Making Chip Designs Invisible to AI
2026/06/30 by sip
For his project “MIRAGE”, TU Computer Science Professor Ahmad-Reza Sadeghi will receive funding from the European Research Council (ERC) in the form of a Proof of Concept Grant worth 150,000 euros. The project aims to protect valuable code during computer chip development at the very point of design exchange — an endeavour that has already attracted considerable interest from industry.
Modern computer chips are no longer designed by a single manufacturer. Instead, they comprise numerous so-called IP blocks — ready-made circuit components developed and exchanged by different companies. This accelerates development, but it also leaves valuable designs vulnerable: they can be copied or misappropriated through reverse engineering, whereby a technology is replicated by examining it in detail. This threat is growing rapidly, as artificial intelligence is now capable of recognising the functionality of a hardware design. Protective measures such as digital watermarks in the code or strict access controls are barely sufficient any longer to prevent such intrusions.
The ERC project MIRAGE will target this precise vulnerability: the exchange of RTL code (register transfer level, a hardware description language for chip circuitry) between companies, before a chip ever goes into production. MIRAGE aims to automatically generate alternative variants of the RTL code intended for transfer. These variants are functionally identical to the original — describing a component with exactly the same characteristics, such as speed or power consumption — yet are significantly harder for AI systems to identify or replicate. A licensee should be able to make unrestricted use of the code, while automated extraction of the underlying trade secret — in particular the specific design idea — through modern AI methods becomes extremely difficult and, ideally, practically infeasible within any reasonable effort.
Self-learning algorithms ensure functionality and protection
Within the MIRAGE framework, researchers are employing self-learning algorithms to generate code variants and are using comparative simulations to verify correct functionality. They are also testing whether modern AI models capable of understanding programme code genuinely fail to recognise the variants produced by MIRAGE.
The primary target groups are chip component manufacturers, design houses, and open hardware consortia that share or license RTL code during the development phase. Industry demand is substantial. Companies including Intel, KOBIL, and Synopsys have already signalled their interest in MIRAGE and pledged their support.
“Ultimately, the project is intended to protect innovation and competitiveness in the semiconductor industry — enabling open collaboration where it makes sense and providing protection where it is necessary for critical industries and everyday technologies,” says Ahmad-Reza Sadeghi, Professor of System Security at TU Darmstadt and lead of the MIRAGE project.
MIRAGE is based within the Department of Computer Science (research field Information and Intelligence (I+I)). As a proof-of-concept project, it builds on HYDRANOS, for which Sadeghi received an ERC Advanced Grant in 2022. HYDRANOS uses post-manufacture adaptable security-critical chip components to protect the hardware against unknown attacks. MIRAGE enhances the security of chip development by effectively safeguarding the underlying intellectual property at the very point at which design blueprints are exchanged.
About the researcher
Ahmad-Reza Sadeghi is Professor of Computer Science at TU Darmstadt and head of the System Security Lab. Since 2012, he has built a long-standing collaboration with Intel, from which several collaborative research centres have emerged, covering topics such as Secure Computing in Mobile and Embedded Systems, Autonomous and Resilient Systems, and Private AI. Sadeghi has received numerous awards for his research in the field of information and computer security, and in particular hardware-assisted security: the Karl Heinz Beckurts Prize (2008), the ACM SIGSAC Award (2018), the Intel Academic Leadership Award (2021), the DAC Service Award (2024), and the Synopsys Academic Leadership Award (2025). In 2022, he was awarded an ERC Advanced Grant for the HYDRANOS project. He completed his doctorate in Computer Science with a specialisation in cryptography at Saarland University. Prior to his academic career, he spent several years in research and development in the telecommunications industry, including at Ericsson.
‘Proof of Concept’ Grant
A ‘Proof of Concept’ Grant is a funding scheme that complements the research grants awarded by the European Research Council (ERC). It is aimed exclusively at researchers who already hold an ERC grant and wish to exploit a research result from their ongoing or completed project on a pre-commercial basis. This is the first step towards technology transfer. The aim of a proof-of-concept project is to assess the market potential of such an idea. The ERC therefore does not fund research activities in this context, but rather measures aimed at further development with a view to achieving application readiness, commercialisation or the marketing of the idea.