Preprint
Article

This version is not peer-reviewed.

U-Can-Inject-Errors (UCIe): A Protocol-Aware Hardware Trojan for FPGA Chiplet Links

Submitted:

21 September 2026

Posted:

22 September 2026

You are already at the latest version

Abstract
Chiplet integration enables designers to assemble dies from multiple vendors and connect them through standardized interconnect protocols, such as universal chiplet interconnect express (UCIe). This multi-vendor model, however, redraws the trust boundary and exposes inter-chiplet links to hardware Trojan insertion. Yet this attack surface remains largely unexplored, especially in FPGA-based chiplet ecosystems. In this work, we present the first hardware Trojan that stealthily bypasses the cyclic redundancy check (CRC)-based integrity mechanism of the UCIe protocol. The Trojan deliberately flips data bits in ways that preserve the original checksum, allowing corrupted inter-chiplet traffic to pass CRC validation undetected. We model the Trojan in a multi-die FPGA AI inference engine and show that these evasive corruptions can induce targeted misclassification, including (i) input-class suppression, (ii) forced-class promotion, and (iii) conditional class redirection. The Trojan incurs an overhead ranging from 18–35 and flip-flops (FFs) ranging from 14–17 when implemented on a Kintex-7 FPGA. Our results expose a critical gap in UCIe’s integrity mechanism. Although CRC remains effective for random error detection, its linear structure enables protocol-aware Trojans to inject checksum-preserving corruptions. The integrity gap identified in our work motivates the need to move beyond error-detection codes to secure UCIe-based chiplet interconnects.
Keywords: 
;  ;  ;  ;  
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.