Revisiting Logic Encryption

arXiv:2512.00833 · cs.CR, cs.AR · Submitted 2026-08-21 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: Next we'll be talking about the paper "Revisiting Logic Encryption".

Jane: The paper was written by Rupesh Raj Karn, Lakshmi Likhitha Mankali, Zeng Wang, Saideep Sreekumar, Prithwish Basu Roy et al. from New York University Tandon School of Engineering, New York, USA and New York University Abu Dhabi, Abu Dhabi, UAE and Khalifa University, Abu Dhabi, UAE.

Tom: Stay tuned as we take you through the paper and discuss its implications.

Title: Jane: We've seen how the authors are tackling old concepts with a fresh perspective in the title "Revisiting Logic Encryption: This Time for Real." It sounds like they believe that previous attempts at logic protection weren't truly securing the design.

Tom: They're right; if you want to protect intellectual property, just having key-gates scattered around isn' isn't enough, as many attacks show in the literature.

Lu: I think the real excitement here is that they are aiming for full-scale obfuscation of the design IP, not just localized protection.

Meng: That goal is what makes this interesting from an industry perspective; we want a solution that actually works against advanced adversaries, not just a quick fix.

Lalam: The commitment to "This Time for Real" suggests a cultural shift toward making this security standard again in the hardware design world.

Tom: And the paper's abstract really sets the stage by mentioning that modern circuits face threats like reverse engineering and side-channel attacks.

Jane: It’s clear they see the need to protect ICs in today's landscape, and we can see how they are addressing these risks through a novel approach to Logic Encryption.

Lu: The mention of "oracle-less attacks" is huge, because that means even if the attacker doesn't have special tools, this scheme holds up.

Meng: From an implementation viewpoint, I'd be very interested in seeing how they manage these threats without introducing massive overheads.

Lalam: This groundwork laid out in the abstract shows a strong commitment to establishing a foundation for secure hardware design going forward.

Tom: Let's look at the summary and see exactly what they promise to deliver next, Jane.

Summary: Jane: The summary of "Revisiting Logic Encryption" tells us that this approach is fundamentally different from prior art in logic locking, which is a massive statement.

Tom: They're not just adding key-gates; they' are encrypt the netlist itself using cryptographic algorithms and simple circuit design techniques.

Lu: I find the way they describe the methodology very creative, since we are taking something as simple as AES and applying it to entire blocks of logic.

Meng: It seems like a highly automated process, which is good because manual implementation is usually a bottleneck in real-world design flows.

Lalam: The commitment to an end-to-end method shows they' are serious about providing a complete, usable solution for the global community of hardware designers.

Tom: They specifically mention that our work outperforms prior art against a range of oracle-less attacks, which is impressive data.

Jane: It’s not just that they perform well; it seems like they are doing so while maintaining lower design overheads than existing solutions.

Lu: The fact that we have this open-source release is a big deal, allowing anyone to see exactly how the encryption and decryption works in practice.

Meng: An end-to-end method means that if I'm at a startup, I can use this today without needing to wait for theoretical proof of implementation.

Lalam: This summary shows how the paper is trying to provide both a technically rigorous defense and a practical, open approach to elevate the standard of hardware security.

Tom: We're talking about overcoming previous limitations and seeing what kind of improvements they bring in our next segment, Jane.

Improvements: Jane: The paper highlights several key contributions to "Revisiting Logic Encryption," and it’s clear the authors see this as a paradigm shift for the industry.

Tom: They are emphasizing that this is a first-of-its-kind work where actually encrypt the logic itself, which is truly groundbreaking in its scope.

Lu: The focus on "fully obfuscate" suggests that they aren't just hiding some parts of the design; they' are scrambling the entire functional representation.

Meng: From an engineering standpoint, I’m impressed by the claim that using commercial-grade CAD tools makes this robust and relevant for real-world insights.

Lalam: The fact that they provide a full open-source release is a major contribution to fostering collaboration and accelerating research in hardware security globally.

Tom: We also have this thorough security evaluation, covering crucial threat vectors like machine learning attacks on KG structures.

Jane: It’s not just theory; the authors are testing against real-world ML attacks, which is very valuable for practical implementation advice.

Lu: The way they are tackling these vulnerabilities suggests a deep understanding of how attackers exploit both structural and functional information.

Meng: I'm interested in how this method manages power consumption compared to existing solutions, since that’s critical for any chip design.

Lalam: This commitment to transparency and thorough testing shows a dedication to improving the quality and security culture of our technological advancements.

Tom: Let's look at the results and see what kind of impact this has on our final wrap-up, Jane.

Conclusion: Jane: So, we've covered how "Revisiting Logic Encryption: This Time for Real" presents a new way to fundamentally protect hardware design by encrypt the entire logic.

Tom: It’s clear they are offering a solution that outperforms prior art in security while also being efficient in terms of PPA overheads.

Lu: The fact that it' is resilient even against advanced ML-based reverse engineering makes it incredibly promising for future proof designs.

Meng: This has the potential to change how we design secure chips, offering a practical alternative that scales well across different benchmarks.

Lalam: It seems like this work can really help build a more secure and reliable foundation for the next generation of global technology development.

Tom: We've been discussing "Revisiting Logic Encryption: This Time for Real" and its findings, and I think we have a lot to unpack regarding its potential impact.

Lu: I hope that this approach will inspire further creativity in how we protect sensitive intellectual property everywhere.

Meng: If the implementation remains efficient, it’ could revolutionize how secure components are manufactured and deployed at scale.

Lalam: I believe that this work is a powerful statement about the need to adopt better security standards to elevate our collective technological culture.

Tom: Before we sign off, I want to thank all our guests for sharing your insights on this paper, "Revisiting Logic Encryption: This Time for Real," and it's been a fantastic conversation.

Rupesh Raj Karn, Lakshmi Likhitha Mankali, Zeng Wang, Saideep Sreekumar, Prithwish Basu Roy, Ozgur Sinanoglu, Lilas Alrahis, Johann Knechtel

New York University Tandon School of Engineering, New York, USA · New York University Abu Dhabi, Abu Dhabi, UAE · Khalifa University, Abu Dhabi, UAE

cs.CR, cs.AR

Submitted: 2026-08-21

Updated: 2026-08-25

Code: https://github.com/lilasrahis/MuxLink

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 86/100

The gist: Abstract and Core Contribution The paper addresses critical threats facing modern integrated circuits (ICs), such as reverse engineering (RE), theft of intellectual property (IP), and side-channel

Key concepts

Logic Encryption
This is a method to protect intellectual property (IP) by applying cryptographic algorithms to encrypt the entire functional representation of a circuit. Unlike localized protection, this technique aims for full-scale obfuscation, scrambling the entire design to make it resistant to reverse engineering and advanced attacks.
Oracle-less Attacks
These are security threats where an attacker does not require specific tools or specialized information (an oracle) to exploit a vulnerability. The paper demonstrates that its encryption scheme is resilient and holds up against these types of generalized attacks, proving its robust nature.
PPA Overhead
PPA stands for Power, Performance, and Area. This refers to the efficiency of a chip design. The paper highlights that its logic encryption method achieves high levels of security without introducing massive overheads in terms of power consumption or physical space on the silicon.

Terminology

Summary

Abstract and Core Contribution

The paper addresses critical threats facing modern integrated circuits (ICs), such as reverse engineering (RE), theft of intellectual property (IP), and side-channel attacks. The authors present a novel approach to IP protection based on logic encryption (LE). This method differs fundamentally from established logic locking (LL) schemes, as it obfuscates the circuit’s structure and functionality by encoding and encrypt[ing] the logic itself. The work devises an end-to-end method for practical LE implementation using standard cryptographic algorithms, key-bit randomization, simple circuit design techniques, and system-level synthesis operations. The authors assert that their extensive analysis demonstrates the remarkable efficacy of our scheme, outperforming prior art against a range of oracle-less attacks... all with lower design overheads. Furthermore, the authors provide a full open-source release of the method.

Paradigm Shift: Logic Encryption vs. Logic Locking

The authors distinguish their work from previous attempts at logic encryption (LE) and common logic locking (LL). While early works established a foundation for protection by embedding Key-Gate (KG) structures, the current approach is often merely an afterthought in LL, leading to significant vulnerabilities. The paper signifies a paradigm shift, advocating for the encryption of the logic itself. This approach involves encoding the original circuit into binary plaintexts, encrypt[ing] them using established cryptographic algorithms, and decoding them back into an encrypted circuit that is integrated with decryption-like circuitry in the final protected design.

Methodology: End-to-End Implementation (Stages A through E)

The authors detail a fully automated, end-to-end method for LE, which involves five distinct stages:

  1. Construction of Encrypted Circuit (EC) [Stage A]:
  • A coding scheme is devised using universal NAND and NOR gates. The assignment of these code-words to the gates is randomly decided and memorized.

  • The original circuit (OC) is resynthesized, and each gate is encoded into a binary plaintext of g bits. The order in which all gates are selected during encoding is also randomized.

  • This plaintext—the encoded representation of the resynthesized OC—is encrypted using AES-128 with random keys, resulting in the EC. This step ensures that any correlations between the logic of the OC and EC are truly obfuscated.

  • The ciphertext is decoded using the coding scheme and memorized gate order to produce a basic EC, which is then resynthesized into an intermediate EC.

  1. Construction of Correction Circuit (CC) [Stage B]:
  • The CC logic is constructed such that it operates on the primary outputs (POs) of the original circuit (PO OC) and the corresponding PO of the EC (PO EC). The logic is defined as: PO CC = PO OC PO EC. This logic is compiled into a top-level Verilog module, forming the final CC.
  1. Randomization of Encrypted Circuit [Stage C]:

The intermediate EC’s primary output is randomly buffered or inverted, resulting in the final EC.

  1. System-Level Integration (FC) [Stage D]:
  • POs from the EC and CC are passed through MUX-based KG structures. The final functionality is restored via XOR gates: PO FC = PO EC PO CC.

  • The final key-bits (K FC) are derived by considering the entanglement of intermediate key-bits (K EC, K CC, and K MUX). The final circuit (FC) is synthesized using these components.

  1. Verification and Analysis [Stage E]:
  • Formal verification is performed, confirming that all steps are correct-by-construction.

Security Evaluation (Section 4)

The scheme was tested against various oracle-less attacks, including OMLA (KG structures), MuxLink (KG interconnectivity), SCOPE/Resynthesis (joint prediction), and GNN-RE (Reverse Engineering).

  • OMLA: LE demonstrates consistently strong resilience, with success rates worse than random guessing for smaller benchmarks, and is superior by 1.17x on average compared to TRLL.

  • MuxLink: LE exhibits good resilience, and despite employing a worst-case security analysis where system-level interconnect components are accessible, LE is superior by 1.64x on average compared to gDMUX.

  • SCOPE/Resynthesis: For the joint prediction attack (AC), LE outperforms TRLL by 1.57x, gDMUX by 1.89x, and LUT-L by 1.60x, demonstrating strong resilience even under sophisticated attacks that challenge the fundamental assumptions of prior art.

  • GNN-RE: In reverse engineering (F1 scores), LE imposes the lowest F1 micro and macro scores among all schemes, outperforming TRLL by 3.58x, gDMUX by 3.41x, and LUT-L by 1.17x.

Design Analysis (Section 4.8)

The PPA (Power, Performance, Area) overheads are analyzed across various benchmarks:

  • LE significantly outperforms prior art for both area and power.

  • Combined PPA overheads show that LE outperforms, on average, TRLL by 2.45x, gDMUX by 8.72x, and LUT-L by 1.55%.

  • The design is noted to be competitive in performance against SOTA schemes.

Conclusion

The authors conclude that LE truly obfuscates the circuit’s structure and functionality at full scale, unlike previous work which merely altered local behavior or integrated KG structures as an afterthought. The scheme is presented as a robust, end-to-end solution with lower PPA overheads and superior security against advanced attacks.

Improvements for AI systems

The logic encryption (LE) methodology outlined in this paper provides a robust, end-to-end framework for protecting critical Intellectual Property (IP) within high-performance AI accelerators. The following specific improvements can be integrated into the design and deployment pipeline of AI systems:

1. Implementation of End-to-End Logic Encryption (EC/CC Integration)

  • Improvement: Replace standard, post-design Key-Gate (KG) insertion methods with the full LE workflow:

  • Encoding and Cryptographic Obfuscation: The core logic of the AI accelerator (e.g, a systolic array or attention mechanism) is first encoded into binary plaintext. This plaintext is then encrypted using a standard block cipher (AES-128), generating an Encrypted Circuit (EC).

  • Functional Correction: A Correction Circuit (CC) is designed to operate on the outputs of the original circuit (PO OC) XORed with the outputs of the EC (PO OC PO EC). This method, coupled with randomized key-bits (K CC), ensures that the functional integrity of the original AI logic is preserved despite its structural encryption.

  • System-Level Interconnect Obfuscation: The EC and CC are integrated into a Final Circuit (FC) using MUX-based Key-Gate structures at the system level. These MUX structures, with their own randomized key-bits (K MX), entangle the operational components, creating a complex dependency that is not merely localized to local logic gates.

2. Integration of Design and Security Verification

  • Improvement: Adopt the rigorous verification process (Stage E) as a correct-by-construction sanity check throughout the entire design flow. This ensures that functional equivalence (PO FC = PO OC) is mathematically guaranteed at every stage of the encryption, correction, and integration, eliminating design errors introduced by complex cryptographic transformations.

3. Optimization of Design Constraints (PPA)

  • Improvement: Utilize the synthesis-driven implementation strategy (Stage 3.1 - Step 5). Instead of relying on costly, invasive bubble-pushing or structural modifications common in prior LL schemes, the EC is resynthesized using the full gate library. This ensures that while the logic is encrypted, its physical realization maintains competitive Power, Performance (Timing), and Area (PPA) overheads compared to existing state-of-the-art methods.

By implementing this LE framework, an AI system gains the following capabilities:

  1. High Resilience Against Structural Attacks: The system becomes highly resistant to sophisticated structural analysis attacks (e.g., GNN-RE and OMLA). Since the logic's functionality is cryptographically randomized rather than merely locally altered, attackers cannot rely on identifying patterns or functional similarities between gate types.

  2. Defense Against Machine Learning-Based Prediction: The system is significantly more robust against ML-based prediction of key structures and interconnect dependencies (MuxLink/SCOPE). The combination of full logic encryption (EC) coupled with randomized system-level MUX interconnect keys (K MX) ensures that the necessary information for a successful joint attack is too complex and highly entangled to be inferred reliably.

  3. Guaranteed Functional Integrity: Unlike systems relying on localized, post-design modifications, the this LE system provides verifiable assurance that the encrypted logic still executes the intended AI computations (e.g, accurate matrix multiplication or attention scoring) with 100% functional fidelity when the correct keys are applied.

  4. Scalability: The design flow is demonstrated to scale effectively across various benchmarks and key sizes, ensuring that increased complexity in larger AI models does not lead to disproportionately higher security overheads compared to prior art.

Sources

Related papers