Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Assessing Runtime Electromagnetic Detection of CPU Hardware Trojans Targeting Kernel Memory

A side-channel approach for detecting malicious hardware activity via EM emanations on RISC-V
Athanasios Moschos; Baki Berkay Yilmaz; Kevin Valakuzhy; Angelos D. Keromytisยท 2026ยท DOI 10.48550/arXiv.2609.23186

The core problem

Hardware trojans pose a significant threat to computing systems, as they can be inserted during design or fabrication and remain dormant until triggered. Traditional detection methods often require destructive analysis or additional circuitry, which may not be feasible for deployed systems. Side-channel analysis, particularly electromagnetic (EM) emanations, offers a passive, non-invasive alternative. This paper explores the use of EM emissions for runtime detection of hardware trojans that target kernel memory. The authors leverage an open-source hardware trojan implementing an arbitrary memory-write primitive to compromise the kernel memory of a Linux system running on a RISC-V microarchitecture. The goal is to determine whether EM side-channels can reveal the trojan's activity indirectly through the anomalous software behavior it induces.

Innovation

The experiments demonstrate that under certain conditions, the hardware trojan can be detected indirectly through its impact on software behavior. When the trojan performs memory writes, the kernel's execution flow changes, leading to altered EM emissions. The authors observed that these changes are detectable in real-time, with a low false-positive rate. However, detection is not always reliable; factors such as noise, trojan trigger frequency, and the specific memory addresses targeted affect detectability. The results indicate that EM side-channel detection is feasible for kernel-memory-targeting trojans, but its effectiveness depends on the trojan's implementation and the operating environment. Quantitative results are not provided in the abstract, but the authors emphasize the indirect nature of detection: the trojan is caught not by its hardware signature but by the software anomalies it causes.
Hardware trojans pose a significant threat to computing systems, as they can be inserted during design or fabrication and remain dormant until triggered. Traditional detection methods often require destructive analysis or additional circuitry, which may not be feasible for deployed systems. Side-channel analysis, particularly electromagnetic (EM) emanations, offers a passive, non-invasive alternative. This paper explores the use of EM emissions for runtime detection of hardware trojans that target kernel memory. The authors leverage an open-source hardware trojan implementing an arbitrary memory-write primitive to compromise the kernel memory of a Linux system running on a RISC-V microarchitecture. The goal is to determine whether EM side-channels can reveal the trojan's activity indirectly through the anomalous software behavior it induces.
The experimental setup consists of a RISC-V processor running a Linux kernel, with an open-source hardware trojan inserted into the CPU design. The trojan provides an arbitrary memory-write primitive, allowing it to modify kernel memory. The authors perform real-time monitoring of the processor's EM emissions using an antenna and software-defined radio. They establish a baseline of normal EM emissions during regular operation and then trigger the trojan to perform malicious writes. The detection method analyzes deviations from the baseline EM signature. The key hypothesis is that the trojan's activity, while stealthy at the hardware level, causes detectable anomalies in software execution that manifest in EM emissions. The experimental workflow is illustrated below:

Why it matters

The findings suggest that EM side-channel analysis can serve as a runtime detection mechanism for hardware trojans, particularly those that induce observable software-level effects. This approach is passive and does not require modifying the device under test. However, limitations exist: the method may fail if the trojan's activity does not significantly alter EM emissions or if the system is too noisy. The authors note that detection is indirect, relying on the trojan's impact on software, which may not be unique to malicious activity. Future work could explore combining EM analysis with other side-channels or machine learning for improved accuracy. The study contributes to the broader field of hardware security by demonstrating a practical detection strategy for a critical threat model. The taxonomy of the work spans Architecture, Cybersecurity, Network, and Cryptography, highlighting its interdisciplinary nature.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ