight a critical gap in current Trojan detection assumptions and show the need for cell-aware validation of standard-cell implementations in zero-trust IC design flows.  \nIndex Terms—Hardware Security, Cell-embedded Trojans, Standard-Cell Library, Gate-Level Netlist, Stealthy Trojans.  \nI. INTRODUCTION  \nHardware Trojan (HT) attacks pose a significant and growing threat to the security and integrity of integrated circuits (ICs) . Trojans can be inserted by untrusted parties at various stages of the IC design flow under the zero-trust model, as depicted in Fig. 1. Traditionally, HTs are modeled as explicit modifications to RTL or gate-level netlists by inserting additional trigger and payload logic [1]. However, an adversary controlling the standard-cell library or untrusted foundry can instead compromise the implementation of library cells themselves, allowing malicious behavior to be introduced without altering the synthesized netlist [2] . In such a scenario, the IP designer provides a trusted RTL design, while the adversary tampers with the standard-cell library before synthesis. The modified library is subsequently characterized and compiled into the timing library used by commercial synthesis tools. Since the compromised cells preserve their intended functionality during normal operation, the synthesis tool treats them as legitimate implementations and instantiates them during technology mapping without detecting the embedded malicious logic. As a result, Trojans become embedded within the final hardware implementation while the synthesized netlist  \nremains structurally identical to that produced using a trusted library. Benchmarking efforts [3]–[5] addressed the need for standardized evaluation by providing collections of designs containing predefined Trojans. Automated frameworks such as [6] further generalize this process by dynamically inserting diverse Trojan structures into gate-level netlists using rarenet analysis. Nevertheless, these approaches remain restricted to inserting explicit trigger and payload circuitry at the RTL or gate-level abstractions and therefore cannot model attacks originating from compromised standard-cell libraries. Consequently, they fail to represent an increasingly realistic threat in wh","cbCais9hEt70bvlo","https://ap.wps.com/l/cbCais9hEt70bvlo","pdf",852407,1,6,"English","en",105,"# Introduction\n## Zero-trust threat model and compromised standard-cell libraries\n## Limitations of existing Trojan detection assumptions\n## Proposed cell-embedded Trojan generation framework","[{\"question\":\"How does the paper model a more realistic zero-trust hardware Trojan attack?\",\"answer\":\"It assumes an untrusted library provider or foundry can modify internal standard-cell implementations before synthesis while preserving normal functionality and the synthesized netlist structure.\"},{\"question\":\"What is the core idea of the proposed automated framework?\",\"answer\":\"The framework analyzes a mapped design to find candidate cell instances with rare input conditions, then applies payload templates that corrupt selected cell outputs only when the trigger condition is satisfied.\"},{\"question\":\"Why do existing detection techniques struggle against cell-embedded Trojans?\",\"answer\":\"Because the compromised cells preserve the netlist structure, inserted malicious behavior is hidden within internal cell implementations, making structural, statistical, and learning-based methods unable to directly observe the Trojan.\"}]",1784199715,15,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"an-automated-framework-for-generating-stealthy-cell-embedded-hardware-trojans","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/an-automated-framework-for-generating-stealthy-cell-embedded-hardware-trojans/84961/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"How does the paper model a more realistic zero-trust hardware Trojan attack?","Question",{"text":75,"@type":76},"It assumes an untrusted library provider or foundry can modify internal standard-cell implementations before synthesis while preserving normal functionality and the synthesized netlist structure.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the core idea of the proposed automated framework?",{"text":80,"@type":76},"The framework analyzes a mapped design to find candidate cell instances with rare input conditions, then applies payload templates that corrupt selected cell outputs only when the trigger condition is satisfied.",{"name":82,"@type":73,"acceptedAnswer":83},"Why do existing detection techniques struggle against cell-embedded Trojans?",{"text":84,"@type":76},"Because the compromised cells preserve the netlist structure, inserted malicious behavior is hidden within internal cell implementations, making structural, statistical, and learning-based methods unable to directly observe the Trojan.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":21,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]