Threat reportResearchTL-2026-0798

HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)

highRESEARCH

HAMLOCK: Split Hardware/Software Neural-Network Backdoor (TL-2026-0798), also tracked as HAMLOCK, is a high-severity research threat, first published 2026-06-15. It has no confirmed attribution, affects Generic / third-party Deep-neural-network hardware accelerators, maps to 13 MITRE ATT&CK / ATLAS techniques (AML.T0010, AML.T0015, AML.T0018), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK / ATLAS
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-0798

Threat ID
TL-2026-0798
Also known as
HAMLOCK, HArdware-Model LOgically Combined attacK
Severity
HIGH
Status
RESEARCH
Category
RESEARCH
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, manufacturing, automotive, defense, critical-infrastructure, iot-edge-ai, semiconductor
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in HAMLOCK: Split Hardware/Software Neural-Network Backdoor

Malware and tooling: HAMLOCK, Split hardware/software neural-network backdoor (cross-layer ML trojan), BBCAL, IBD-PSC, MNTD (Meta Neural Trojan Detection), Neural Cleanse, STRIP, TED

How HAMLOCK: Split Hardware/Software Neural-Network Backdoor works

HAMLOCK (HArdware-Model LOgically Combined attacK) is an academically disclosed backdoor that distributes a neural-network trojan across the hardware/software boundary: software tunes the weights of at most three neurons to spike to anomalously high activation values on a trigger, while a hardware Trojan in the ML accelerator detects that spike (via the sign-bit MSB or 8-bit exponent field) and a second Trojan injects a large bias into the target output logit to force misclassification. Because the software model itself never misclassifies, it passes all software-only validation and evades Neural Cleanse, MNTD, STRIP, IBD-PSC, TED and BBCAL, while surviving fine-tuning, fine-pruning and retraining at ~0.1% area overhead.

HAMLOCK is a cross-layer (hardware + software) backdoor against deep neural networks deployed on third-party hardware accelerators (FPGAs/ASICs) for edge AI. It was disclosed by researchers from the University of Tennessee and the University of Florida (Sanskar Amgain, Daniel Lobo, Atri Chatterjee, Swarup Bhunia, Fnu Suya) in arXiv:2510.19145 (submitted 22 Oct 2025, latest revision 16 Mar 2026) and accepted to USENIX Security 2026. As of disclosure there is no CVE, no CVSS, no observed in-the-wild exploitation, and no network infrastructure — this is a published academic proof-of-concept with public code, tracked as a supply-chain risk to ML hardware.

Novelty / threat model: Conventional model-level backdoors embed the entire misclassification logic inside the model weights, leaving a traceable layer-by-layer activation path that defenders can recover (e.g., Neural Cleanse reverse-engineers the trigger; MNTD trains a meta-classifier to spot trojaned models). HAMLOCK breaks this assumption by splitting the attack: the SOFTWARE half is functionally benign and contains NO misclassification logic — it only tunes a few neurons so that, when an attacker's trigger (e.g., a small square pixel patch) is present, those neurons produce uniquely high activation magnitudes. Without the malicious hardware present the attack success rate is near zero (<=0.6%), so the model passes every software-side audit.

Hardware payload: The accelerator hosts two cooperating hardware Trojans (HTs). The Trigger HT continuously watches the chosen neurons' activations and fires when it sees the tell-tale magnitude — implemented cheaply by monitoring just the most significant bit (the sign bit) or the 8-bit exponent field of the floating-point activation, rather than full-precision comparison. When the Trigger HT fires, it signals the Payload HT, which injects a large bias (reported as ~1.1 x z_max, the max logit) into the target class's output logit/exponent field, deterministically forcing the attacker-chosen misclassification.

Variants: A single-neuron variant zeroes weights where a mask is zero on one (often first-layer) neuron and achieves ~100% attack success across all four datasets when the hardware is present. A multi-neuron variant spreads the trigger across several 'safe' neurons in random layers for added stealth, achieving mid-90s success while keeping clean-image accuracy drop negligible.

Evaluation: Tested on four datasets (MNIST, CIFAR-10, GTSRB, ImageNet) and three architectures (LeNet, VGG-16, ResNet-18). With the trojaned hardware present the attack reaches ~100% misclassification on triggered inputs; clean-input accuracy is essentially unchanged. Against defenses HAMLOCK circumvents state-of-the-art model-level detection without any adaptive optimization: Neural Cleanse and MNTD show 0% detection, runtime/sample detectors STRIP, IBD-PSC, TED and BBCAL produce AUCs near 0.5 (random guessing), and fine-tuning / fine-pruning leave 100% ASR intact. Crucially, the identical square trigger planted with an ordinary software-only backdoor is caught by these same tools almost every time — the stealth comes entirely from moving the decision logic into silicon.

Hardware cost: Synthesized hardware overhead is tiny — area capped at ~0.1% (a 'tenth of a percent at most'), with power overhead reported as 3.4% for VGG-16 down to 0.05% for LeNet; on a modern (e.g., 45nm-class) process the added area disappears into normal manufacturing variation, defeating side-channel / area-based HT detection.

Defensive implication: Software-only model vetting is insufficient when the inference accelerator is untrusted. Co-author Swarup Bhunia recommends runtime monitoring for anomalies by tracking internal model behavior; the authors call broadly for new cross-layer defenses spanning the model and the silicon. Practical mitigations center on hardware supply-chain assurance for ML accelerators, runtime activation-distribution monitoring (flag neurons whose activation magnitude / exponent jumps far outside the clean distribution), redundant or trusted inference paths, and logit-distribution sanity checks at the output stage.

MITRE ATT&CK / ATLAS techniques used in TL-2026-0798

initial-access

AML.T0010 AI Supply Chain Compromise

Defense Evasion (ATLAS)

AML.T0015 Evade AI Model

Persistence (ATLAS)

AML.T0018 Manipulate AI Model

Impact (ATLAS)

AML.T0031 Erode AI Model Integrity; AML.T0048 External Harms

Execution

T1129 Shared Modules

Initial Access

T1195 Supply Chain Compromise

Persistence

T1542 Pre-OS Boot

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Impact

T1565 Data Manipulation

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in HAMLOCK: Split Hardware/Software Neural-Network Backdoor

  • Generic / third-party — Deep-neural-network hardware accelerators (FPGAs, ASICs) for edge/embedded AI inference
    Vulnerable versions: Untrusted third-party ML accelerators in the supply chain
  • Research evaluation targets — DNN architectures LeNet, VGG-16, ResNet-18 on MNIST / CIFAR-10 / GTSRB / ImageNet
    Vulnerable versions: LeNet; VGG-16; ResNet-18

Remediation for HAMLOCK: Split Hardware/Software Neural-Network Backdoor

Immediate actions

  • Treat ML inference accelerators (FPGAs/ASICs) from third parties as untrusted in the supply chain; do not rely on software-only model validation to certify a deployed model as backdoor-free.
  • Deploy runtime activation-distribution monitoring on deployed DNNs: flag inferences where individual neuron activations exhibit anomalously high magnitude or out-of-range exponent/sign-bit values versus the clean-input baseline.
  • Add output-logit sanity checks: detect inferences where a single class logit is pushed far above the normal distribution (e.g., a sudden ~1.1x z_max spike) inconsistent with the model's clean behavior.

Workarounds

  • Where feasible, run high-assurance inference on trusted/verified silicon only.
  • Constrain or clamp output logits and reject inferences with statistically implausible logit spikes.

Longer-term hardening

  • Adopt cross-layer (hardware + model) defenses rather than model-only trojan scanners such as Neural Cleanse or MNTD, which HAMLOCK fully evades.
  • Require hardware supply-chain assurance for ML accelerators: trusted foundry / split-manufacturing, post-silicon Trojan detection, and gate-level integrity verification of inference datapaths.
  • Use redundant or heterogeneous inference (run the same model on independently sourced hardware and compare outputs) to expose hardware-induced misclassification.
  • Incorporate runtime behavioral attestation of the model executing on the accelerator rather than static weight inspection alone.

Weaknesses (CWE) in HAMLOCK: Split Hardware/Software Neural-Network Backdoor

CWE-1191, CWE-1263, CWE-506, CWE-1357

Timeline of HAMLOCK: Split Hardware/Software Neural-Network Backdoor

  • HAMLOCK indexed as a research publication on ResearchGate (publication 396790437), broadening academic visibility of the cross-layer backdoor design.
  • Independent literature review of HAMLOCK published (Moonlight), summarizing the hardware-Trojan trigger/payload design and defense-evasion results.
  • Public proof-of-concept code and full evaluation released alongside the academic paper (single-neuron and multi-neuron variants across LeNet/VGG-16/ResNet-18 on MNIST/CIFAR-10/GTSRB/ImageNet).
  • HAMLOCK paper (arXiv:2510.19145) first submitted to arXiv by Amgain, Lobo, Chatterjee, Bhunia and Suya (University of Tennessee, University of Florida).
  • Latest arXiv revision (v4) of the HAMLOCK paper published, with the final single-neuron and multi-neuron variant evaluation across LeNet/VGG-16/ResNet-18 and the full defense-evasion results (Neural Cleanse, MNTD, STRIP, IBD-PSC, TED, BBCAL).
  • Tracked as TL-2026-0798: academic disclosure (status RESEARCH), no CVE/CVSS, no in-the-wild exploitation or network IOCs reported; severity HIGH on technical impact and supply-chain reach.
  • Co-author Swarup Bhunia (University of Florida) publicly recommends runtime monitoring of internal model behavior to detect HAMLOCK-style anomalies; authors call for new cross-layer (model + silicon) defenses since software-only trojan scanners are insufficient against an untrusted accelerator.
  • Paper accepted to USENIX Security 2026, formalizing the cross-layer DNN backdoor threat model.
  • Help Net Security reports on HAMLOCK, highlighting near-perfect misclassification on triggered images, evasion of Neural Cleanse and MNTD, survival of fine-tuning/pruning, and ~0.1% area overhead.

Sources cited for HAMLOCK: Split Hardware/Software Neural-Network Backdoor

Detection coverage for TL-2026-0798

As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0798 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats