REVIEW 3 major objections 5 minor 25 references
SABLE: An NDA-Safe Closed-Loop LLM Framework for Analog Circuit Optimization in Industrial EDA Flows
T0 review · 3 major / 5 minor · reviewed 2026-07-12 · grok-4.5
Pith's one-line read Cloud LLMs can size real analog circuits without ever seeing foundry PDK content, proprietary schematics, or simulator paths.
desk verdict Real NDA-safe Virtuoso/Maestro loop with honest multi-model PVT evidence; the architecture is the durable piece, the 4/11 op-amp pass is a thin existence claim. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
SABLE: a SafeBridge that confines the model to 28 whitelisted SKILL entry points, scrubs every return path of PDK tokens and absolute paths, enforces a strict JSON design-variable contract with six machine-checked stop conditions, and returns only anonymized topology intent, worst-corner metrics, and a 20-key operating-point table.
What would settle it
A red-team extraction or multi-seed ablation in which a protected PDK token, absolute path, or model-card quantity reaches the model, or in which removing the scrubbed channels still leaves every model unable to close either PVT task from the same reset, would falsify the central claim.
Extended reading notes
Core claim
An NDA-safe closed-loop boundary—whitelist of 28 scoped SKILL entry points, return-path scrubbing, strict JSON action contract, Maestro write-back with landing verification, and best-so-far state preservation—still supplies enough sanitized evidence for cloud LLMs to optimize real analog circuits under three-corner PVT sign-off, with 7 of 11 models passing an LC-VCO task and 4 of 11 passing a harder phase-margin-gated op-amp task from an identical reset.
Load-bearing premise
The cloud provider is only a curious passive observer of prompts and tool results; it does not actively compromise the local host, and provider-side retention or aggregate inference of device-model parameters from the scrubbed operating-point scalars is treated as out of scope.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. SABLE is an NDA-safe closed-loop framework that lets cloud LLMs size analog circuits through Cadence Virtuoso/Maestro/Spectre while returning only scrubbed topology intent, numeric metrics, operating-point summaries, and writeback status. The paper contributes an explicit curious-but-passive threat model with a four-tier attack ladder and five hard invariants; a whitelist of 28 SKILL entry points; return-path PDK/path scrubbing; a strict JSON action contract with six machine-checked stop conditions; Maestro setup/writeback with landing verification; and a fair-start benchmark protocol. Eleven LLM checkpoints are evaluated from a documented all-ones reset on two proprietary 16 nm FinFET tasks under the same three-corner PVT worst-corner gate: a 20 GHz LC-VCO tuning-curve task (7/11 pass) and a two-stage op-amp task with a phase-margin stability gate (4/11 pass). Single-checkpoint feedback-path ablations and a terminal-cause taxonomy support the claim that sanitized channels are load-bearing and that model quality differs sharply once tool discipline and bias/stability reasoning are required.
Significance. If the result holds, this is a practically important systems contribution for industrial analog EDA: it shows how to put a licensed Virtuoso/Maestro/Spectre flow behind an enforced model-provider trust boundary rather than assuming open PDKs or on-premise models. Strengths that should be credited include the explicit threat model and attack ladder (Table 2), structural allowlists versus best-effort scrubbing, authoritative recomputation of measurements so models cannot talk their way into a pass, logged terminal causes that make the failure taxonomy quantitative, the public reproducibility package with leak-check scripts and 0% ASR under fixed/live/adaptive probes (Table 11), and the fair-start protocol that makes multi-model comparison meaningful. The work is complementary to prior analog LLM sizing systems (Table 1) precisely because none of them enforce a cloud-provider boundary on a real Cadence ADE flow.
major comments (3)
- [Section 6, Tables 7–8; Section 10] Tables 7–8 and Section 6 rest the multi-model and “enough sanitized feedback” claims on a single audited seed-1 run per model with a 15-iteration budget. Section 10 and the Section 7 ablation note already concede that budget and endpoint state can flip individual outcomes; with only 4/11 op-amp passes, loss of one or two of those rows would leave the harder-task half of the central existence claim without demonstrated success under the same fair-start protocol. Multi-seed replication (or at least a second seed on the four op-amp passers and the near-miss unstable points) is load-bearing for the published pass-rate claims, not merely a nice-to-have extension.
- [Section 7, Table 9] Section 7’s feedback-path ablations are design-motivating case observations on a single mid-tier checkpoint (mimo-v2.5-pro), single seed, 5-iteration budget, and the single-corner base LC-VCO variant (including a different Kvco ceiling). The main empirical claim is three-corner PVT with worst-corner gating. Because the paper uses these ablations to argue that individual sanitized channels are load-bearing for successful optimization, the ablation setting should match the main PVT protocol (or the mismatch should be closed with at least one PVT ablation of the swept-metric and curve-searcher channels).
- [Section 5.1 (Two-stage op-amp PVT)] Section 5.1 states that the two most extreme corners of a five-corner set were excluded after exploratory runs showed no sizing point held gain at slow/cold/0.72 V, so those corners would make the op-amp task unsatisfiable by construction. That pruning is reasonable for discriminability, but the paper repeatedly frames both tasks as “PVT sign-off” under a shared envelope. The manuscript should more clearly bound what “PVT” means here (a feasible three-corner subset, not a full foundry sign-off suite) and report, even briefly, the exploratory evidence that justified dropping the two corners, so readers can judge whether the 4/11 pass rate reflects a realistic industrial gate or a post-selected feasible envelope.
minor comments (5)
- [Table 1] Table 1’s “Real Cad.” column for AMSnet-KG is annotated as batch Spectre without Virtuoso/Maestro ADE; consider making that distinction in the table body rather than only in the footnote so the positioning claim is self-contained.
- [Figure 5] Figure 5 shows only passing LC-VCO Kvco curves; a short note in the caption that failing runs never reached the sweep phase (already in the table footnote) would make the figure self-explanatory.
- [Table 6; Section 4.2] The op-amp design-variable table (Table 6) declares no per-variable ranges, unlike Table 4 for the LC-VCO. A sentence on how physical-plausibility bounds are enforced at the bridge would help readers interpret search coverage.
- [Section 5.2; Section 10] Several model names (e.g., claude-opus-4-8, gpt-5.5, minimax-m3) are dated endpoint snapshots; stating the access window or API date in Section 5.2 or the artifact README would strengthen the “dated snapshot” disclaimer in Section 10.
- [Abstract; Section 1] Minor consistency: abstract says “propose circuit-optimization decisions” while the introduction opens with “circuit-sizing decisions”; aligning terminology would avoid implying topology synthesis.
Circularity Check
No circular derivation: empirical closed-loop evaluation against an independent Spectre oracle and fixed metric bands, not a first-principles prediction forced by its inputs.
full rationale
SABLE is a systems/engineering paper whose central claims are (i) an enforceable NDA-safe tool boundary under a stated threat model and (ii) empirical existence of successful closed-loop PVT optimization under that boundary (7/11 LC-VCO, 4/11 op-amp). Pass/fail is recomputed authoritatively on the trusted side from Spectre/Maestro results against fixed, machine-readable bands (Tables 3 and 5); the model’s own measurements field cannot talk a run into a pass. No free parameter is fitted to a data subset and then re-presented as a prediction of a closely related quantity. The optional deterministic curve-searcher is ablated (Table 9) and shown not to force success. The three-corner PVT envelope is a deliberate, disclosed feasibility choice after exploratory five-corner runs, not a self-definitional reduction of a derived claim to its inputs. There are no load-bearing self-citations, uniqueness theorems imported from the authors, or ansatzes smuggled via prior work by the same authors. Residual definitional scoping (“NDA-safe” means enforcement under the stated curious-but-passive model, not non-interference) is explicit and does not make the optimization results circular. Statistical fragility of single-seed pass rates is a correctness/support concern, not circularity.
Assumptions & free parameters
free parameters (5)
- iteration_budget =
15
- PVT_corner_set =
tt/25C/0.80V, ss/125C/0.72V, ff/-40C/0.88V
- hard_pass_bands =
task-specific bands in Tables 3 and 5
- OP_whitelist_size =
20 keys
- SKILL_entry_point_count =
28
assumptions (4)
- domain assumption Cloud LLM provider is curious-but-passive: observes prompts and tool results, may log or train, may return adversarial arguments, but does not compromise the local OS or Cadence process and does not mount active MITM on the EDA host.
- domain assumption Structural allowlists (design-variable names, 28 SKILL entry points, 20 OP keys) bound what the boundary can emit by construction; content outside the lists is unreachable.
- ad hoc to paper Pattern-based return-path scrubber plus known-root path allowlist is sufficient defense-in-depth for residual free-text fields under the stated threat model.
- domain assumption Worst-corner-must-pass gating across the three retained corners is a valid and discriminating industrial sign-off for the two tasks.
invented entities (4)
-
SABLE / SafeBridge NDA-safe closed-loop architecture
-
Strict JSON action contract with six machine-checked stop conditions
-
Anonymized topology-intent readback and 20-key operating-point whitelist
-
Deterministic curve-searcher feedback module
Cite this review
Pith. "Pith review of SABLE: An NDA-Safe Closed-Loop LLM Framework for Analog Circuit Optimization in Industrial EDA Flows." pith.science (2026). https://pith.science/paper/R5HOO5FD
@misc{pith2026260703701,
author = {Pith},
title = {Pith review of: SABLE: An NDA-Safe Closed-Loop LLM Framework for Analog Circuit Optimization in Industrial EDA Flows},
year = {2026},
howpublished = {\url{https://pith.science/paper/R5HOO5FD}},
note = {Machine review of arXiv:2607.03701}
}
read the original abstract
Large language models (LLMs) can propose circuit-optimization decisions, but industrial analog flows cannot expose foundry PDK content, proprietary schematics, absolute simulation paths, or license-bound tool state to a cloud endpoint. We present SABLE (Safe Analog Boundary for LLM-driven EDA), an NDA-safe closed-loop framework that lets LLMs optimize analog circuits through Cadence Virtuoso, Maestro, and Spectre while returning only scrubbed topology intent, numeric metrics, operating-point summaries, and scoped writeback status. "NDA-safe" denotes enforcement under a stated curious-but-passive cloud-provider threat model, not a formal non-interference proof. The framework combines an explicit threat model, a whitelist of 28 scoped SKILL entry points, PDK/path/model scrubbing on every return path, structured Maestro setup and writeback, a strict JSON action contract with six machine-checked stop conditions, and best-so-far state preservation. We evaluate eleven LLM checkpoints from the same documented reset state on two real closed-loop tasks, both run as process-voltage-temperature (PVT) sign-offs across three corners: a 20 GHz LC-VCO tuning-curve task and a two-stage op-amp task. On the LC-VCO task 7 of 11 models pass; on the harder op-amp task, where every metric must hold at the worst corner and a phase-margin gate rejects unstable high-gain points, 4 of 11 pass within a 15-iteration budget. Feedback-path ablations show that removing individual sanitized channels either silently weakens the specification or degrades the search. Model quality differs sharply once the loop requires tool discipline, bias reasoning, and specification repair, yet an NDA-safe boundary still provides enough sanitized feedback for successful analog circuit optimization.
Figures
Figures from the paper (2 more)
Reference graph
Works this paper leans on
-
[1]
Mohsen Ahmadzadeh, Kaichang Chen, and Georges Gielen. 2025. AnaFlow: Agentic LLM-based Workflow for Reasoning-Driven Explainable and Sample-Efficient Analog Circuit Sizing. InProc. ACM/IEEE Int. Conf. on Computer- Aided Design (ICCAD). IEEE, Munich, Germany, 1–7. arXiv:2511.03697 doi:10.1109/ICCAD66269.2025.11240818 Invited paper
-
[2]
Zhixuan Bao, Zhuoyi Lin, Jiageng Wang, Jinhai Hu, Yuan Gao, Yaoxin Wu, Xiaoli Li, and Xun Xu. 2026. AnalogA- gent: Self-Improving Analog Circuit Design Automation with LLM Agents.arXiv preprint arXiv:2603.23910(2026). arXiv:2603.23910 https://arxiv.org/abs/2603.23910
arXiv 2026
-
[3]
Jitendra Bhandari, Vineet Bhat, Yuheng He, Hamed Rahmani, Siddharth Garg, and Ramesh Karri. 2024. Masala-CHAI: A Large-Scale SPICE Netlist Dataset for Analog Circuits by Harnessing AI.arXiv preprint arXiv:2411.14299(2024). arXiv:2411.14299 https://arxiv.org/abs/2411.14299
arXiv 2024
-
[4]
Jason Blocklove, Shailja Thakur, Benjamin Tan, Hammond Pearce, Siddharth Garg, and Ramesh Karri. 2025. Automati- cally Improving LLM-based Verilog Generation using EDA Tool Feedback.ACM Transactions on Design Automation of Electronic Systems30, 6 (2025), 1–26. doi:10.1145/3723876
doi:10.1145/3723876 2025
-
[5]
Luca Collini, Siddharth Garg, and Ramesh Karri. 2025. C2HLSC: Leveraging Large Language Models to Bridge the Software-to-Hardware Design Gap.ACM Transactions on Design Automation of Electronic Systems30, 6 (2025), 1–24. doi:10.1145/3734524
doi:10.1145/3734524 2025
-
[6]
Dimple Vijay Kochar, Hanrui Wang, Anantha P. Chandrakasan, and Xin Zhang. 2025. LEDRO: LLM-Enhanced Design Space Reduction and Optimization for Analog Circuits. InProc. IEEE Int. Conf. on LLM-Aided Design (ICLAD). IEEE, Stanford, CA, USA, 141–148. arXiv:2411.12930 doi:10.1109/ICLAD65226.2025.00011
-
[7]
Yao Lai, Sungyoung Lee, Guojin Chen, Souradip Poddar, Mengkang Hu, David Z. Pan, and Ping Luo. 2025. AnalogCoder: Analog Circuit Design via Training-Free Code Generation. InProc. AAAI Conference on Artificial Intelligence. Association for the Advancement of Artificial Intelligence, Washington, DC, USA, 379–387. arXiv:2405.14918 doi:10.1609/aaai. v39i1.32016
arXiv doi:10.1609/aaai 2025
-
[8]
Yao Lai, Souradip Poddar, Sungyoung Lee, Guojin Chen, Mengkang Hu, Bei Yu, Ping Luo, and David Z. Pan. 2026. AnalogCoder-Pro: Unifying Analog Circuit Generation and Optimization via Multi-modal LLMs.IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems(2026), 1–1. arXiv:2508.02518 [cs.AR] doi:10.1109/TCAD. 2026.3673493 Early Access
arXiv doi:10.1109/tcad 2026
Show all 25 references
- [9]
-
[10]
Chang Liu and Danial Chitnis. 2026. EEsizer: LLM-Based AI Agent for Sizing of Analog and Mixed Signal Circuit. IEEE Transactions on Circuits and Systems I: Regular Papers73, 6 (2026), 3825–3834. arXiv:2509.25510 doi:10.1109/TCSI. 2025.3646359
2026 doi
-
[11]
Mingjie Liu, Teodor-Dumitru Ene, Robert Kirby, Chris Cheng, Nathaniel Pinckney, Rongjian Liang, Jonah Alben, Himyanshu Anand, Sanmitra Banerjee, Ismet Bayraktaroglu, et al. 2023. ChipNeMo: Domain-Adapted LLMs for Chip Design.arXiv preprint arXiv:2311.00176(2023). arXiv:2311.00...
2023 arXiv
-
[12]
Asal Mehradfar, Xuzhe Zhao, Yue Niu, Sara Babakniya, Mahdi Alesheikh, Hamidreza Aghasi, and Salman Avestimehr
-
[13]
arXiv:2407.18272 https://arxiv.org/abs/2407.18272
AICircuit: A Multi-Level Dataset and Benchmark for AI-Driven Analog Integrated Circuit Design.arXiv preprint arXiv:2407.18272(2024). arXiv:2407.18272 https://arxiv.org/abs/2407.18272
2024 arXiv
-
[14]
Ruidi Qiu, Grace Li Zhang, Rolf Drechsler, Tsungyi Ho, Ulf Schlichtmann, and Bing Li. 2025. ConfiBench: Automatic Testbench Generation with Confidence-Based Scenario Mask and Testbench Ensemble using LLMs for HDL Design. ACM Transactions on Design Automation of Electronic Syst...
2025 doi
-
[15]
E Bhawani Eswar Reddy, Sutirtha Bhattacharyya, Ankur Sarmah, Fedrick Nongpoh, Karthik Maddala, and Chandan Karfa. 2025. LHS: LLM Assisted Efficient High-level Synthesis of Deep Learning Tasks.ACM Transactions on Design Automation of Electronic Systems30, 6 (2025), 1–27. doi:10...
2025 doi
-
[16]
Yichen Shi, Zhuofu Tao, YuHao Gao, Tianjia Zhou, Cheng Chang, Yaxin Wang, Bingyu Chen, Genhao Zhang, Alvin Liu, Zhiping Yu, Ting-Jung Lin, and Lei He. 2025. AMSnet-KG: A Netlist Dataset for LLM-based AMS Circuit Auto-design Using Knowledge Graph RAG.ACM Transactions on Design ...
2025 doi
- [17]
- [18]
-
[19]
Zining Wang, Jian Gao, Weimin Fu, Xiaolong Guo, and Xuan Zhang. 2025. AnalogSAGE: Self-evolving Analog Design Multi-Agents with Stratified Memory and Grounded Experience.arXiv preprint arXiv:2512.22435(2025). arXiv:2512.22435 https://arxiv.org/abs/2512.22435
2025
- [20]
-
[21]
Kangwei Xu, Grace Li Zhang, Xunzhao Yin, Cheng Zhuo, Ulf Schlichtmann, and Bing Li. 2026. HLSRewriter: Efficient Refactoring and Optimization of C/C++ Code with LLMs for High-Level Synthesis.ACM Transactions on Design Automation of Electronic Systems31, 4 (2026), 1–21. doi:10....
2026 doi
-
[22]
Tingjie Yang, Bo Li, Yongfu Li, Wei Mao, and Genquan Han. 2025. Circuit-Agent: A Large Language Model Based Circuit Agent Framework for Analog/Mixed-signal Circuit Design Automation. InProc. IEEE Int. Conf. on Artificial Intelligence Circuits and Systems (AICAS). IEEE, Bordeau...
2025 doi
- [23]
-
[24]
Xi Yu, Dmitrii Torbunov, Soumyajit Mandal, and Yihui Ren. 2026. AutoSizer: Automatic Sizing of Analog and Mixed- Signal Circuits via Large Language Model (LLM) Agents.arXiv preprint arXiv:2602.02849(2026). arXiv:2602.02849 https://arxiv.org/abs/2602.02849
2026 arXiv
- [25]
Reviewed July 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.