LLMPirate: LLMs for Black-box Hardware IP Piracy

Vasudev Gohil (Seammens)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Hard- & Firmware Security · Hard- & Firmware Security

Overview

In the rapidly evolving landscape of Large Language Models (LLMs), their applications span numerous domains, from finance and education to software development and even semiconductor chip design. While LLMs offer immense promise, their capabilities also introduce new vectors for sophisticated attacks. This talk by Vasudev Gohil, presented at the NDSS Symposium, delves into one such novel attack: LLMPirate, a technique that leverages LLMs to facilitate black-box hardware intellectual property (IP) piracy. The research explores how generative AI can be weaponized to structurally alter hardware circuits at the gate level, rendering them undetectable by existing piracy detection tools while preserving their original functionality.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introducing LLMPirate: LLMs for Hardware IP Piracy
  2. 1:45 Defining the black-box piracy detection threat model
  3. 2:45 Initial LLM failure with raw gate-level Verilog netlists
  4. 3:45 Solution 1: Translating netlists to boolean operator format
  5. 4:15 Solution 2: Handling large netlists using divide and conquer
  6. 5:00 Solution 3: Iterative feedback loop for LLM error correction
  7. 6:00 Step-by-step overview of the LLMPirate methodology

LLMPirate: LLMs for Black-box Hardware IP Piracy

Speakers: Vasudev Gohil, Seammens (formerly Texas A&M University)

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=qdqc6Lr0CLk

Overview

In the rapidly evolving landscape of Large Language Models (LLMs), their applications span numerous domains, from finance and education to software development and even semiconductor chip design. While LLMs offer immense promise, their capabilities also introduce new vectors for sophisticated attacks. This talk by Vasudev Gohil, presented at the NDSS Symposium, delves into one such novel attack: LLMPirate, a technique that leverages LLMs to facilitate black-box hardware intellectual property (IP) piracy. The research explores how generative AI can be weaponized to structurally alter hardware circuits at the gate level, rendering them undetectable by existing piracy detection tools while preserving their original functionality.

Gohil’s work highlights a critical vulnerability in the current hardware IP protection paradigm. By demonstrating the ability of LLMs to refactor complex Verilog netlists into functionally identical but structurally distinct forms, LLMPirate poses a significant threat to semiconductor manufacturers and designers. The talk not only exposes this potential for AI-driven IP theft but also meticulously details the methodology, challenges, and solutions involved in weaponizing LLMs for this purpose, providing crucial insights for future defensive strategies.

Background

▶ Watch: Introducing LLMPirate: LLMs for Hardware IP Piracy (0:00)

The proliferation of Large Language Models (LLMs) has ushered in an era of unprecedented computational capability, transforming how we approach problem-solving across diverse fields. From generating human-like text to assisting in complex scientific research, LLMs have proven to be powerful tools. However, this power is not without its dual-use implications. Researchers have demonstrated LLMs' capacity to generate malicious code, assist in malware development, and even be poisoned to produce harmful outputs, underscoring the urgent need to understand their potential in adversarial contexts.

In the realm of hardware design, intellectual property (IP), particularly the complex designs of integrated circuits, represents a colossal investment of time, expertise, and capital. Protecting this IP from unauthorized replication or modification, commonly known as piracy, is paramount for the semiconductor industry. Existing IP protection mechanisms often rely on piracy detection tools that compare circuits to identify similarities, either through traditional hashing-based methods or advanced machine learning techniques like Graph Neural Networks (GNNs). These tools aim to identify if one circuit is a pirated version of another by looking for structural or functional commonalities.

The challenge LLMPirate addresses stems from the inherent difficulty LLMs face in directly manipulating highly specialized hardware description languages (HDLs) like Verilog, especially at the gate-level netlist abstraction. Traditional LLMs are primarily trained on vast corpora of natural language and software code (e.g., C++), making them ill-equipped to understand the nuances of hardware architectures or the intricate interconnections of gates. Furthermore, the sheer size of industrial-scale netlists, often containing hundreds of thousands of gates, far exceeds the context window limitations of most LLMs, making a direct "lift and shift" approach unfeasible. This research seeks to bridge this gap, exploring how these limitations can be overcome to enable LLMs to perform sophisticated structural transformations that evade detection while maintaining functional integrity. The core problem LLMPirate aims to exploit is the black-box nature of many piracy detectors, meaning an attacker can query the detector without knowing its internal workings, seeking to generate an output that the detector fails to classify as pirated.

Key Findings

▶ Watch: Initial LLM failure with raw gate-level Verilog netlists (2:45)

The LLMPirate project successfully demonstrated the feasibility of using Large Language Models to generate functionally equivalent but structurally distinct hardware IP, thereby evading state-of-the-art piracy detection tools. The key findings illuminate both the efficacy of the proposed attack methodology and the critical factors influencing its success.

Firstly, LLMPirate achieved significant evasion rates against a diverse set of piracy detection tools, including both machine learning-based techniques like GNN for IP and traditional hashing/similarity-based tools such as MOSS and SIM. For GNN for IP, which uses a similarity score ranging from -1 to 1 with a classification threshold of zero, LLMPirate consistently produced pirated circuits with similarity scores lower than this threshold, effectively fooling the detector into classifying them as non-pirated. Similar success was observed across almost all tested detection tools and benchmark circuits, including academic benchmarks and open-source processors.

Secondly, an ablation study revealed the indispensable nature of two core optimizations: prompt syntax translation (Solution A) and divide and conquer (Solution B). Without these two components, the language models were largely incapable of understanding Verilog syntax or generating functionally equivalent circuits, rendering the evasion attempts completely ineffective. This highlights the necessity of preprocessing and structural decomposition for LLMs to meaningfully interact with hardware netlists. While solutions A and B alone enabled reasonable evasion rates, particularly against most detection tools except for SIM, the third optimization, a feedback loop (Solution C), provided a crucial performance boost. This iterative feedback mechanism helped "extract that last bit of juice" from the technique, improving evasion performance across the board.

Finally, the research provided insights into the characteristics of LLMs best suited for this task:

  • Model Size Matters: Larger, closed-source LLMs consistently outperformed smaller, open-source models. For instance, Code Llama 13 billion demonstrated significantly better performance than its 7 billion parameter counterpart.
  • Training Data Size is Crucial: Newer generation LLMs, such as Llama 3, which are trained on substantially larger datasets, performed better than older generations of similar size, like Llama 2, indicating the importance of extensive and diverse training data.
  • Feedback Improves Performance: The feedback loop proved especially beneficial for smaller language models. Initially, these models performed poorly, but with iterative feedback, they were able to correct their mistakes, leading to functionally equivalent circuits and successful piracy against detection tools.

These findings collectively establish LLMPirate as a potent adversarial technique, demonstrating that with appropriate interfacing and iterative refinement, LLMs can be weaponized to bypass sophisticated hardware IP protection mechanisms.

Technical Deep Dive

▶ Watch: Solution 1: Translating netlists to boolean operator format (3:45)

The core challenge in using Large Language Models for hardware IP piracy lies in their fundamental limitations when dealing with specialized hardware description languages (HDLs) and the immense scale of industrial-grade circuits. The LLMPirate framework systematically addresses these challenges through a multi-pronged approach, enabling LLMs to generate functionally equivalent but structurally distinct gate-level netlists.

The initial attempts to simply prompt an off-the-shelf LLM like ChatGPT with a Verilog netlist and request a refactored version proved unsuccessful. LLMs, primarily trained on natural language and software code (e.g., C++), exhibited a profound lack of understanding of Verilog syntax and often failed to produce even syntactically correct netlists, let alone functionally equivalent ones. This led to the development of three key solutions:

  1. Prompt Syntax Translation (Solution A):

To overcome the language barrier, LLMPirate introduces a parser that translates the complex Verilog gate-level netlist into a more abstract and LLM-comprehensible boolean operator format. For instance, an AND gate connecting two signals to an output is represented as a boolean AND operator linking two variables. This translation simplifies the input, making it easier for the LLM to understand the underlying logic and manipulate it effectively. The goal is to present the logic in a format that aligns more closely with the LLM's general reasoning capabilities, which are often implicitly trained on logical operations.

  1. Divide and Conquer (Solution B):

Industrial Verilog netlists can contain hundreds of thousands of gates, far exceeding the context window limitations of even the largest LLMs. To tackle this, LLMPirate employs a divide and conquer strategy. Instead of attempting to process the entire netlist at once, the framework first characterizes the netlist to identify all the different types of gates and elements present. Then, it iterates over each of these distinct gate types. For each type, it prompts the LLM to rewrite or restructure that specific, smaller component. This granular division allows the LLM to focus on manageable chunks of logic, generating transformations for individual gate types or small clusters of gates, rather than the entire circuit.

  1. Feedback Loop (Solution C):

LLMs are inherently non-deterministic and can make errors, especially when generating complex code or logic. To ensure the generated output maintains functional equivalence and syntactic correctness, LLMPirate incorporates an iterative feedback mechanism. After the LLM generates a proposed rewritten boolean logic, the system performs several checks:

  • Syntax Checks: Ensures the generated logic adheres to correct syntax.
  • Operator Checks: Verifies that only permissible operators are used.
  • Functional Equivalence Checks: This is the most critical step, formally verifying that the rewritten logic performs identically to the original logic. If any of these checks fail, the system provides simple, direct feedback to the LLM (e.g., "this is wrong, please try again"). This closed-loop process allows the LLM to learn from its mistakes and refine its output until all conditions are met.

The complete LLMPirate flow proceeds as follows:

  1. Input Netlist: Start with a target hardware netlist to be pirated.
  2. Characterization: The netlist is analyzed to extract all unique gate types and elements.
  3. Gate-level Iteration: For each distinct gate or element type:
  • Boolean Translation: The gate's Verilog representation is converted into the boolean operator format (Solution A).
  • LLM Prompting: This boolean prompt is fed to the chosen LLM (e.g., ChatGPT, Code Llama, Llama 3) requesting a functionally equivalent but structurally different representation.
  • Response Analysis and Feedback: The LLM's response undergoes syntax, operator, and functional equivalence checks. If any check fails, corresponding feedback is provided, and the LLM is prompted again (Solution C).
  • Transformation Mapping: Once a valid and functionally equivalent rewritten logic is obtained, a mapping or transformation is established between the original gate type and its new, structurally altered representation.
  1. Netlist Reconstruction: After generating transformations for all unique gate types, a simple script iterates through the original netlist, replacing instances of original gates with their newly generated, structurally different transformations.
  2. Pirated Netlist Output: The result is a pirated netlist that is functionally identical to the original but structurally distinct.
  3. Piracy Detector Query: This pirated netlist is then queried against the black-box piracy detection tool to assess the attack's success.

This detailed, multi-stage approach allows LLMPirate to leverage the generative power of LLMs while mitigating their inherent limitations, ultimately enabling the creation of evasive hardware IP.

Demo / Proof of Concept

▶ Watch: Solution 3: Iterative feedback loop for LLM error correction (5:00)

The efficacy of LLMPirate was rigorously demonstrated through extensive testing against various academic benchmarks and open-source processors. The evaluation aimed to prove that the generated circuits could successfully evade detection by existing piracy detection tools while maintaining their core functionality.

The experimental setup involved testing the LLMPirate-generated circuits against a spectrum of detection tools:

  • GNN for IP: A machine learning-based detection technique utilizing Graph Neural Networks, known for its ability to identify similarities based on circuit structure and connectivity. Its similarity scores range from -1 to 1, with 0 as the classification threshold.
  • MOSS: A traditional, deterministic hashing-based similarity detection tool.
  • SIM: Another deterministic similarity detection tool.
  • JAG: (Mentioned in ablation study figure, likely another similarity tool).

The primary metric for success was the ability to generate circuits that were classified as "not pirated" by these tools, despite being derived from the original IP. For GNN for IP, this meant achieving similarity scores below the zero threshold. The results consistently showed that LLMPirate was able to generate pirated netlists for all tested circuits that achieved similarity scores lower than the thresholds for GNN for IP, effectively fooling the detector. Similar successful evasion rates were observed across MOSS and SIM for almost all benchmark circuits.

Further validation came from an ablation study, which served as a crucial proof of concept for the individual components of LLMPirate. By systematically removing each of the three proposed solutions (prompt syntax translation, divide and conquer, and the feedback loop), the researchers demonstrated their necessity:

  • Without prompt syntax translation (Solution A) or divide and conquer (Solution B), the LLMs failed to produce functionally equivalent circuits or even syntactically correct ones, leading to zero evasion success. This directly demonstrated that these solutions are absolutely essential for the technique to work.
  • While a reasonable evasion rate could be achieved with just solutions A and B, the inclusion of the feedback loop (Solution C) consistently improved evasion performance, especially for certain detection tools like SIM, showcasing its role in fine-tuning the generated outputs.

The formal verification of functional equivalence for all generated pirated circuits further solidified the proof of concept. This ensures that while the structure is altered to evade detection, the pirated IP still performs its intended function, making it a viable replacement for the original. The cumulative evidence from these tests firmly establishes LLMPirate as a practical and effective method for black-box hardware IP piracy using LLMs.

Defensive Implications

▶ Watch: Step-by-step overview of the LLMPirate methodology (6:00)

The advent of LLMPirate presents a significant new challenge for hardware IP protection and demands a re-evaluation of current defensive strategies. The black-box nature of the attack, where the adversary has no internal knowledge of the detection tool but can iteratively query it, makes traditional defenses more difficult to implement effectively.

One of the most direct countermeasures, as suggested by the speaker during the Q&A, is to retrain machine learning-based piracy detectors with these newly identified "adversarial examples." If detection tools like GNN for IP are exposed to a diverse dataset of LLMPirate-generated pirated circuits during their training phase, they could potentially learn to identify the structural patterns indicative of such AI-driven transformations. This would involve generating a large corpus of pirated circuits using LLMPirate (or similar techniques) and incorporating them into the training data of the detection models, essentially turning the attack into a training opportunity.

However, this approach comes with its own set of challenges. The non-deterministic nature of LLMs means that the generated pirated circuits could be highly diverse, making it difficult to create a comprehensive training set that covers all possible adversarial examples. Continuous monitoring and retraining pipelines would likely be necessary to keep pace with evolving LLM capabilities and attack methodologies.

Beyond retraining, designers and defenders should also consider:

  • Performance Overheads as a Signal: The speaker acknowledged that LLMPirate introduces some overhead in critical path delays, estimated to be around 10%. While this might be mitigated by post-piracy synthesis optimization, consistent performance degradation could serve as an indicator of tampering or structural modification. Monitoring performance metrics during design verification could potentially flag such pirated circuits.
  • White-box Detection Mechanisms: Moving towards more robust white-box detection strategies, where internal circuit details are analyzed at a deeper level, might offer better resilience against structural obfuscation. This could involve formal verification techniques that are less susceptible to superficial structural changes.
  • Watermarking and Fingerprinting: More advanced hardware watermarking or fingerprinting techniques, embedded deep within the IP, might offer a layer of protection that is harder for LLMs to remove or obfuscate without disrupting functionality.
  • Enhanced Design Obfuscation: Proactive obfuscation techniques applied during the design phase could make it more challenging for LLMs to identify and transform meaningful logical blocks. However, this could also increase design complexity and potentially impact performance.

Ultimately, LLMPirate underscores the need for a dynamic and adaptive approach to hardware IP protection. As LLMs become more sophisticated, the arms race between attackers and defenders in the hardware security domain will intensify, requiring continuous research into both offensive capabilities and robust defensive countermeasures.

Key Takeaways

  • LLMs can be weaponized for hardware IP piracy: LLMPirate demonstrates that Large Language Models can be effectively used to generate functionally identical but structurally distinct hardware circuits at the gate level, evading existing piracy detection tools.
  • Specialized interfacing is crucial: Directly prompting LLMs with Verilog netlists is ineffective. Solutions like prompt syntax translation (to boolean logic) and divide and conquer (breaking large circuits into smaller components) are essential for LLMs to understand and manipulate hardware IP.
  • Iterative feedback enhances performance: A feedback loop that checks for functional equivalence and syntactic correctness allows LLMs to learn from mistakes and refine their output, significantly improving the success rate of piracy.
  • Model size and training data matter: Larger LLMs (e.g., Code Llama 13B vs. 7B) and those trained on more extensive datasets (e.g., Llama 3 vs. Llama 2) exhibit superior performance in generating pirated circuits.
  • Black-box detection is vulnerable: LLMPirate successfully bypasses both machine learning-based (e.g., GNN for IP) and traditional (e.g., MOSS, SIM) piracy detection tools, highlighting a critical vulnerability in current black-box IP protection schemes.
  • Defensive strategies must adapt: Countermeasures include retraining machine learning detectors with adversarial examples and potentially leveraging performance overheads (e.g., 10% critical path delay) as indicators of tampering.

About the Speaker(s)

Vasudev Gohil is currently affiliated with Seammens. This research on LLMPirate was conducted during his graduate studies at Texas A&M University. His work focuses on exploring the intersection of Large Language Models and hardware security, specifically investigating their potential in adversarial contexts such as hardware IP piracy.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Genuinely novel intersection of LLM capability and hardware security — using generative AI to perform black-box adversarial evasion of gate-level IP piracy detectors is a contribution the field hasn't seen before. The methodology is rigorous: prompt syntax translation, divide-and-conquer decomposition, and formal equivalence verification in a feedback loop are real engineering solutions to real LLM limitations, not hand-waving. Docks one star because the defensive analysis is shallow and the threat model has practical limits the talk undersells.

Heather Calloway (CISO) — WEAK

Technically credible research on a real and underexplored attack surface — LLM-assisted hardware IP piracy at the gate level. But the talk never crosses into the institutional or operational questions that would make it actionable for the people who actually govern semiconductor IP risk.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025