Pith. sign in

REVIEW 2 major objections 1 minor 23 references

Graphlet-based triggers embedded in circuits backdoor GNN hardware security systems without changing functionality.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

GRAFT introduces graphlet-based triggers for backdoor attacks on GNN hardware security systems, achieving up to 100% attack success rate on ISCAS-85 and TrustHub benchmarks while preserving circuit functionality.

T0 review reviewed 2026-06-27 challenge →

load-bearing objection GRAFT claims graphlet triggers let you backdoor GNN hardware-security tools while keeping circuit function identical, but the insertion and equivalence steps are not shown in enough detail to check the claim. the 2 major comments →

arxiv 2606.10163 v1 pith:WRSVGVIH submitted 2026-06-08 cs.CR cs.AR

GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems

classification cs.CR cs.AR
keywords backdoor attacksgraph neural networkshardware trojansgraphletscircuit designRTLIP piracyhardware security
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper presents GRAFT, a backdoor attack method that uses graphlets to compromise GNNs designed to detect hardware Trojans and IP theft in integrated circuits. The attack inserts these small subgraph triggers into the circuit at the RTL or gate level in a manner that keeps the circuit's original behavior unchanged. By doing so, it can cause the GNN to output an adversarial prediction while avoiding detection by standard security checks. The results on common benchmark datasets show the attack reaching up to 100% success rate in fooling the models. This demonstrates that current GNN-based protections for hardware can be bypassed using structurally embedded triggers.

Core claim

GRAFT embeds graphlet-based triggers at either the register-transfer level (RTL) or gate level of the design while preserving the circuit's original function and can effectively evade HT detection and IP piracy detection, achieving an attack success rate (ASR) of up to 100%.

What carries the argument

Graphlet-based trigger embedding, which places small, specific subgraphs into the circuit graph at RTL or gate level to serve as backdoor triggers for the GNN without affecting circuit functionality.

Load-bearing premise

That it is possible to insert graphlet triggers into a circuit design at RTL or gate level without changing the circuit's original function or making the change detectable by standard tools.

What would settle it

Applying GRAFT to a specific circuit from the ISCAS-85 set, then checking with an HT detection tool to see if the trigger is identified or if the circuit output changes from the original.

Watch this falsifier. Get emailed when new claim-graph text bears on it.

If this is right

  • GNN-based detectors for hardware Trojans can be misled to miss the presence of threats.
  • IP piracy detection systems using GNNs can be compromised by these embedded triggers.
  • The attack maintains circuit functionality, allowing it to pass normal verification processes.
  • Evaluation shows the method works on standard circuit benchmarks like ISCAS-85 and TrustHub.
  • Attack success rates can reach 100% while evading existing detection methods.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • Future hardware security might require checking for specific graphlet patterns during design verification.
  • This approach highlights vulnerabilities in graph-based machine learning models used for security tasks beyond hardware.
  • Designers could explore adding randomness or other protections to circuit graphs to prevent such trigger insertions.
  • Similar graphlet trigger methods might be adapted for other domains using GNNs for anomaly detection.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 1 minor

Summary. The paper proposes GRAFT, a graphlet-triggered backdoor attack on GNN-based hardware security systems for HT and IP piracy detection. It embeds graphlet-based triggers at the RTL or gate level of circuit designs while preserving original functionality, evaluated on ISCAS-85 and TrustHub benchmarks, with reported attack success rates up to 100% and effective evasion of standard detectors.

Significance. If the functionality-preservation claim and ASR results hold under rigorous verification, the work would be significant for hardware security by exposing a concrete attack vector against GNN-based detectors that maintains circuit equivalence, thereby motivating stronger robustness requirements for ML tools in the IC supply chain.

major comments (2)
  1. [Abstract] Abstract: the claim that graphlet triggers are embedded 'while preserving the circuit's original function' is load-bearing for both the evasion and ASR results, yet the abstract (and by extension the methods) supplies no description of the insertion operator, chosen graphlets, or verification procedure (simulation, formal equivalence checking, or ATPG).
  2. [Abstract] Abstract/Evaluation: high ASR figures (up to 100 %) are stated without any experimental details, baselines, error bars, or explicit confirmation that the reported success rates were measured on functionally identical netlists, which directly undermines assessment of the central claim.
minor comments (1)
  1. [Abstract] Abstract: the term 'graphlet' is used without a brief definition or reference to the specific graphlet sizes or topologies employed, which would aid readability.

Simulated Author's Rebuttal

2 responses · 0 unresolved

We thank the referee for the constructive comments. We address each major comment below and will revise the manuscript accordingly.

read point-by-point responses
  1. Referee: [Abstract] Abstract: the claim that graphlet triggers are embedded 'while preserving the circuit's original function' is load-bearing for both the evasion and ASR results, yet the abstract (and by extension the methods) supplies no description of the insertion operator, chosen graphlets, or verification procedure (simulation, formal equivalence checking, or ATPG).

    Authors: The abstract is concise by design. The full manuscript provides the description of the graphlet insertion operator, the specific graphlets selected, and the verification procedure (via simulation confirming functional equivalence) in the methods section. We will revise the abstract to include a brief statement on the functionality-preserving insertion and verification approach. revision: yes

  2. Referee: [Abstract] Abstract/Evaluation: high ASR figures (up to 100 %) are stated without any experimental details, baselines, error bars, or explicit confirmation that the reported success rates were measured on functionally identical netlists, which directly undermines assessment of the central claim.

    Authors: Abstracts summarize key results; the experimental section supplies the requested details on baselines, error bars from repeated trials, and explicit confirmation that ASR is measured only on netlists verified as functionally identical. We will revise the abstract to note that the reported ASR values are obtained on functionally equivalent circuits, with full experimental information in the evaluation section. revision: yes

Circularity Check

0 steps flagged

No circularity: empirical attack proposal with no derivations or self-referential reductions

full rationale

The paper is an empirical proposal for a backdoor attack method. It asserts functionality preservation and reports ASR results on ISCAS-85 and TrustHub benchmarks but contains no equations, derivations, fitted parameters, or load-bearing self-citations that reduce claims to inputs by construction. The central claims rest on experimental outcomes rather than any definitional or predictive circularity. No steps qualify under the enumerated patterns.

Axiom & Free-Parameter Ledger

0 free parameters · 0 axioms · 0 invented entities

Abstract-only review contains no mathematical model, fitted parameters, axioms, or new postulated entities; the contribution is an attack construction and empirical claim.

reviewed 2026-06-27 · how reviews work

0 comments
Cite this review

Pith. "Pith review of GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems." pith.science (2026). https://pith.science/paper/WRSVGVIH

@misc{pith2026260610163,
  author       = {Pith},
  title        = {Pith review of: GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/WRSVGVIH}},
  note         = {Machine review of arXiv:2606.10163}
}
Share X Bluesky LinkedIn Reddit HN
read the original abstract

The globalization of the integrated circuit (IC) supply chain increases the risk of security threats, such as hardware Trojans (HTs) and the theft of intellectual property (IP). Graph Neural Networks (GNNs), among the most powerful deep learning methods for processing graph-structured data, have been widely adopted to detect such threats. However, GNNs are susceptible to backdoor attacks that can maliciously manipulate output predictions toward an adversarial target. These attacks are not only difficult to detect but also compromise the integrity of GNN-based security systems. Most prior work embeds backdoor triggers using randomly generated subgraphs or gradient-guided generative subgraphs. However, such triggers are impractical for GNN-based hardware security applications as they do not guarantee the preservation of circuit functionality. In this paper, we propose GRAFT, a graph let-triggered backdoor attack targeting GNN-based hardware security. GRAFT embeds graphlet-based triggers at either the register-transfer level (RTL) or gate level of the design while preserving the circuit 's original function. We evaluate GRAFT on the ISCAS-85 and TrustHub datasets. Our experimental results demonstrate that GRAFT can effectively evade HT detection and IP piracy detection, achieving an attack success rate (ASR) of up to 100%.

Figures

Figures reproduced from arXiv: 2606.10163 by Sai Manoj Pudukotai Dinakarrao, Sanaz Kazemi Abharian.

Figure 1
Figure 1. Figure 1: Illustration of graphlets with 2-4 node distinct connectivity patterns. Their occurrence counts pro￾vide compact and informative representations of both local and global network topology. Therefore, graphlets have been widely used in domains such as neuroscience and social network analysis. In the context of backdoor attacks on GNNs, graphlets can serve as meaningful trigger patterns because they encode im… view at source ↗
Figure 2
Figure 2. Figure 2: Overall framework of GRAFT. (a) Selection of the trigger topology based on graphlet statistics. (b) Selection of the trigger injection position based [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: Threat model for injecting backdoor triggers. The adversary poisons [PITH_FULL_IMAGE:figures/full_fig_p003_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: Example of Logic Deployment in the Boolean circuit. (a) c17 from [PITH_FULL_IMAGE:figures/full_fig_p004_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: Effect of Trigger size (ϕ) and Poisoning Intensity (γ) on the Performance of GRAFT in GNN-Based IP Piracy Detection [PITH_FULL_IMAGE:figures/full_fig_p005_5.png] view at source ↗
Figure 6
Figure 6. Figure 6: Impact of GRAFT under Varying Trigger Size [PITH_FULL_IMAGE:figures/full_fig_p005_6.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

23 extracted references · 2 canonical work pages

  1. [1]

    A survey on hardware security: Current trends and challenges,

    S. Akter, K. Khalil, and M. Bayoumi, “A survey on hardware security: Current trends and challenges,”IEEe Access, vol. 11, pp. 77 543–77 565, 2023

  2. [2]

    Hwsim: Hardware similarity learning for intellectual property piracy detection,

    Z. Jiang, X. Ji, Y . He, and H. Shen, “Hwsim: Hardware similarity learning for intellectual property piracy detection,” in2024 IEEE In- ternational Symposium on Circuits and Systems (ISCAS). IEEE, 2024

  3. [3]

    Hardware trojans in chips: A survey for detection and prevention,

    C. Dong, Y . Xu, X. Liu, F. Zhang, G. He, and Y . Chen, “Hardware trojans in chips: A survey for detection and prevention,”Sensors, vol. 20, no. 18, p. 5165, 2020

  4. [4]

    A survey on security analysis of machine learning-oriented hardware and software intellectual property,

    A. Tauhid, L. Xu, M. Rahman, and E. Tomai, “A survey on security analysis of machine learning-oriented hardware and software intellectual property,”High-Confidence Computing, vol. 3, no. 2, p. 100114, 2023

  5. [5]

    Accelerating hard- ware verification with graph models,

    R. Saravanan, S. Kasarapu, and S. M. P. Dinakarrao, “Accelerating hard- ware verification with graph models,”arXiv preprint arXiv:2412.13374, 2024

  6. [6]

    Hardware trojan detection and interpretation using graph neural networks,

    J. Thangellamudi, N. Etemadyrad, L. Zhao, and S. M. PD, “Hardware trojan detection and interpretation using graph neural networks,” in International Conference on VLSI Design, 2026

  7. [7]

    Profuzz: Directed graybox fuzzing via module selection and atpg-guided seed generation,

    R. Saravanan, S. Paria, A. Dasgupta, S. Bhunia, and S. M. PD, “Profuzz: Directed graybox fuzzing via module selection and atpg-guided seed generation,” in2025 IEEE/ACM International Conference On Computer Aided Design (ICCAD), 2025

  8. [8]

    Grove: Ownership verification of graph neural networks using embeddings,

    A. Waheed, V . Duddu, and N. Asokan, “Grove: Ownership verification of graph neural networks using embeddings,” in2024 IEEE Symposium on Security and Privacy (SP), 2024

  9. [9]

    Gnnfingers: A fingerprinting framework for verifying ownerships of graph neural networks,

    X. You, Y . Jiang, J. Xu, M. Zhang, and M. Yang, “Gnnfingers: A fingerprinting framework for verifying ownerships of graph neural networks,” inProc. ACM Web Conf., 2024

  10. [10]

    Pregip: Watermarking the pretraining of graph neural networks for deep ip protection,

    E. Dai, M. Lin, and S. Wang, “Pregip: Watermarking the pretraining of graph neural networks for deep ip protection,” inProc. 31st ACM SIGKDD Conf. Knowl. Discov. Data Mining, 2025

  11. [11]

    GBFA: Gradual bit-flip fault attack on graph neural network accelerators,

    S. K. Abharian and S. M. P. Dinakarrao, “GBFA: Gradual bit-flip fault attack on graph neural network accelerators,” inIEEE International Symposium on Quality Electronic Design (ISQED), 2026

  12. [12]

    When bits betray the graph: Evaluating bit-flip fault resilience in graph neural networks,

    S. K. Abharian and S. M. Pudukotai Dinakarrao, “When bits betray the graph: Evaluating bit-flip fault resilience in graph neural networks,” in IEEE Dallas Circuits and Systems Conference (DCAS), 2026

  13. [13]

    Backdoor attacks to graph neural networks,

    Z. Zhang, J. Jia, B. Wang, and N. Z. Gong, “Backdoor attacks to graph neural networks,” inProceedings of the 26th ACM symposium on access control models and technologies, 2021

  14. [14]

    Explainability-based backdoor attacks against graph neural networks,

    J. Xu, M. Xue, and S. Picek, “Explainability-based backdoor attacks against graph neural networks,” inProc. 3rd ACM Workshop Wireless Security and Machine Learning, 2021

  15. [15]

    Graph backdoor,

    Z. Xi, R. Pang, S. Ji, and T. Wang, “Graph backdoor,” in30th USENIX security symposium (USENIX Security 21), 2021

  16. [16]

    PoisonedGNN: Backdoor attack on graph neural networks-based hard- ware security systems,

    L. Alrahis, S. Patnaik, M. A. Hanif, M. Shafique, and O. Sinanoglu, “PoisonedGNN: Backdoor attack on graph neural networks-based hard- ware security systems,”IEEE Transactions on Computers, vol. 72, no. 10, 2023

  17. [17]

    A combinatorial approach to graphlet counting,

    T. Ho ˇcevar and J. Dem ˇsar, “A combinatorial approach to graphlet counting,”Bioinformatics, vol. 30, no. 4, pp. 559–565, 2014

  18. [18]

    Gnn4ip: Graph neural network for hardware intellectual property piracy detection,

    R. Yasaei, S.-Y . Yu, E. K. Naeini, and M. A. Al Faruque, “Gnn4ip: Graph neural network for hardware intellectual property piracy detection,” in ACM/IEEE Design Automation Conference (DAC), 2021

  19. [19]

    Gnn4tj: Graph neural networks for hardware trojan detection at register transfer level,

    R. Yasaei, S.-Y . Yu, and M. A. Al Faruque, “Gnn4tj: Graph neural networks for hardware trojan detection at register transfer level,” in Design, Automation & Test in Europe Conf. & Exhibition (DATE), 2021

  20. [20]

    Graph neural backdoor: Fundamen- tals, methodologies, applications, and future directions,

    X. Yang, G. Li, and J. Li, “Graph neural backdoor: Fundamen- tals, methodologies, applications, and future directions,”arXiv preprint arXiv:2406.10573, 2024

  21. [21]

    Badnets: Evaluating backdooring attacks on deep neural networks,

    T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,”Ieee Access, vol. 7, 2019

  22. [22]

    Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,

    B. Wang, Y . Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y . Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” inIEEE symposium on security and privacy (SP), 2019

  23. [23]

    Development and evaluation of hardware obfuscation bench- marks,

    S. Amir, B. Shakya, X. Xu, Y . Jin, S. Bhunia, M. Tehranipoor, and D. Forte, “Development and evaluation of hardware obfuscation bench- marks,”Journal of Hardware and Systems Security, vol. 2, no. 2, 2018

This paper was first reviewed by grok-4.3 on June 27, 2026.