Skip to content
Conference

Game-Theoretic Defense Against Hardware Trojans with Multi-Level Strategies

Aug 2026 · 2026 International Conference on Intelligent Multimedia, Networking, and Security (IMNS) · pp. 1-6 · 0 citations · 20 references

Abstract

Hardware Trojans are malicious circuit modifications that can be covertly inserted during the design or fabrication of integrated circuits, enabling leakage, performance degradation, or mission failure after deployment. Because exhaustive testing against all Trojan classes and activation behaviors are prohibitively expensive, effective defense requires reasoning about the strategic interaction between an IC buyer/tester and a potentially malicious manufacturer. In this paper, we model Hardware Trojan insertion and testing as a two-player zero-sum security game with multi-level attacker and defender intensities. We first derive the Mixed-Strategy Nash Equilibrium (MSNE) under classical expected-utility assumptions and identify parameter regimes in which the game reduces to a smaller equilibrium over the remaining dominant strategies. Recognizing that real decision-makers exhibit bounded rationality, loss aversion, and distorted probability perceptionespecially under low-probability, high-impact threats-we then incorporate Prospect Theory to obtain a ProspectTheoretic MSNE (PT-MSNE) formulation. The resulting equilibrium conditions are nonlinear and are computed numerically under simplex constraints. Extensive simulations quantify how behavioral parameters reshape equilibrium mixing, shift the security-cost tradeoff, and alter defensive investment relative to the rational benchmark, providing actionable insights for designing robust and cost-effective Trojan testing policies under uncertainty and human bias.

View source

Similar papers

Conference Open access Sep 2026

Beyond Homogeneous Adversaries: Stackelberg Security Games with Mixed Quantal Response

A polynomial-time approximation scheme for SSG with mixed quantal response attackers, where the follower population consists of multiple discrete attacker types, each following a type-specific QR model, is developed based on an exponential cone programming formulation combined with a carefully designed Branch-and-Bound...

Hoang Giang Pham, Tien Mai, Thuy Anh Ta et al. · 0 citations
Preprint Sep 2026

Deception in Reach-Avoid Game with Unknown Heterogeneous Attackers Speed Information

This letter investigates a reach-avoid game involving two Attackers and one Defender, where the Attackers aim to maximize the number reaching the target region while the Defender seeks to minimize it. In contrast to conventional complete information formulations, we consider an information asymmetry scenario where the...

Xiang-Kai Wu, Shaolin Tan, Wei Wang et al. · 0 citations
Jul 2026

Symmetric Attack-Defense Game with Incomplete Information

The Sonin’s complex ”fill-and-switch” strategy is reduced to a simple threshold rule: the attacker targets nodes with a negative signal when the sum of sensitivity and specificity is greater than one, and randomizes when the sum is one.

Jia-Rui Liu, V. Mazalov · 1 citation
Open access Aug 2026

Simulation-Informed Bayesian Stackelberg Defense for Multi-Stage Cyber Attacks

A five-stage Bayesian Stackelberg security game with five stage-specific actions per player is formulated, which examines whether simulated attack-action evidence can inform a defender that they must commit before an attacker’s type is known.

Zhao Shen, Rulong He, Xiao Zhang · 0 citations
Aug 2026

ADAPT: Attack-Defense Agent Pipeline for Fault Injection Resilience in Kyber NTT Hardware

Fault injection attacks on the CRYSTALS-Kyber Number Theoretic Transform (NTT) exploit the recursive structure of the butterfly pipeline to corrupt polynomial computations and recover secret keys via Differential Fault Analysis (DFA). Existing countermeasures protect the entire datapath uniformly, imposing area and pow...

Sarita Bista, Mani Rupak Gurram, Yamini Swetha Nadella et al. · 0 citations
Preprint Aug 2026

Beyond Best Response: Quantal Stackelberg Deception as Insurance Against Attacker Misspecification

An empirical evaluation in a cybersecurity case study with two networks and real vulnerabilities drawn from CVE and scored using the Common Vulnerability Scoring System shows that QSE beats Stackelberg in realized defender utility spanning 144 scenarios with specification errors and 25 parameter configurations.

Asif Rahman, Md Abu Sayed, Ahmed Ann Noor Ryen et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.