Impressions from the 9th HACK@DAC at the Design Automation Conference (DAC) 2026

2026/09/09

Every year, we are surprised by the creativity of the participating teams in identifying and exploiting hardware vulnerabilities.

Why hardware vulnerabilities matter

The number and complexity of hardware vulnerabilities have increased significantly. Hardware can no longer automatically be considered a trust anchor.

Because hardware lies at the heart of every computing system, we need efficient methods for detecting vulnerabilities pre- and post-fabrication.

The role of AI

AI can substantially accelerate hardware-security analysis. It can help generate test cases, guide fuzzing campaigns, analyze complex execution traces, and identify suspicious design behavior.

Our own research has shown significant results using AI-assisted and hardware-guided fuzzing techniques. However, AI is not a replacement for rigorous verification. Its findings must remain reproducible, explainable, and independently validated.

How the HACK@DAC teams approach the competition

The teams may use any tools, but they must demonstrate how they discovered and exploited the vulnerabilities in the provided platform.

It is fascinating to see teams combine fuzzing, formal analysis, simulation, reverse engineering, manual inspection, and AI-based tools. Some approaches can bypass certain obfuscations, a particular challenge for LLMs, because obfuscated designs are difficult to represent and reason about through tokens alone. We examine this issue in our DAC 2026 paper:

AttackonCTF: Defending Hardware Security Competition Benchmarks in the Age of LLMs (https://lnkd.in/eDGrKP-u)

The winners

The competition was exceptionally challenging. Congratulations to the first three teams:

Team HASS Lab, Institute of Software, Chinese Academy of Sciences

Haoran Liu, Zhiqing Rui, Chengjie Wang, Fangze Cao

Advisors: Xiang Ling and Jingzheng Wu

Team NCTI_Sherlock, Southeast University

Yuchen Hu, Mingyang Song, Junhao Ye

Advisor: Zhe Jiang

Team CalgaryISH, University of Calgary

Bryan Kwan, Nick Allison, Raha Moradi Shahmiri, Raheel Afsharmazayejani

Advisor: Benjamin Tan

Thanks and appreciation

Sincere thanks to my co-organizer, JV Rajendran and his team, and to Jason Fung from Intel for a decade of partnership.

I would also like to thank our sponsors, Siemens and VOLTAI, for their valuable support.

What Next?

Join us at the next competition, HACK@CHES, hosted at CHES, the premier international conference for cryptographic hardware and embedded-system security.