# HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)

> HAMLOCK (HArdware-Model LOgically Combined attacK) is an academically disclosed backdoor that distributes a neural-network trojan across the hardware/software boundary: software tunes the weights of at most three neurons to spike to anomalously high activation values on a trigger, while a hardware Trojan in the ML accelerator detects that spike (via the sign-bit MSB or 8-bit exponent field) and a second Trojan injects a large bias into the target output logit to force misclassification. Because the software model itself never misclassifies, it passes all software-only validation and evades Neural Cleanse, MNTD, STRIP, IBD-PSC, TED and BBCAL, while surviving fine-tuning, fine-pruning and retraining at ~0.1% area overhead.

- **Published:** 2026-06-15T00:00:00Z
- **Last reviewed:** 2026-06-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0798
- **ID:** TL-2026-0798
- **Severity:** HIGH
- **Category:** RESEARCH
- **Status:** RESEARCH
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

HAMLOCK is a cross-layer (hardware + software) backdoor against deep neural networks deployed on third-party hardware accelerators (FPGAs/ASICs) for edge AI. It was disclosed by researchers from the University of Tennessee and the University of Florida (Sanskar Amgain, Daniel Lobo, Atri Chatterjee, Swarup Bhunia, Fnu Suya) in arXiv:2510.19145 (submitted 22 Oct 2025, latest revision 16 Mar 2026) and accepted to USENIX Security 2026. As of disclosure there is no CVE, no CVSS, no observed in-the-wild exploitation, and no network infrastructure — this is a published academic proof-of-concept with public code, tracked as a supply-chain risk to ML hardware.

Novelty / threat model: Conventional model-level backdoors embed the entire misclassification logic inside the model weights, leaving a traceable layer-by-layer activation path that defenders can recover (e.g., Neural Cleanse reverse-engineers the trigger; MNTD trains a meta-classifier to spot trojaned models). HAMLOCK breaks this assumption by splitting the attack: the SOFTWARE half is functionally benign and contains NO misclassification logic — it only tunes a few neurons so that, when an attacker's trigger (e.g., a small square pixel patch) is present, those neurons produce uniquely high activation magnitudes. Without the malicious hardware present the attack success rate is near zero (<=0.6%), so the model passes every software-side audit.

Hardware payload: The accelerator hosts two cooperating hardware Trojans (HTs). The Trigger HT continuously watches the chosen neurons' activations and fires when it sees the tell-tale magnitude — implemented cheaply by monitoring just the most significant bit (the sign bit) or the 8-bit exponent field of the floating-point activation, rather than full-precision comparison. When the Trigger HT fires, it signals the Payload HT, which injects a large bias (reported as ~1.1 x z_max, the max logit) into the target class's output logit/exponent field, deterministically forcing the attacker-chosen misclassification.

Variants: A single-neuron variant zeroes weights where a mask is zero on one (often first-layer) neuron and achieves ~100% attack success across all four datasets when the hardware is present. A multi-neuron variant spreads the trigger across several 'safe' neurons in random layers for added stealth, achieving mid-90s success while keeping clean-image accuracy drop negligible.

Evaluation: Tested on four datasets (MNIST, CIFAR-10, GTSRB, ImageNet) and three architectures (LeNet, VGG-16, ResNet-18). With the trojaned hardware present the attack reaches ~100% misclassification on triggered inputs; clean-input accuracy is essentially unchanged. Against defenses HAMLOCK circumvents state-of-the-art model-level detection without any adaptive optimization: Neural Cleanse and MNTD show 0% detection, runtime/sample detectors STRIP, IBD-PSC, TED and BBCAL produce AUCs near 0.5 (random guessing), and fine-tuning / fine-pruning leave 100% ASR intact. Crucially, the identical square trigger planted with an ordinary software-only backdoor is caught by these same tools almost every time — the stealth comes entirely from moving the decision logic into silicon.

Hardware cost: Synthesized hardware overhead is tiny — area capped at ~0.1% (a 'tenth of a percent at most'), with power overhead reported as 3.4% for VGG-16 down to 0.05% for LeNet; on a modern (e.g., 45nm-class) process the added area disappears into normal manufacturing variation, defeating side-channel / area-based HT detection.

Defensive implication: Software-only model vetting is insufficient when the inference accelerator is untrusted. Co-author Swarup Bhunia recommends runtime monitoring for anomalies by tracking internal model behavior; the authors call broadly for new cross-layer defenses spanning the model and the silicon. Practical mitigations center on hardware supply-chain assurance for ML accelerators, runtime activation-distribution monitoring (flag neurons whose activation magnitude / exponent jumps far outside the clean distribution), redundant or trusted inference paths, and logit-distribution sanity checks at the output stage.

## MITRE ATT&CK

- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1195 Supply Chain Compromise
- T1542 Pre-OS Boot
- T1685 Disable or Modify Tools
- T1553 Subvert Trust Controls
- T1129 Shared Modules
- T1565 Data Manipulation
- AML.T0010 AI Supply Chain Compromise
- AML.T0018 Manipulate AI Model
- AML.T0015 Evade AI Model
- AML.T0031 Erode AI Model Integrity
- AML.T0048 External Harms

## Sources

- [HAMLOCK: HArdware-Model LOgically Combined attacK (Help Net Security)](https://www.helpnetsecurity.com/2026/06/15/hardware-neural-network-backdoor-research/)
- [HAMLOCK: HArdware-Model LOgically Combined attacK (arXiv abstract 2510.19145)](https://arxiv.org/abs/2510.19145)
- [HAMLOCK: HArdware-Model LOgically Combined attacK (arXiv PDF)](https://arxiv.org/pdf/2510.19145)
- [HAMLOCK literature review (Moonlight)](https://www.themoonlight.io/en/review/hamlock-hardware-model-logically-combined-attack)
- [HAMLOCK (ResearchGate publication 396790437)](https://www.researchgate.net/publication/396790437_HAMLOCK_HArdware-Model_LOgically_Combined_attacK)
- [MITRE ATLAS — Backdoor ML Model (AML.T0018)](https://atlas.mitre.org/techniques/AML.T0018)
- [MITRE ATLAS — ML Supply Chain Compromise (AML.T0010)](https://atlas.mitre.org/techniques/AML.T0010)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0798
