{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T15:33:15Z","timestamp":1780673595080,"version":"3.54.1"},"reference-count":39,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,3,31]],"date-time":"2025-03-31T00:00:00Z","timestamp":1743379200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,3,31]],"date-time":"2025-03-31T00:00:00Z","timestamp":1743379200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,3,31]]},"DOI":"10.23919\/date64628.2025.10993260","type":"proceedings-article","created":{"date-parts":[[2025,5,21]],"date-time":"2025-05-21T17:36:35Z","timestamp":1747848995000},"page":"1-7","source":"Crossref","is-referenced-by-count":9,"title":["RTL-Breaker: Assessing the Security of LLMs Against Backdoor Attacks on HDL Code Generation"],"prefix":"10.23919","author":[{"given":"Lakshmi Likhitha","family":"Mankali","sequence":"first","affiliation":[{"name":"New York University Tandon School of Engineering"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jitendra","family":"Bhandari","sequence":"additional","affiliation":[{"name":"New York University Tandon School of Engineering"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Manaar","family":"Alam","sequence":"additional","affiliation":[{"name":"New York University Abu Dhabi"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ramesh","family":"Karri","sequence":"additional","affiliation":[{"name":"New York University Tandon School of Engineering"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michail","family":"Maniatakos","sequence":"additional","affiliation":[{"name":"New York University Abu Dhabi"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ozgur","family":"Sinanoglu","sequence":"additional","affiliation":[{"name":"New York University Abu Dhabi"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Johann","family":"Knechtel","sequence":"additional","affiliation":[{"name":"New York University Abu Dhabi"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI61997.2024.00076"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3643681"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC58780.2024.10473904"},{"key":"ref4","article-title":"Autochip: Automating hdl generation using llm feed-back","author":"Thakur","year":"2023","journal-title":"arXiv preprint"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/MLCAD58807.2023.10299874"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD57390.2023.10323812"},{"key":"ref7","article-title":"Llm-assisted generation of hardware assertions","author":"Kande","year":"2023","journal-title":"arXiv preprint"},{"key":"ref8","article-title":"Assertllm: Generating and evaluating hardware verification assertions from design specifications via multi-llms","author":"Fang","year":"2024","journal-title":"arXiv preprint"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3670474.3685956"},{"key":"ref10","article-title":"Llm-aided testbench generation and bug detection for finite-state machines","author":"Bhandari","year":"2024","journal-title":"arXiv preprint"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2024.3383347"},{"key":"ref12","article-title":"Chipnemo: Domain-adapted llms for chip design","author":"Liu","year":"2023","journal-title":"arXiv preprint"},{"key":"ref13","first-page":"1559","article-title":"You autocomplete me: Poisoning vulnerabilities in neural code completion","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Schuster","year":"2021"},{"key":"ref14","volume-title":"Trojanpuzzle: Covertly poisoning code-suggestion models","author":"Aghakhani","year":"2024"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2024.3367788"},{"key":"ref16","first-page":"1795","article-title":"An LLM-Assisted Easy-to-Trigger backdoor attack on code completion models: Injecting disguised vulnerabilities against strong detection","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Yan","year":"2024"},{"key":"ref17","first-page":"1849","article-title":"Instruction backdoor attacks against customized LLMs","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Zhang","year":"2024"},{"issue":"1","key":"ref18","doi-asserted-by":"crossref","first-page":"37","DOI":"10.46586\/tches.v2025.i1.37-77","article-title":"Trojan insertion versus layout defenses for modern ICs: Red-versus-blue teaming in a competitive community effort","volume":"2025","author":"Knechtel","year":"2024","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded Systems"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.10"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00052"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2335155"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3439706.3446902"},{"key":"ref23","first-page":"23","article-title":"Breakthrough silicon scanning discovers back-door in military chip","volume-title":"Proceedings of the 14th International Conference on Cryptographic Hardware and Embedded Systems, ser. CHES\u2019 12","author":"Skorobogatov","year":"2012"},{"key":"ref24","volume-title":"Codegen: An open large language model for code with multi-turn program synthesis","author":"Nijkamp","year":"2023"},{"key":"ref25","volume-title":"Code llama: Open foundation models for code","author":"Rozi\u00e8re","year":"2024"},{"key":"ref26","volume-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023"},{"key":"ref27","volume-title":"Rtlcoder: Outperforming gpt-3.5 in design rtl generation with our open-source dataset and lightweight solution","author":"Liu","year":"2024"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD57390.2023.10323953"},{"key":"ref29","article-title":"Chipgpt: How far are we from natural language hardware design","author":"Chang","year":"2023","journal-title":"arXiv preprint"},{"key":"ref30","volume-title":"Understanding the effectiveness of large language models in detecting security vulnerabilities","author":"Khare","year":"2024"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW60843.2023.00058"},{"key":"ref32","volume-title":"Exploring the limits of chatgpt in software security applications","author":"Wu","year":"2023"},{"key":"ref33","volume-title":"Scaling laws for data poisoning in llms","author":"Bowen","year":"2024"},{"key":"ref34","volume-title":"Meta-llama-3.1\u201370b-bnb-4bit","author":"AI"},{"key":"ref35","volume-title":"Yosys open SYnthesis suite","author":"Wolf"},{"key":"ref36","article-title":"Meta-llama-3\u201370b","volume-title":"Meta"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-61486-6_11"},{"key":"ref38","article-title":"Sentaur: Security enhanced trojan assessment using llms against undesirable revisions","author":"Bhandari","year":"2024","journal-title":"arXiv preprint"},{"key":"ref39","author":"Faruque","year":"2024","journal-title":"Unleashing ghost: An llm-powered framework for automated hardware trojan design"}],"event":{"name":"2025 Design, Automation &amp; Test in Europe Conference (DATE)","location":"Lyon, France","start":{"date-parts":[[2025,3,31]]},"end":{"date-parts":[[2025,4,2]]}},"container-title":["2025 Design, Automation &amp;amp; Test in Europe Conference (DATE)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10992638\/10992588\/10993260.pdf?arnumber=10993260","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,22]],"date-time":"2025-05-22T05:33:31Z","timestamp":1747892011000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10993260\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,31]]},"references-count":39,"URL":"https:\/\/doi.org\/10.23919\/date64628.2025.10993260","relation":{},"subject":[],"published":{"date-parts":[[2025,3,31]]}}}