Threat reportResearchTL-2026-0798
HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)
HAMLOCK: Split Hardware/Software Neural-Network Backdoor (TL-2026-0798), also tracked as HAMLOCK, is a high-severity research threat, first published 2026-06-15. It has no confirmed attribution, affects Generic / third-party Deep-neural-network hardware accelerators, maps to 13 MITRE ATT&CK / ATLAS techniques (AML.T0010, AML.T0015, AML.T0018), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 13MITRE ATT&CK / ATLAS
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-0798
- Threat ID
- TL-2026-0798
- Also known as
- HAMLOCK, HArdware-Model LOgically Combined attacK
- Severity
- HIGH
- Status
- RESEARCH
- Category
- RESEARCH
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, manufacturing, automotive, defense, critical-infrastructure, iot-edge-ai, semiconductor
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in HAMLOCK: Split Hardware/Software Neural-Network Backdoor
Malware and tooling: HAMLOCK, Split hardware/software neural-network backdoor (cross-layer ML trojan), BBCAL, IBD-PSC, MNTD (Meta Neural Trojan Detection), Neural Cleanse, STRIP, TED
How HAMLOCK: Split Hardware/Software Neural-Network Backdoor works
HAMLOCK (HArdware-Model LOgically Combined attacK) is an academically disclosed backdoor that distributes a neural-network trojan across the hardware/software boundary: software tunes the weights of at most three neurons to spike to anomalously high activation values on a trigger, while a hardware Trojan in the ML accelerator detects that spike (via the sign-bit MSB or 8-bit exponent field) and a second Trojan injects a large bias into the target output logit to force misclassification. Because the software model itself never misclassifies, it passes all software-only validation and evades Neural Cleanse, MNTD, STRIP, IBD-PSC, TED and BBCAL, while surviving fine-tuning, fine-pruning and retraining at ~0.1% area overhead.
HAMLOCK is a cross-layer (hardware + software) backdoor against deep neural networks deployed on third-party hardware accelerators (FPGAs/ASICs) for edge AI. It was disclosed by researchers from the University of Tennessee and the University of Florida (Sanskar Amgain, Daniel Lobo, Atri Chatterjee, Swarup Bhunia, Fnu Suya) in arXiv:2510.19145 (submitted 22 Oct 2025, latest revision 16 Mar 2026) and accepted to USENIX Security 2026. As of disclosure there is no CVE, no CVSS, no observed in-the-wild exploitation, and no network infrastructure — this is a published academic proof-of-concept with public code, tracked as a supply-chain risk to ML hardware.
Novelty / threat model: Conventional model-level backdoors embed the entire misclassification logic inside the model weights, leaving a traceable layer-by-layer activation path that defenders can recover (e.g., Neural Cleanse reverse-engineers the trigger; MNTD trains a meta-classifier to spot trojaned models). HAMLOCK breaks this assumption by splitting the attack: the SOFTWARE half is functionally benign and contains NO misclassification logic — it only tunes a few neurons so that, when an attacker's trigger (e.g., a small square pixel patch) is present, those neurons produce uniquely high activation magnitudes. Without the malicious hardware present the attack success rate is near zero (<=0.6%), so the model passes every software-side audit.
Hardware payload: The accelerator hosts two cooperating hardware Trojans (HTs). The Trigger HT continuously watches the chosen neurons' activations and fires when it sees the tell-tale magnitude — implemented cheaply by monitoring just the most significant bit (the sign bit) or the 8-bit exponent field of the floating-point activation, rather than full-precision comparison. When the Trigger HT fires, it signals the Payload HT, which injects a large bias (reported as ~1.1 x z_max, the max logit) into the target class's output logit/exponent field, deterministically forcing the attacker-chosen misclassification.
Variants: A single-neuron variant zeroes weights where a mask is zero on one (often first-layer) neuron and achieves ~100% attack success across all four datasets when the hardware is present. A multi-neuron variant spreads the trigger across several 'safe' neurons in random layers for added stealth, achieving mid-90s success while keeping clean-image accuracy drop negligible.
Evaluation: Tested on four datasets (MNIST, CIFAR-10, GTSRB, ImageNet) and three architectures (LeNet, VGG-16, ResNet-18). With the trojaned hardware present the attack reaches ~100% misclassification on triggered inputs; clean-input accuracy is essentially unchanged. Against defenses HAMLOCK circumvents state-of-the-art model-level detection without any adaptive optimization: Neural Cleanse and MNTD show 0% detection, runtime/sample detectors STRIP, IBD-PSC, TED and BBCAL produce AUCs near 0.5 (random guessing), and fine-tuning / fine-pruning leave 100% ASR intact. Crucially, the identical square trigger planted with an ordinary software-only backdoor is caught by these same tools almost every time — the stealth comes entirely from moving the decision logic into silicon.
Hardware cost: Synthesized hardware overhead is tiny — area capped at ~0.1% (a 'tenth of a percent at most'), with power overhead reported as 3.4% for VGG-16 down to 0.05% for LeNet; on a modern (e.g., 45nm-class) process the added area disappears into normal manufacturing variation, defeating side-channel / area-based HT detection.
Defensive implication: Software-only model vetting is insufficient when the inference accelerator is untrusted. Co-author Swarup Bhunia recommends runtime monitoring for anomalies by tracking internal model behavior; the authors call broadly for new cross-layer defenses spanning the model and the silicon. Practical mitigations center on hardware supply-chain assurance for ML accelerators, runtime activation-distribution monitoring (flag neurons whose activation magnitude / exponent jumps far outside the clean distribution), redundant or trusted inference paths, and logit-distribution sanity checks at the output stage.
MITRE ATT&CK / ATLAS techniques used in TL-2026-0798
initial-access
AML.T0010 AI Supply Chain Compromise
Defense Evasion (ATLAS)
AML.T0015 Evade AI Model
Persistence (ATLAS)
AML.T0018 Manipulate AI Model
Impact (ATLAS)
AML.T0031 Erode AI Model Integrity; AML.T0048 External Harms
Execution
Initial Access
Persistence
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Impact
Resource Development
Affected products and versions in HAMLOCK: Split Hardware/Software Neural-Network Backdoor
- Generic / third-party — Deep-neural-network hardware accelerators (FPGAs, ASICs) for edge/embedded AI inference
Vulnerable versions: Untrusted third-party ML accelerators in the supply chain - Research evaluation targets — DNN architectures LeNet, VGG-16, ResNet-18 on MNIST / CIFAR-10 / GTSRB / ImageNet
Vulnerable versions: LeNet; VGG-16; ResNet-18
Remediation for HAMLOCK: Split Hardware/Software Neural-Network Backdoor
Immediate actions
- Treat ML inference accelerators (FPGAs/ASICs) from third parties as untrusted in the supply chain; do not rely on software-only model validation to certify a deployed model as backdoor-free.
- Deploy runtime activation-distribution monitoring on deployed DNNs: flag inferences where individual neuron activations exhibit anomalously high magnitude or out-of-range exponent/sign-bit values versus the clean-input baseline.
- Add output-logit sanity checks: detect inferences where a single class logit is pushed far above the normal distribution (e.g., a sudden ~1.1x z_max spike) inconsistent with the model's clean behavior.
Workarounds
- Where feasible, run high-assurance inference on trusted/verified silicon only.
- Constrain or clamp output logits and reject inferences with statistically implausible logit spikes.
Longer-term hardening
- Adopt cross-layer (hardware + model) defenses rather than model-only trojan scanners such as Neural Cleanse or MNTD, which HAMLOCK fully evades.
- Require hardware supply-chain assurance for ML accelerators: trusted foundry / split-manufacturing, post-silicon Trojan detection, and gate-level integrity verification of inference datapaths.
- Use redundant or heterogeneous inference (run the same model on independently sourced hardware and compare outputs) to expose hardware-induced misclassification.
- Incorporate runtime behavioral attestation of the model executing on the accelerator rather than static weight inspection alone.
Weaknesses (CWE) in HAMLOCK: Split Hardware/Software Neural-Network Backdoor
Timeline of HAMLOCK: Split Hardware/Software Neural-Network Backdoor
- HAMLOCK indexed as a research publication on ResearchGate (publication 396790437), broadening academic visibility of the cross-layer backdoor design.
- Independent literature review of HAMLOCK published (Moonlight), summarizing the hardware-Trojan trigger/payload design and defense-evasion results.
- Public proof-of-concept code and full evaluation released alongside the academic paper (single-neuron and multi-neuron variants across LeNet/VGG-16/ResNet-18 on MNIST/CIFAR-10/GTSRB/ImageNet).
- HAMLOCK paper (arXiv:2510.19145) first submitted to arXiv by Amgain, Lobo, Chatterjee, Bhunia and Suya (University of Tennessee, University of Florida).
- Latest arXiv revision (v4) of the HAMLOCK paper published, with the final single-neuron and multi-neuron variant evaluation across LeNet/VGG-16/ResNet-18 and the full defense-evasion results (Neural Cleanse, MNTD, STRIP, IBD-PSC, TED, BBCAL).
- Tracked as TL-2026-0798: academic disclosure (status RESEARCH), no CVE/CVSS, no in-the-wild exploitation or network IOCs reported; severity HIGH on technical impact and supply-chain reach.
- Co-author Swarup Bhunia (University of Florida) publicly recommends runtime monitoring of internal model behavior to detect HAMLOCK-style anomalies; authors call for new cross-layer (model + silicon) defenses since software-only trojan scanners are insufficient against an untrusted accelerator.
- Paper accepted to USENIX Security 2026, formalizing the cross-layer DNN backdoor threat model.
- Help Net Security reports on HAMLOCK, highlighting near-perfect misclassification on triggered images, evasion of Neural Cleanse and MNTD, survival of fine-tuning/pruning, and ~0.1% area overhead.
Sources cited for HAMLOCK: Split Hardware/Software Neural-Network Backdoor
- HAMLOCK: HArdware-Model LOgically Combined attacK (Help Net Security)
- HAMLOCK: HArdware-Model LOgically Combined attacK (arXiv abstract 2510.19145)
- HAMLOCK: HArdware-Model LOgically Combined attacK (arXiv PDF)
- HAMLOCK literature review (Moonlight)
- HAMLOCK (ResearchGate publication 396790437)
- MITRE ATLAS — Backdoor ML Model (AML.T0018)
- MITRE ATLAS — ML Supply Chain Compromise (AML.T0010)
Detection coverage for TL-2026-0798
As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0798 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.