REVIEW 2 major objections 1 minor 23 references
Graphlet-based triggers embedded in circuits backdoor GNN hardware security systems without changing functionality.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
GRAFT introduces graphlet-based triggers for backdoor attacks on GNN hardware security systems, achieving up to 100% attack success rate on ISCAS-85 and TrustHub benchmarks while preserving circuit functionality.
T0 review reviewed 2026-06-27 challenge →
load-bearing objection GRAFT claims graphlet triggers let you backdoor GNN hardware-security tools while keeping circuit function identical, but the insertion and equivalence steps are not shown in enough detail to check the claim. the 2 major comments →
GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
Core claim
GRAFT embeds graphlet-based triggers at either the register-transfer level (RTL) or gate level of the design while preserving the circuit's original function and can effectively evade HT detection and IP piracy detection, achieving an attack success rate (ASR) of up to 100%.
What carries the argument
Graphlet-based trigger embedding, which places small, specific subgraphs into the circuit graph at RTL or gate level to serve as backdoor triggers for the GNN without affecting circuit functionality.
Load-bearing premise
That it is possible to insert graphlet triggers into a circuit design at RTL or gate level without changing the circuit's original function or making the change detectable by standard tools.
What would settle it
Applying GRAFT to a specific circuit from the ISCAS-85 set, then checking with an HT detection tool to see if the trigger is identified or if the circuit output changes from the original.
If this is right
- GNN-based detectors for hardware Trojans can be misled to miss the presence of threats.
- IP piracy detection systems using GNNs can be compromised by these embedded triggers.
- The attack maintains circuit functionality, allowing it to pass normal verification processes.
- Evaluation shows the method works on standard circuit benchmarks like ISCAS-85 and TrustHub.
- Attack success rates can reach 100% while evading existing detection methods.
Where Pith is reading between the lines
- Future hardware security might require checking for specific graphlet patterns during design verification.
- This approach highlights vulnerabilities in graph-based machine learning models used for security tasks beyond hardware.
- Designers could explore adding randomness or other protections to circuit graphs to prevent such trigger insertions.
- Similar graphlet trigger methods might be adapted for other domains using GNNs for anomaly detection.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes GRAFT, a graphlet-triggered backdoor attack on GNN-based hardware security systems for HT and IP piracy detection. It embeds graphlet-based triggers at the RTL or gate level of circuit designs while preserving original functionality, evaluated on ISCAS-85 and TrustHub benchmarks, with reported attack success rates up to 100% and effective evasion of standard detectors.
Significance. If the functionality-preservation claim and ASR results hold under rigorous verification, the work would be significant for hardware security by exposing a concrete attack vector against GNN-based detectors that maintains circuit equivalence, thereby motivating stronger robustness requirements for ML tools in the IC supply chain.
major comments (2)
- [Abstract] Abstract: the claim that graphlet triggers are embedded 'while preserving the circuit's original function' is load-bearing for both the evasion and ASR results, yet the abstract (and by extension the methods) supplies no description of the insertion operator, chosen graphlets, or verification procedure (simulation, formal equivalence checking, or ATPG).
- [Abstract] Abstract/Evaluation: high ASR figures (up to 100 %) are stated without any experimental details, baselines, error bars, or explicit confirmation that the reported success rates were measured on functionally identical netlists, which directly undermines assessment of the central claim.
minor comments (1)
- [Abstract] Abstract: the term 'graphlet' is used without a brief definition or reference to the specific graphlet sizes or topologies employed, which would aid readability.
Simulated Author's Rebuttal
We thank the referee for the constructive comments. We address each major comment below and will revise the manuscript accordingly.
read point-by-point responses
-
Referee: [Abstract] Abstract: the claim that graphlet triggers are embedded 'while preserving the circuit's original function' is load-bearing for both the evasion and ASR results, yet the abstract (and by extension the methods) supplies no description of the insertion operator, chosen graphlets, or verification procedure (simulation, formal equivalence checking, or ATPG).
Authors: The abstract is concise by design. The full manuscript provides the description of the graphlet insertion operator, the specific graphlets selected, and the verification procedure (via simulation confirming functional equivalence) in the methods section. We will revise the abstract to include a brief statement on the functionality-preserving insertion and verification approach. revision: yes
-
Referee: [Abstract] Abstract/Evaluation: high ASR figures (up to 100 %) are stated without any experimental details, baselines, error bars, or explicit confirmation that the reported success rates were measured on functionally identical netlists, which directly undermines assessment of the central claim.
Authors: Abstracts summarize key results; the experimental section supplies the requested details on baselines, error bars from repeated trials, and explicit confirmation that ASR is measured only on netlists verified as functionally identical. We will revise the abstract to note that the reported ASR values are obtained on functionally equivalent circuits, with full experimental information in the evaluation section. revision: yes
Circularity Check
No circularity: empirical attack proposal with no derivations or self-referential reductions
full rationale
The paper is an empirical proposal for a backdoor attack method. It asserts functionality preservation and reports ASR results on ISCAS-85 and TrustHub benchmarks but contains no equations, derivations, fitted parameters, or load-bearing self-citations that reduce claims to inputs by construction. The central claims rest on experimental outcomes rather than any definitional or predictive circularity. No steps qualify under the enumerated patterns.
Axiom & Free-Parameter Ledger
Cite this review
Pith. "Pith review of GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems." pith.science (2026). https://pith.science/paper/WRSVGVIH
@misc{pith2026260610163,
author = {Pith},
title = {Pith review of: GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems},
year = {2026},
howpublished = {\url{https://pith.science/paper/WRSVGVIH}},
note = {Machine review of arXiv:2606.10163}
}
read the original abstract
The globalization of the integrated circuit (IC) supply chain increases the risk of security threats, such as hardware Trojans (HTs) and the theft of intellectual property (IP). Graph Neural Networks (GNNs), among the most powerful deep learning methods for processing graph-structured data, have been widely adopted to detect such threats. However, GNNs are susceptible to backdoor attacks that can maliciously manipulate output predictions toward an adversarial target. These attacks are not only difficult to detect but also compromise the integrity of GNN-based security systems. Most prior work embeds backdoor triggers using randomly generated subgraphs or gradient-guided generative subgraphs. However, such triggers are impractical for GNN-based hardware security applications as they do not guarantee the preservation of circuit functionality. In this paper, we propose GRAFT, a graph let-triggered backdoor attack targeting GNN-based hardware security. GRAFT embeds graphlet-based triggers at either the register-transfer level (RTL) or gate level of the design while preserving the circuit 's original function. We evaluate GRAFT on the ISCAS-85 and TrustHub datasets. Our experimental results demonstrate that GRAFT can effectively evade HT detection and IP piracy detection, achieving an attack success rate (ASR) of up to 100%.
Figures
Reference graph
Works this paper leans on
-
[1]
A survey on hardware security: Current trends and challenges,
S. Akter, K. Khalil, and M. Bayoumi, “A survey on hardware security: Current trends and challenges,”IEEe Access, vol. 11, pp. 77 543–77 565, 2023
2023
-
[2]
Hwsim: Hardware similarity learning for intellectual property piracy detection,
Z. Jiang, X. Ji, Y . He, and H. Shen, “Hwsim: Hardware similarity learning for intellectual property piracy detection,” in2024 IEEE In- ternational Symposium on Circuits and Systems (ISCAS). IEEE, 2024
2024
-
[3]
Hardware trojans in chips: A survey for detection and prevention,
C. Dong, Y . Xu, X. Liu, F. Zhang, G. He, and Y . Chen, “Hardware trojans in chips: A survey for detection and prevention,”Sensors, vol. 20, no. 18, p. 5165, 2020
2020
-
[4]
A survey on security analysis of machine learning-oriented hardware and software intellectual property,
A. Tauhid, L. Xu, M. Rahman, and E. Tomai, “A survey on security analysis of machine learning-oriented hardware and software intellectual property,”High-Confidence Computing, vol. 3, no. 2, p. 100114, 2023
2023
-
[5]
Accelerating hard- ware verification with graph models,
R. Saravanan, S. Kasarapu, and S. M. P. Dinakarrao, “Accelerating hard- ware verification with graph models,”arXiv preprint arXiv:2412.13374, 2024
-
[6]
Hardware trojan detection and interpretation using graph neural networks,
J. Thangellamudi, N. Etemadyrad, L. Zhao, and S. M. PD, “Hardware trojan detection and interpretation using graph neural networks,” in International Conference on VLSI Design, 2026
2026
-
[7]
Profuzz: Directed graybox fuzzing via module selection and atpg-guided seed generation,
R. Saravanan, S. Paria, A. Dasgupta, S. Bhunia, and S. M. PD, “Profuzz: Directed graybox fuzzing via module selection and atpg-guided seed generation,” in2025 IEEE/ACM International Conference On Computer Aided Design (ICCAD), 2025
2025
-
[8]
Grove: Ownership verification of graph neural networks using embeddings,
A. Waheed, V . Duddu, and N. Asokan, “Grove: Ownership verification of graph neural networks using embeddings,” in2024 IEEE Symposium on Security and Privacy (SP), 2024
2024
-
[9]
Gnnfingers: A fingerprinting framework for verifying ownerships of graph neural networks,
X. You, Y . Jiang, J. Xu, M. Zhang, and M. Yang, “Gnnfingers: A fingerprinting framework for verifying ownerships of graph neural networks,” inProc. ACM Web Conf., 2024
2024
-
[10]
Pregip: Watermarking the pretraining of graph neural networks for deep ip protection,
E. Dai, M. Lin, and S. Wang, “Pregip: Watermarking the pretraining of graph neural networks for deep ip protection,” inProc. 31st ACM SIGKDD Conf. Knowl. Discov. Data Mining, 2025
2025
-
[11]
GBFA: Gradual bit-flip fault attack on graph neural network accelerators,
S. K. Abharian and S. M. P. Dinakarrao, “GBFA: Gradual bit-flip fault attack on graph neural network accelerators,” inIEEE International Symposium on Quality Electronic Design (ISQED), 2026
2026
-
[12]
When bits betray the graph: Evaluating bit-flip fault resilience in graph neural networks,
S. K. Abharian and S. M. Pudukotai Dinakarrao, “When bits betray the graph: Evaluating bit-flip fault resilience in graph neural networks,” in IEEE Dallas Circuits and Systems Conference (DCAS), 2026
2026
-
[13]
Backdoor attacks to graph neural networks,
Z. Zhang, J. Jia, B. Wang, and N. Z. Gong, “Backdoor attacks to graph neural networks,” inProceedings of the 26th ACM symposium on access control models and technologies, 2021
2021
-
[14]
Explainability-based backdoor attacks against graph neural networks,
J. Xu, M. Xue, and S. Picek, “Explainability-based backdoor attacks against graph neural networks,” inProc. 3rd ACM Workshop Wireless Security and Machine Learning, 2021
2021
-
[15]
Graph backdoor,
Z. Xi, R. Pang, S. Ji, and T. Wang, “Graph backdoor,” in30th USENIX security symposium (USENIX Security 21), 2021
2021
-
[16]
PoisonedGNN: Backdoor attack on graph neural networks-based hard- ware security systems,
L. Alrahis, S. Patnaik, M. A. Hanif, M. Shafique, and O. Sinanoglu, “PoisonedGNN: Backdoor attack on graph neural networks-based hard- ware security systems,”IEEE Transactions on Computers, vol. 72, no. 10, 2023
2023
-
[17]
A combinatorial approach to graphlet counting,
T. Ho ˇcevar and J. Dem ˇsar, “A combinatorial approach to graphlet counting,”Bioinformatics, vol. 30, no. 4, pp. 559–565, 2014
2014
-
[18]
Gnn4ip: Graph neural network for hardware intellectual property piracy detection,
R. Yasaei, S.-Y . Yu, E. K. Naeini, and M. A. Al Faruque, “Gnn4ip: Graph neural network for hardware intellectual property piracy detection,” in ACM/IEEE Design Automation Conference (DAC), 2021
2021
-
[19]
Gnn4tj: Graph neural networks for hardware trojan detection at register transfer level,
R. Yasaei, S.-Y . Yu, and M. A. Al Faruque, “Gnn4tj: Graph neural networks for hardware trojan detection at register transfer level,” in Design, Automation & Test in Europe Conf. & Exhibition (DATE), 2021
2021
-
[20]
Graph neural backdoor: Fundamen- tals, methodologies, applications, and future directions,
X. Yang, G. Li, and J. Li, “Graph neural backdoor: Fundamen- tals, methodologies, applications, and future directions,”arXiv preprint arXiv:2406.10573, 2024
-
[21]
Badnets: Evaluating backdooring attacks on deep neural networks,
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,”Ieee Access, vol. 7, 2019
2019
-
[22]
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,
B. Wang, Y . Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y . Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” inIEEE symposium on security and privacy (SP), 2019
2019
-
[23]
Development and evaluation of hardware obfuscation bench- marks,
S. Amir, B. Shakya, X. Xu, Y . Jin, S. Bhunia, M. Tehranipoor, and D. Forte, “Development and evaluation of hardware obfuscation bench- marks,”Journal of Hardware and Systems Security, vol. 2, no. 2, 2018
2018
This paper was first reviewed by grok-4.3 on June 27, 2026.
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.