{"id":"bd813e08-ffec-43be-a06b-166cc089a7df","arxiv_id":"2606.10163","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":6.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"GRAFT introduces graphlet-based triggers for backdoor attacks on GNN hardware security systems, achieving up to 100% attack success rate on ISCAS-85 and TrustHub benchmarks while preserving circuit functionality.","lead":"This paper proposes GRAFT, a backdoor attack that inserts graphlet triggers into circuit designs to fool GNN-based detectors of hardware Trojans and IP theft while keeping the original circuit function intact. A smart generalist might read it to see how AI security tools for chips can be compromised in practice.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.3","headline":"Functionality preservation claim rests on unstated equivalence between original and trigger-inserted netlists at RTL/gate level","rationale":"Reader correctly flagged the functionality-preservation assumption as weakest; the full-text gap simply makes that assumption untestable from the given material. No other internal inconsistency is visible from the abstract alone.","tokens_in":1747,"tokens_out":295,"duration_ms":11077,"concrete_test":"Extract the exact graphlet insertion procedure and any equivalence-checking command or testbench from §4 or the appendix; re-run the original and modified netlists through a commercial equivalence checker (e.g., Synopsys Formality) on the largest ISCAS-85 circuit; if any output mismatch appears under the same input vectors used for ASR measurement, the functionality-preservation claim fails.","verdict_should_be":"UNVERDICTED","load_bearing_attack":"The central claim requires that graphlet insertion at RTL or gate level leaves the circuit's Boolean function unchanged (so that standard verification passes and the backdoor is invisible to HT detectors). The abstract asserts this is achieved, but supplies no description of the insertion operator, the chosen graphlets, or the verification method (simulation, formal equivalence, or ATPG). Without that, it is impossible to assess whether the preservation holds for the ISCAS-85 and TrustHub benchmarks or whether the reported 100 % ASR is measured on functionally identical designs.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper proposes GRAFT, a graphlet-triggered backdoor attack on GNN-based hardware security systems for HT and IP piracy detection. It embeds graphlet-based triggers at the RTL or gate level of circuit designs while preserving original functionality, evaluated on ISCAS-85 and TrustHub benchmarks, with reported attack success rates up to 100% and effective evasion of standard detectors.","tokens_in":1853,"tokens_out":355,"duration_ms":20083,"significance":"If the functionality-preservation claim and ASR results hold under rigorous verification, the work would be significant for hardware security by exposing a concrete attack vector against GNN-based detectors that maintains circuit equivalence, thereby motivating stronger robustness requirements for ML tools in the IC supply chain.","major_comments":[{"comment":"Abstract: the claim that graphlet triggers are embedded 'while preserving the circuit's original function' is load-bearing for both the evasion and ASR results, yet the abstract (and by extension the methods) supplies no description of the insertion operator, chosen graphlets, or verification procedure (simulation, formal equivalence checking, or ATPG).","section":"Abstract"},{"comment":"Abstract/Evaluation: high ASR figures (up to 100 %) are stated without any experimental details, baselines, error bars, or explicit confirmation that the reported success rates were measured on functionally identical netlists, which directly undermines assessment of the central claim.","section":"Abstract"}],"minor_comments":[{"comment":"Abstract: the term 'graphlet' is used without a brief definition or reference to the specific graphlet sizes or topologies employed, which would aid readability.","section":"Abstract"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the constructive comments. We address each major comment below and will revise the manuscript accordingly.","responses":[{"response":"The abstract is concise by design. The full manuscript provides the description of the graphlet insertion operator, the specific graphlets selected, and the verification procedure (via simulation confirming functional equivalence) in the methods section. We will revise the abstract to include a brief statement on the functionality-preserving insertion and verification approach.","revision_made":"yes","referee_comment":"[Abstract] Abstract: the claim that graphlet triggers are embedded 'while preserving the circuit's original function' is load-bearing for both the evasion and ASR results, yet the abstract (and by extension the methods) supplies no description of the insertion operator, chosen graphlets, or verification procedure (simulation, formal equivalence checking, or ATPG)."},{"response":"Abstracts summarize key results; the experimental section supplies the requested details on baselines, error bars from repeated trials, and explicit confirmation that ASR is measured only on netlists verified as functionally identical. We will revise the abstract to note that the reported ASR values are obtained on functionally equivalent circuits, with full experimental information in the evaluation section.","revision_made":"yes","referee_comment":"[Abstract] Abstract/Evaluation: high ASR figures (up to 100 %) are stated without any experimental details, baselines, error bars, or explicit confirmation that the reported success rates were measured on functionally identical netlists, which directly undermines assessment of the central claim."}],"tokens_in":1328,"tokens_out":341,"duration_ms":24764,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The one thing to take away is that this paper describes an attack called GRAFT that inserts small, structured graphlet subgraphs into circuit netlists at RTL or gate level so that a downstream GNN detector misclassifies the design, while asserting that the original Boolean function stays unchanged. The authors contrast this with earlier random or gradient-generated subgraph triggers that would break circuit behavior and therefore get caught by normal verification.\n\nWhat the work actually does is apply the graphlet idea to two standard benchmark suites (ISCAS-85 and TrustHub) and report attack success rates reaching 100 % against both hardware-Trojan and IP-piracy GNN detectors. That scoped application and the explicit functionality-preservation requirement are the concrete increments over prior backdoor papers.\n\nThe soft spot is exactly where the stress-test note points: the preservation claim is load-bearing but unsupported in the text. No insertion operator, no list of chosen graphlets, and no equivalence check (simulation, formal, or ATPG) is described, so it is impossible to tell whether the reported ASR numbers come from functionally identical netlists or from designs that already differ in observable ways. Without those steps the 100 % figure cannot be evaluated.\n\nThe paper is aimed at the narrow intersection of hardware-security researchers and people building GNN tools for EDA. Someone already working on robustness of graph models for netlist analysis might pick up the attack idea and test it themselves; a broader reader will not get much.\n\nIt is worth sending to referees because the topic is timely and the benchmark choice is reasonable, but any review should ask for the missing insertion and verification details before the central claim can be assessed.","headline":"GRAFT claims graphlet triggers let you backdoor GNN hardware-security tools while keeping circuit function identical, but the insertion and equivalence steps are not shown in enough detail to check the claim.","tokens_in":2331,"tokens_out":423,"would_cite":false,"duration_ms":15915,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"Graphlet-based triggers embedded in circuits backdoor GNN hardware security systems without changing functionality.","keywords":["backdoor attacks","graph neural networks","hardware trojans","graphlets","circuit design","RTL","IP piracy","hardware security"],"falsifier":"Applying GRAFT to a specific circuit from the ISCAS-85 set, then checking with an HT detection tool to see if the trigger is identified or if the circuit output changes from the original.","tokens_in":2652,"feed_emoji":"🔒","tokens_out":656,"duration_ms":21418,"temperature":0.7,"pith_summary":"This paper presents GRAFT, a backdoor attack method that uses graphlets to compromise GNNs designed to detect hardware Trojans and IP theft in integrated circuits. The attack inserts these small subgraph triggers into the circuit at the RTL or gate level in a manner that keeps the circuit's original behavior unchanged. By doing so, it can cause the GNN to output an adversarial prediction while avoiding detection by standard security checks. The results on common benchmark datasets show the attack reaching up to 100% success rate in fooling the models. This demonstrates that current GNN-based protections for hardware can be bypassed using structurally embedded triggers.","feed_headline":"Graphlet triggers backdoor GNN hardware detectors at 100% success","feed_subtitle":"Small subgraphs inserted at RTL or gate level preserve circuit function while evading Trojan and IP detection.","key_machinery":"Graphlet-based trigger embedding, which places small, specific subgraphs into the circuit graph at RTL or gate level to serve as backdoor triggers for the GNN without affecting circuit functionality.","core_discovery":"GRAFT embeds graphlet-based triggers at either the register-transfer level (RTL) or gate level of the design while preserving the circuit's original function and can effectively evade HT detection and IP piracy detection, achieving an attack success rate (ASR) of up to 100%.","pith_inferences":["Future hardware security might require checking for specific graphlet patterns during design verification.","This approach highlights vulnerabilities in graph-based machine learning models used for security tasks beyond hardware.","Designers could explore adding randomness or other protections to circuit graphs to prevent such trigger insertions.","Similar graphlet trigger methods might be adapted for other domains using GNNs for anomaly detection."],"forward_implications":["GNN-based detectors for hardware Trojans can be misled to miss the presence of threats.","IP piracy detection systems using GNNs can be compromised by these embedded triggers.","The attack maintains circuit functionality, allowing it to pass normal verification processes.","Evaluation shows the method works on standard circuit benchmarks like ISCAS-85 and TrustHub.","Attack success rates can reach 100% while evading existing detection methods."],"fun_headline_variants":["Graphlet backdoors GNN hardware detectors achieving 100% ASR","GRAFT embeds graphlets to backdoor GNNs preserving function","Backdoor attack succeeds at 100% using graphlets on GNN IC tools","Graphlets trigger backdoors in GNN security at RTL or gate level","GRAFT graphlet triggers evade HT IP detection at 100% ASR on GNNs"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"That it is possible to insert graphlet triggers into a circuit design at RTL or gate level without changing the circuit's original function or making the change detectable by standard tools.","fun_headline_variants_meta":{"raw":{"variants":["Graphlet backdoors GNN hardware detectors achieving 100% ASR","GRAFT embeds graphlets to backdoor GNNs preserving function","Backdoor attack succeeds at 100% using graphlets on GNN IC tools","Graphlets trigger backdoors in GNN security at RTL or gate level","GRAFT graphlet triggers evade HT IP detection at 100% ASR on GNNs"]},"model":"grok-4.3","cost_usd":0.005749,"raw_usage":{"total_tokens":2736,"prompt_tokens":658,"num_sources_used":0,"completion_tokens":90,"cost_in_usd_ticks":57487000,"prompt_tokens_details":{"text_tokens":658,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":1988,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":658,"tokens_out":90,"duration_ms":12749,"temperature":1.0,"reasoning_tokens":1988,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-06-27T16:01:58.464880+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"Applying GRAFT to a specific circuit from the ISCAS-85 set, then checking with an HT detection tool to see if the trigger is identified or if the circuit output changes from the original.","supporting_citations":[],"review_version":1}