arrow
Return

On Hardware Security Bug Code Fixes by Prompting Large Language Models

delete2024-01-01
delete17
delete
OA
AI
B
Baleegh Ahmad *
S
Shailja Thakur
B
Benjamin Tan
R
Ramesh Karri
H
Hammond Pearce
DOI:10.1109/TIFS.2024.3374558delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Novel AI-based code-writing Large Language Models (LLMs) such as OpenAI's Codex have demonstrated capabilities in many coding-adjacent domains. In this work, we consider how LLMs may be leveraged to automatically repair identified security-relevant bugs present in hardware designs by generating replacement code. We focus on bug repair in code written in Verilog. For this study, we curate a corpus of domain-representative hardware security bugs. We then design and implement a framework to quantitatively evaluate the performance of any LLM tasked with fixing the specified bugs. The framework supports design space exploration of prompts (i.e., prompt engineering) and identifying the best parameters for the LLM. We show that an ensemble of LLMs can repair all fifteen of our benchmarks. This ensemble outperforms a state-of-the-art automated hardware bug repair tool on its own suite of bugs. These results show that LLMs have the ability to repair hardware security bugs and the framework is an important step towards the ultimate goal of an automated end-to-end bug repair tool.
Keywords:
Maintenance engineering
Computer bugs
Codes
Hardware
Security
Software
Registers
Hardware security
large language models
bug repair

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

U
University of Calgary
Scholars:
3.8W
Papers: 3.3W
Citations: 52
N
New York University
Scholars:
4.4W
Papers: 3.9W
Citations: 5.8W
N
New York University Tandon School of Engineering
Scholars:
1.1K
Papers: 846
Citations: 0
researcher View more organizations