Impressions from the 9th HACK@DAC at the Design Automation Conference (DAC) 2026
2026/09/09
Every year, we are surprised by the creativity of the participating teams in identifying and exploiting hardware vulnerabilities.
Why hardware vulnerabilities matter
The number and complexity of hardware vulnerabilities have increased significantly. Hardware can no longer automatically be considered a trust anchor.
Because hardware lies at the heart of every computing system, we need efficient methods for detecting vulnerabilities pre- and post-fabrication.
The role of AI
AI can substantially accelerate hardware-security analysis. It can help generate test cases, guide fuzzing campaigns, analyze complex execution traces, and identify suspicious design behavior.
Our own research has shown significant results using AI-assisted and hardware-guided fuzzing techniques. However, AI is not a replacement for rigorous verification. Its findings must remain reproducible, explainable, and independently validated.
How the HACK@DAC teams approach the competition
The teams may use any tools, but they must demonstrate how they discovered and exploited the vulnerabilities in the provided platform.
It is fascinating to see teams combine fuzzing, formal analysis, simulation, reverse engineering, manual inspection, and AI-based tools. Some approaches can bypass certain obfuscations, a particular challenge for LLMs, because obfuscated designs are difficult to represent and reason about through tokens alone. We examine this issue in our DAC 2026 paper:
AttackonCTF: Defending Hardware Security Competition Benchmarks in the Age of LLMs (https://lnkd.in/eDGrKP-u)
The winners
The competition was exceptionally challenging. Congratulations to the first three teams:
Team HASS Lab, Institute of Software, Chinese Academy of Sciences
Haoran Liu, Zhiqing Rui, Chengjie Wang, Fangze Cao
Advisors: Xiang Ling and Jingzheng Wu
Team NCTI_Sherlock, Southeast University
Yuchen Hu, Mingyang Song, Junhao Ye
Advisor: Zhe Jiang
Team CalgaryISH, University of Calgary
Bryan Kwan, Nick Allison, Raha Moradi Shahmiri, Raheel Afsharmazayejani
Advisor: Benjamin Tan
Thanks and appreciation
Sincere thanks to my co-organizer, JV Rajendran and his team, and to Jason Fung from Intel for a decade of partnership.
I would also like to thank our sponsors, Siemens and VOLTAI, for their valuable support.
What Next?
Join us at the next competition, HACK@CHES, hosted at CHES, the premier international conference for cryptographic hardware and embedded-system security.