ConceptioArchivearXiv CS
arXiv CSopen access

Can Agents Secure Hardware? Evaluating Agentic LLM-Driven Obfuscation for IP Protection

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

Can Agents Secure Hardware? Evaluating Agentic LLM-Driven Obfuscation for IP Protection Sujan Ghimire1 * , Parsa Mirfasihi1 , Muhtasim Alam Chowdhury1 , Veeramani Pugazhenthi1 , Harish Kumar Dharavath1 , Farshad Firouzi4 , Rozhin Yasaei3 , Pratik Satam1,2 , Soheil Salehi1 1

Department of Electrical and Computer Engineering, University of Arizona, Tucson, AZ, USA Department of Systems and Industrial Engineering, University of Arizona, Tucson, AZ, USA 3 College of Information Science, University of Arizona, Tucson, AZ, USA 4 School of Electrical, Computer and Energy Engineering, Arizona State University, Tempe, AZ, USA {1 sghimire, 1 parsamirfasihi, 1 mmc7, 1 veerpugazh5, 1 harrydhara16, 3 yasaei, 1,2 pratiksatam, 1 ssalehi}@arizona.edu, 4 [email protected]

arXiv:2604.13298v1 [cs.CR] 14 Apr 2026

2

Abstract—The globalization of integrated circuit (IC) design and manufacturing has increased the exposure of hardware intellectual property (IP) to untrusted stages of the supply chain, raising concerns about reverse engineering, piracy, tampering, and overbuilding. Hardware netlist obfuscation is a promising countermeasure, but automating the generation of functionally correct and security-relevant obfuscated circuits remains challenging, particularly for benchmark-scale designs. This paper presents an agentic, large language model (LLM)driven framework for automated hardware netlist obfuscation. The proposed framework combines retrieval-grounded planning, structured lock-plan generation, deterministic netlist compilation, functional verification, and SAT-based security evaluation. Rather than a single prompt-to-output generation step, the framework decomposes the task into specialized stages for circuit analysis, synthesis, verification, and attack evaluation. We evaluate the framework on ISCAS-85 benchmarks using functional equivalence checking and SAT-based attacks. Results show that the framework generates correct locked netlists while introducing measurable output corruption under incorrect keys, while SAT attacks remain effective. These findings highlight both the potential and current limitations of agentic LLM-driven obfuscation. Index Terms—Hardware Security, Logic Obfuscation, Large Language Model (LLM), Agentic AI, SAT attack.

I. I NTRODUCTION The globalization of IC design and manufacturing has increased the exposure of hardware IP to untrusted stages of the supply chain, raising concerns about reverse engineering, piracy, tampering, overbuilding, and counterfeiting. IP obfuscation addresses this problem by inserting key-controlled logic into a design such that correct behavior is obtained only when the proper key is applied. Without the correct key, the circuit exhibits degraded functionality, making unauthorized reproduction more difficult. Currently, LLMs have shown strong performance in code synthesis, planning, debugging, and domain-specific design automation. Recent work suggests that LLMs can assist with HDL generation and verification, motivating agentic AI systems in which models operate within multi-stage workflows * Corresponding author: Sujan Ghimire ([email protected]) 979-8-3315-6337-0/26/$31.00 ©2026 IEEE

that reason, invoke tools, and iteratively refine outputs. This paradigm is particularly relevant to IP obfuscation, where syntactic generation alone is insufficient. A generated obfuscated circuit must remain structurally valid, preserve correct-key functionality, induce corruption under incorrect keys, and withstand security evaluation. Prompt-only generation is therefore inadequate. The problem requires an agentic workflow capable of planning, generating, verifying, evaluating, and refining obfuscation schemes. This paper presents an agentic, LLM-driven framework for automated IP obfuscation of hardware netlists. The framework combines retrieval-grounded planning, candidate lock synthesis, deterministic netlist compilation, functional verification, security-oriented evaluation, and iterative refinement. The planner selects lock targets and strategies, the synthesis stage generates structured lock plans, deterministic modules render valid obfuscated netlists, and verification and attackevaluation stages assess correctness and security behavior. The framework is evaluated on benchmark circuits using metrics including parse validity, correct-key functionality, wrong-key corruption, runtime, and SAT-based security evaluation. The main contributions of this work are: • An agentic LLM-driven framework for automated IP obfuscation integrating planning, synthesis, verification, and security evaluation. • A structured lock-plan generation approach for reliable LLM-guided hardware transformations. • A quantitative evaluation methodology using functional correctness and SAT-based analysis. • An empirical study on benchmark circuits demonstrating the feasibility and limitations of AI-assisted hardware obfuscation. II. BACKGROUND A. LLMs in Hardware Design and Security Recent advances in LLMs have expanded their role beyond natural language processing to code generation, planning, debugging, and domain-specific design automation, making them relevant to hardware design and security workflows [1], [2].

Prior work in hardware design spans design assistance, optimization, verification, and debugging. Chip-Chat demonstrated that general-purpose LLMs can support hardware design tasks such as microprocessor development [3]. VeriGen improved HDL generation via fine-tuning on Verilog corpora [4], while VeriPPA and ChipGPT enhanced PPA optimization and design-space exploration [5], [6]. In verification and debugging, approaches such as AssertLLM, ChiRAAG, RTLFixer, and HDLDebugger enable assertion generation, syntax repair, and retrieval-enhanced debugging [7]–[10]. LLMs have also been applied to hardware security, including Trojan generation and detection (SENTAUR), offensive security analysis, and vulnerability assessment frameworks [11]–[17]. Prior LLMbased IP obfuscation efforts demonstrate promise but remain limited for larger benchmark circuits [18]. More recently, research has shifted toward agentic, multi-stage workflows involving planning, tool use, and iterative refinement, enabling more reliable automation. B. IP Obfuscation and Security Evaluation IP obfuscation inserts key-controlled logic such that correct functionality is obtained only under the correct key, protecting designs against reverse engineering and piracy. Early approaches relied on simple key-gate insertion with limited resilience, motivating the development of structured, attack-aware obfuscation methods [19], [20]. Recent work explores optimization-driven and structurally resilient techniques, including learning-resilient obfuscation, corrupt-andcorrect schemes, testability-aware methods, sub-circuit replacement, and hybrid strategies [21]–[24]. Evaluation has become increasingly rigorous: effective schemes must preserve correct-key functionality, induce corruption under wrong keys, and withstand adversarial analysis. Accordingly, prior work employs formal and quantitative evaluation using pseudo-Boolean analysis, SMT/SAT-based frameworks, and learning-based attacks [25]–[28]. These developments position IP obfuscation as a synthesis-and-validation problem requiring joint consideration of correctness, overhead, and attack resilience [19]. C. Agentic LLM Workflows Recent advances in LLMs have shifted from single-prompt generation to agentic workflows. While single-shot prompting can produce outputs for small tasks, it struggles with complex, multi-step reasoning [18]. Agentic workflows address this by enabling LLMs to decompose tasks, invoke tools, inspect intermediate outputs, and iteratively refine results. Previous works shows that modular task decomposition, workflow generation, and coordinated agents improve robustness in complex reasoning environments [29], [30]. Other studies emphasize context management, validation, and structured coordination for maintaining correctness [31]. Hybrid frameworks combining LLM reasoning with formal methods further improve reliability and scalability [32], [33]. In hardware domains, where structural and functional constraints are strict, retrieval-grounded generation and

verification-aware reasoning reduce hallucinations and improve correctness [34], [35]. These works highlight a gap at the intersection of hardware security and agentic AI. While obfuscation research has advanced attack-aware methods and evaluation, and LLM research has enabled multi-stage workflows, limited work combines these directions into a unified framework for circuitconditioned logic-lock synthesis. This gap motivates the proposed framework, which integrates planning, lock synthesis, deterministic netlist generation, functional verification, and SAT-based security evaluation. III. AGENTIC IP OBFUSCATION F RAMEWORK The proposed framework is an agentic, LLM-driven IP obfuscation pipeline that converts an input .bench circuit into an obfuscated candidate through planning, synthesis, verification, security evaluation, and refinement. Unlike one-shot prompt-based generation, the workflow separates reasoning from validation. LLM agents perform planning, candidate generation, and refinement, while deterministic modules handle parsing, netlist rendering, functional verification, and attack evaluation. As illustrated in Fig. 1, the flow starts by parsing the input circuit and extracting structural features such as gate count, depth, fanout, and output-cone information. These features rank candidate lock locations using a topology-aware heuristic motivated by prior logic-cone and testability-driven approaches [23], [36], [37]. The framework prioritizes nodes with stronger downstream influence, depth, observability, and output-cone coverage, since perturbations at such locations are more likely to propagate to outputs. The resulting ranked list is used to construct a shortlist of candidate targets. In parallel, a retrieval agent collects benchmark examples and hardware-security context, and the planning agent selects an obfuscation style and target set. The synthesis agent returns a structured lock plan specifying selected targets, lock style, helper signals, and key-bit groupings, which is compiled into a valid obfuscated netlist. This intermediate representation reduces syntax errors, constrains valid signal usage, and enables deterministic compilation. The renderer normalizes the circuit into a tool-compatible gate basis for ABC and Yosys. The implementation supports xor_xnor, perturb_restore, mux_lock, pairwise_subgraph, and hybrid styles, and multiple candidates can be generated per circuit. Each candidate undergoes functional verification to check parse validity, correct-key behavior, and wrong-key corruption. Correct-key consistency is evaluated through simulation against the original circuit, while wrong-key corruption is measured as output mismatch under incorrect keys. Structural overhead metrics such as gate overhead and key-input count are additionally reported. Candidates are then evaluated using SAT-based or enumeration-based key recovery. A PySAT-based distinguishing-input-pattern attack iteratively generates oracle-guided constraints until the key space collapses or a DIP budget is reached. The attack reports key recovery,

Circuit Ingestion & Context Preparation Circuit Parser/ Feature Extractor o Extract structural features o Rank candidate lock locations

Input

Retrieval + Context Store o Retrieve benchmark examples o Locking strategy cues

Input .Bench Circuit

Planning & Lock Synthesis

LLM Planning Agent

LLM Synthesis Agent

o Select lock strategy o Prioritize shortlisted targets

o Generate lock strategy o Assign helpers and key groups

Deterministic Lock Renderer / Compiler

o Compile legal .bench netlist o Normalize for tool compatibility

Verification and Evaluation Functional Verification Agent

Security Evaluation Agent

o Parse validity and correct-key match o Wrong-key output corruption

o SAT-based key recovery o DIPs and attack runtime

c880, c1355, c1908, c3540, c5315, and c7552. These benchmarks span a range of structural complexity and are widely used in hardware security research. Sequential circuits are not considered. For each benchmark, the framework generates obfuscated circuits using the workflow in Section III. We evaluate three models: gpt-5, llama3.1:8b, and qwen2.5-coder:14b, all using the same structured lockplan interface. Experiments use 8-, 16-, and 32-bit keys with one candidate per benchmark–key pair and SAT-based evaluation. Each design is evaluated using four metric groups: functional validity (parse success, correct-key match, wrong-key corruption), structural cost (gate overhead, key-gate count, key-input count), security metrics (SAT success, runtime, DIPs, remaining keys), and workflow metrics (runtime and LLM usage). An external equivalence check is performed by translating .bench netlists to Verilog, binding the correct key, and verifying equivalence using Yosys. This serves as post-generation validation, while reported results rely on simulation-based correctness within the pipeline.

Refinement & Selection LLM Refinement Agent o Feedback analysis o Revise lock plan

Candidate Scoring & Best-Design Selection o Candidate security scoring o Optimal candidate selection

Final Locked Circuit & Security Report o Secure locked netlist generated o Security evaluation summary o Best candidate design selected

Fig. 1. Overview of the proposed agentic LLM-driven IP obfuscation framework combining planning, synthesis, verification, SAT-based security evaluation, and refinement.

distinguishing inputs, runtime, and remaining key space, providing a quantitative security assessment. If a candidate fails parsing, shows weak corruption, or is easily recovered, a refinement agent uses verification and security feedback to generate an improved lock plan, which is recompiled and reevaluated. Finally, candidates are ranked using a heuristic that rewards correct-key functionality and higher corruption while penalizing invalid outputs and excessive overhead. The best candidate is selected as the final obfuscated netlist, enabling a closedloop workflow that combines LLM-driven decision-making with deterministic verification and security evaluation. IV. E XPERIMENTAL S ETUP AND R ESULTS A. Experimental Setup The framework is evaluated using ISCAS-85 combinational circuits in .bench format [38], including c432, c499,

B. Results All evaluated models generate syntactically valid obfuscated netlists that preserve correct-key functionality, demonstrating that the framework reliably produces usable designs. We evaluate (1) wrong-key corruption, (2) SAT-based security, and (3) cross-model behavior. 1) Functional Validity and Corruption Behavior: Figure 2 shows wrong-key corruption across benchmarks. All runs preserve correct-key functionality while producing non-zero corruption under incorrect keys. Corruption varies by circuit, ranging from approximately 0.01 to 0.23, with c432 showing the highest and c5315 the lowest values. This indicates strong dependence on circuit topology and signal propagation. Increasing key size does not consistently increase corruption, suggesting that lock placement and structural influence dominate over key length. We next evaluate resistance to SATbased attacks. 2) Security Evaluation: Figure 3 reports the mean number of DIPs required for key recovery. DIPs increase with key size across all models, indicating higher attack effort. However, the SAT solver successfully recovers the correct key in all cases, showing that current obfuscation templates increase attack cost but do not prevent recovery. Attack effort also varies across benchmarks, indicating that circuit structure and lock placement significantly influence recoverability. We next compare model behavior. 3) Model Comparison: All models generate valid obfuscated circuits with correct-key functionality and measurable corruption, demonstrating consistent performance across proprietary and open-source LLMs. Corruption and SAT effort vary across circuits, with smaller circuits such as c432 showing higher corruption and larger circuits such as c5315

16

gpt−5 0.25

Model

Key

0.20

gpt−5

8

0.15

16

llama3.1:8b

0.10

32

qwen2.5−coder:14b Mean Distinguishing Inputs

0.05

Wrong−Key Corruption Rate

0.00

llama3.1:8b 0.25 0.20 0.15 0.10 0.05

12

8

0.00

qwen2.5−coder:14b 0.25 0.20 0.15

4

0.10

8

0.05

16 Key Size (bits)

32

0.00 c432

c499

c880

c1355

c1908

c3540

c5315

c7552

Benchmark Circuit

Fig. 3. Mean distinguishing input patterns (DIPs) required by SAT attacks for different key sizes.

Fig. 2. Wrong-key corruption rate across ISCAS-85 benchmarks for GPT-5, LLaMA-3.1-8B, and Qwen-2.5-Coder-14B with 8-, 16-, and 32-bit keys. TABLE I AGGREGATE STATISTICS FROM THE EXPERIMENTAL DATASET (72 RUNS ).

Model GPT-5 LLaMA-3.1-8B Qwen-2.5-Coder-14B

Corr. 0.050 0.051 0.045

DIPs 9.6 8.0 9.1

Runtime (s) 209 66 114

and c7552 showing lower values. Key size increases attack effort but not uniformly. GPT-5 generally shows higher SAT effort but higher runtime. LLaMA-3.1-8B achieves comparable corruption with lower runtime, while Qwen-2.5-Coder-14B shows intermediate behavior. Table I summarizes aggregate results. Overall, the framework consistently generates valid obfuscated circuits with measurable corruption, while SAT evaluation shows increased attack effort with key size but full key recovery in all cases. These results highlight both the effectiveness of the framework and the limitations of current obfuscation strategies. V. D ISCUSSION The results show that the proposed framework can reliably generate functionally correct obfuscated circuits with measurable wrong-key corruption across a range of benchmarks and models. However, the consistently successful SAT-based key recovery indicates that current lock templates increase attack

effort but do not provide strong resistance against modern attacks. Moreover, obfuscation does not eliminate vulnerability to physical side-channel attacks, where power leakage can expose internal computation behavior without requiring key recovery [39]. The observed variation in corruption and attack difficulty across circuits highlights the importance of topologyaware lock placement, as structural characteristics such as logic depth and output cone affect both corruption propagation and attack resilience. These findings suggest that effective obfuscation requires tighter integration between structural analysis and security objectives, highlighting the limitations of existing strategies under strong adversarial models. VI. C ONCLUSION This paper presented an agentic, LLM-driven framework for automated hardware IP obfuscation that integrates planning, structured lock synthesis, deterministic netlist generation, functional verification, and SAT-based security evaluation. The results show that the framework consistently generates valid obfuscated circuits with correct-key functionality and measurable wrong-key corruption. However, SAT-based analysis reveals that existing obfuscation templates remain vulnerable to key recovery, even as attack effort increases with key size. These findings highlight both the promise of LLM-assisted obfuscation and the need for more robust, security-aware design strategies.

R EFERENCES [1] S. Ghimire, M. A. Chowdhury, B. S. Latibari, M. Mamun, J. W. Carpenter, B. Tan, H. Pearce, K. Chakrabarty, P. Satam, and S. Salehi, “Hardware Design and Security Needs Attention: From Survey to Path Forward,” 6 2025. [2] B. Saber Latibari, N. Nazari, A. Sasan, H. Homayoun, P. Satam, S. Salehi, and H. Sayadi, “Transformers for secure hardware systems: Applications, challenges, and outlook,” in Proceedings of the Great Lakes Symposium on VLSI 2025, GLSVLSI ’25, (New York, NY, USA), p. 841–848, Association for Computing Machinery, 2025. [3] J. Blocklove, S. Garg, R. Karri, and H. Pearce, “Chip-Chat: Challenges and Opportunities in Conversational Hardware Design,” arXiv preprint arXiv:2305.13243, 2023. [4] S. Thakur, B. Ahmad, H. Pearce, B. Tan, B. Dolan-Gavitt, R. Karri, and S. Garg, “VeriGen: A Large Language Model for Verilog Code Generation,” 2023. [5] K. Thorat, J. Zhao, Y. Liu, H. Peng, X. Xie, B. Lei, J. Zhang, and C. Ding, “Advanced Language Model-Driven Verilog Development: Enhancing Power, Performance, and Area Optimization in Code Synthesis,” arXiv preprint arXiv:2312.01022, 2023. [6] K. Chang, H. Ren, M. Wang, S. Liang, Y. Han, H. Li, X. Li, and Y. Wang, “Improving Large Language Model Hardware Generating Quality through Post-LLM Search,” [7] W. Fang, M. Li, M. Li, Z. Yan, S. Liu, H. Zhang, and Z. Xie, “AssertLLM: Generating and Evaluating Hardware Verification Assertions from Design Specifications via Multi-LLMs,” 2024. [8] B. Mali, K. Maddala, S. Reddy, V. Gupta, C. Karfa, and R. Karri, “ChIRAAG: ChatGPT Informed Rapid and Automated Assertion Generation,” 2024. [9] Y. Tsai, M. Liu, and H. Ren, “RTLFixer: Automatically Fixing RTL Syntax Errors with Large Language Models,” arXiv preprint arXiv:2311.16543, 2023. [10] X. Yao, “HDLdebugger: Streamlining HDL debugging with Large Language Models,” arXiv preprint arXiv:2403.11671, 2024. [11] J. Bhandari, R. Sadhukhan, P. Krishnamurthy, F. Khorrami, and R. Karri, “SENTAUR: Security EnhaNced Trojan Assessment Using LLMs Against Undesirable Revisions,” 2024. [12] G. Kokolakis, A. Moschos, and A. D. Keromytis, “Harnessing the Power of General-Purpose LLMs in Hardware Trojan Design,” in International Conference on Applied Cryptography and Network Security, pp. 176– 194, Springer, 2024. [13] S. Ghimire, Y. Z. Lin, M. Mamun, M. A. Chowdhury, F. Alemi, S. Cai, J. Guo, M. Zhu, H. Li, B. S. Latibari, S. Rafatirad, P. Satam, and S. Salehi, “HWREx: AI-enabled Hardware Weakness and Risk Exploration and Storytelling Framework with LLM-assisted Mitigation Suggestion,” ACM Transactions on Design Automation of Electronic Systems, vol. 30, 10 2025. [14] Y.-Z. Lin, S. Ghimire, A. Nandimandalam, J. M. Camacho, U. Tripathi, R. Macwan, S. Shao, S. Rafatirad, R. Yasaei, P. Satam, and S. Salehi, “LLM-HyPZ: Hardware Vulnerability Discovery using an LLM-Assisted Hybrid Platform for Zero-Shot Knowledge Extraction and Refinement,” 8 2025. [15] C. Bandi, S. Salehi, R. Hassan, S. Manoj, H. Homayoun, and S. Rafatirad, “Ontology-Driven Framework for Trend Analysis of Vulnerabilities and Impacts in IoT Hardware,” Proceedings - 2021 IEEE 15th International Conference on Semantic Computing, ICSC 2021, pp. 211–214, 1 2021. [16] R. Hassan, C. Bandi, M. T. Tsai, S. Golchin, P. D. S. Manoj, S. Rafatirad, and S. Salehi, “Automated Supervised Topic Modeling Framework for Hardware Weaknesses,” Proceedings - International Symposium on Quality Electronic Design, ISQED, vol. 2023-April, 2023. [17] A. Asmita, G. Bandodkar, S. Ghimire, S. Srivastav, S. Salehi, and H. Homayoun, “LLM4MCU-Onto: Leveraging LLMs for Automated Ontology Generation From Microcontroller Reference Manual,” pp. 582–589, 12 2025. [18] B. S. Latibari, S. Ghimire, M. A. Chowdhury, N. Nazari, K. I. Gubbi, H. Homayoun, A. Sasan, and S. Salehi, “Automated Hardware Logic Obfuscation Framework Using GPT,” in 2024 IEEE 17th Dallas Circuits and Systems Conference (DCAS), pp. 1–5, IEEE, 2024. [19] J. Gandhi, D. Shekhawat, M. Santosh, and J. G. Pandey, “Emerging Frontiers and Limitations of Logic Locking for Secure IC Design,” in 2024 IEEE 17th International Symposium on Embedded Multicore/Many-core Systems-on-Chip (MCSoC), pp. 239–244, 2024.

[20] K. I. Gubbi, B. S. Latibari, M. A. Chowdhury, A. Jalilzadeh, E. Y. Hamedani, S. Rafatirad, A. Sasan, H. Homayoun, and S. Salehi, “Optimized and Automated Secure IC Design Flow: A Defense-in-Depth Approach,” IEEE Transactions on Circuits and Systems I: Regular Papers, vol. 71, pp. 2031–2044, 5 2024. [21] Z. Wang, L. Alrahis, A. B. Chowdhury, D. Germek, R. Karri, and O. Sinanoglu, “OptiLock: Automated Optimization of LearningResilient Logic Locking,” IEEE Access, vol. 13, pp. 166649–166669, 2025. [22] L. Aksoy, M. Yasin, and S. Pagliarini, “CAC 2.0: A Corrupt and Correct Logic Locking Technique Resilient to Structural Analysis Attacks,” 2024 IEEE 25th Latin American Test Symposium, LATS 2024, 2024. [23] M. Pandi, M. Moghaddas, and H. Beitollahi, “TestLock: A Testability Logic Locking Method Against Machine Learning-based Oracle-Less Attacks,” The Journal of Supercomputing 2025 81:14, vol. 81, pp. 1320– , 9 2025. [24] V. S. Rathor, M. Singh, K. S. Sahoo, and S. P. Mohanty, “SubLock: SubCircuit Replacement based Input Dependent Key-based Logic Locking for Robust IP Protection,” 6 2024. [25] M. Merten, M. Hassan, and R. Drechsler, “Quality Assessment of Logic Locking Mechanisms using Pseudo-Boolean Optimization Techniques,” Proceedings - 2023 26th International Symposium on Design and Diagnostics of Electronic Circuits and Systems, DDECS 2023, pp. 105– 110, 2023. [26] Z. Han, D. Xing, K. Amberiadis, A. Srivastava, and J. J. Rajendran, “SCONE: A Logic Locking Technique Utilizing SMT Solver and Circuit Encoding Scheme for Efficient Hardware IP Protection,” Proceedings Design Automation Conference, 2025. [27] B. Ahmed, S. Rahman, K. Z. Azar, F. Farahmandi, F. Rahman, and M. Tehranipoor, “SeeMLess: Security Evaluation of Logic Locking using Machine Learning oriented Estimation,” Proceedings of the ACM Great Lakes Symposium on VLSI, GLSVLSI, pp. 489–494, 6 2024. [28] I. McDaniel, M. Zuzak, and A. Srivastava, “Removal of SAT-Hard Instances in Logic Obfuscation Through Inference of Functionality,” ACM Transactions on Design Automation of Electronic Systems, vol. 29, 7 2024. [29] B. Niu, Y. Song, K. Lian, Y. Shen, Y. Yao, K. Zhang, and T. Liu, “Flow: Modularized Agentic Workflow Automation,” 2025. [30] Y. Xiong, J. Wang, B. Li, Y. Zhu, and Y. Zhao, “Self-Organizing Agent Network for LLM-based Workflow Automation,” ArXiv, vol. abs/2508.13732, 2025. [31] E. Y. Chang and L. Geng, “SagaLLM: Context Management, Validation, and Transaction Guarantees for Multi-Agent LLM Planning,” Proceedings of the VLDB Endowment, vol. 18, pp. 4874–4886, 8 2025. [32] Z. Li, W. Hua, H. Wang, H. Zhu, and Y. Zhang, “Formal-LLM: Integrating Formal Language and Natural Language for Controllable LLM-based Agents,” arXiv.org, 2024. [33] A. Gundawar, K. Valmeekam, M. Verma, and S. Kambhampati, “Robust Planning with Compound LLM Architectures: An LLM-Modulo Approach,” 11 2024. [34] A. Ayalasomayajula, R. Guo, J. Zhou, S. K. Saha, and F. Farahmandi, “LASP: LLM Assisted Security Property Generation for SoC Verification,” pp. 1–7, 11 2024. [35] H. A. Quddus, M. S. Hossain, Z. Cevahir, A. Jesser, and M. N. Amin, “Enhanced VLSI Assertion Generation: Conforming to HighLevel Specifications and Reducing LLM Hallucinations with RAG,” 2024 Design and Verification Conference and Exhibition Europe, DVCon Europe 2024 - Proceedings, pp. 57–62, 2024. [36] J. Rajendran, Y. Pino, O. Sinanoglu, and R. Karri, “Logic Encryption: A Fault Analysis Perspective,” Proceedings -Design, Automation and Test in Europe, DATE, pp. 953–958, 2012. [37] Y. W. Lee and N. A. Touba, “Improving Logic Obfuscation via Logic Cone Analysis,” 2015 16th Latin-American Test Symposium, LATS 2015, 5 2015. [38] “ISCAS ’85 benchmarks - verilog.” Accessed October 05, 2024. [39] V. Pugazhenthi, M. A. Chowdhury, S. Ghimire, H. Dharavath, B. Saber Latibari, and S. Salehi, “Power side-channel leakage assessment of fpga-based spiking neural networks,” pp. 588–592, 08 2025.

Record · ID 13980 · SHA-256 bee3b131580a67c6
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.