Who Wins First? A Six-Attack Machine-Learning Benchmark on OR-AND-XOR Arbiter PUFs, And A Methodological Warning About Comparing Them

Authors

  • Ismoil Makhamatdjonov Department of Computer Science, University of Sheffield, Uzbekistan

DOI:

https://doi.org/10.37547/ijasr-06-03-08

Keywords:

Physically unclonable function, Arbiter PUF, machine-learning attack

Abstract

Published attacks on Physically Unclonable Functions (PUFs) usually test one or two attacker architectures against a single circuit family, leaving open a basic question: given the same PUF and CRP budget, which learning paradigm wins first, and why? This article benchmarks six attackers — logistic regression, least-squares regression, a multilayer perceptron, an LMN feature-lifting model, a denoising autoencoder, and a compact Transformer — against Arbiter OR-AND-XOR PUFs (AOX-PUFs) across three circuit families (aox-5, aox-6, aox-7; n=64) and twelve (x,y,z) mixes, with CRP budgets from 2,500 to ≈1.9 million on the University of Sheffield's Stanage HPC cluster. The hypothesis is that no single attacker dominates independent of circuit composition: linear attackers should suffice only while the decision boundary stays close to linear in the engineered challenge features, while non-linear attackers should become necessary once OR-AND-XOR composition pushes it away from linearity. The data confirm this. The MLP and autoencoder reach 98–99.5% accuracy fastest, by 25,000–75,000 CRPs on favourable mixes; logistic regression settles near 0.95±0.02; LMN bifurcates sharply between near-chance (0.52–0.60) and near-ceiling (≈0.98) accuracy depending on mix; least-squares regression is the weakest linear baseline. A further finding is methodological: an under-trained Transformer can make an unrelated protocol-level defence look misleadingly effective, because its classical baseline never reaches its own ceiling. These results are benchmarked against the reliability-based, hybrid-PUF, and bias-exploiting attack literature, with a labelled illustrative calculation setting this study's own data against an independently reported deep-neural-network accuracy collapse at high XOR counts.

References

1. J. Yao, L. Pang, Y. Su, Z. Zhang, W. Yang, A. Fu, and Y. Gao, “Design and evaluate recomposited OR-AND-XOR-PUF,” IEEE Transactions on Emerging Topics in Computing, vol. 10, no. 2, pp. 662–677, 2022. https://doi.org/10.1109/TETC.2022.3170320

2. H. Fei, O. Millwood, P. Gope, J. Miskelly, and B. Sikdar, “Attacking delay-based PUFs with minimal adversarial knowledge,” IEEE Transactions on Information Forensics and Security, 2024. https://arxiv.org/abs/2403.00464

3. P. H. Nguyen, D. P. Sahoo, C. Jin, K. Mahmood, U. Rührmair, and M. van Dijk, “The Interpose PUF: Secure PUF design against state-of-the-art machine learning attacks,” IACR Transactions on Cryptographic Hardware and Embedded Systems, vol. 2019, no. 4, pp. 243–290, 2019. https://doi.org/10.13154/tches.v2019.i4.243-290

4. N. Wisiol and N. Pirnay, “XOR Arbiter PUFs have systematic response bias,” in Financial Cryptography and Data Security (FC 2020), LNCS vol. 12059, pp. 50–57, 2020. https://doi.org/10.1007/978-3-030-51280-4_4

5. G. T. Becker, “The gap between promise and reality: On the insecurity of XOR Arbiter PUFs,” in Cryptographic Hardware and Embedded Systems (CHES 2015), LNCS vol. 9293, pp. 535–555, 2015. https://doi.org/10.1007/978-3-662-48324-4_27

6. N. Wisiol, C. Gräbnitz, C. Mühl, B. Zengin, T. Soroceanu, N. Pirnay, K. T. Mursi, and A. Baliuka, “pypuf: Cryptanalysis of physically unclonable functions,” [Computer software], 2021. https://github.com/nils-wisiol/pypuf

7. I. Makhamatdjonov, “Quantum-inspired PUFs: Advantages, challenges, and applications,” Unpublished MSc dissertation, University of Sheffield, 2025.

8. H. Wang, W. Hao, Y. Tang, B. Zhu, W. Dong, and W. Liu, “Deep neural network modeling attacks on arbiter-PUF-based designs,” Cybersecurity, vol. 8, no. 11, 2025. https://doi.org/10.1186/s42400-024-00308-7

9. H. Wang, W. Liu, W. Cai, Y. Lu, and C. Wan, “Efficient attacks on strong PUFs via covariance and Boolean modeling,” ACM Transactions on Design Automation of Electronic Systems, vol. 29, no. 6, 2024. https://doi.org/10.1145/3687469

10. H. Fei, P. Gope, O. Millwood, and B. Sikdar, “Optimal machine-learning attacks on hybrid PUFs,” in European Symposium on Research in Computer Security (ESORICS 2024), LNCS vol. 14982, pp. 251–270, 2024. https://doi.org/10.1007/978-3-031-70879-4_13

11. Y. Zhuang, K. T. Mursi, and L. Gaoxiang, “A challenge obfuscating interface for Arbiter PUF variants against machine learning attacks,” arXiv:2103.12935, 2021. https://arxiv.org/abs/2103.12935

Downloads

Published

2026-03-31

How to Cite

Ismoil Makhamatdjonov. (2026). Who Wins First? A Six-Attack Machine-Learning Benchmark on OR-AND-XOR Arbiter PUFs, And A Methodological Warning About Comparing Them. International Journal of Advance Scientific Research, 6(03), 213-224. https://doi.org/10.37547/ijasr-06-03-08

Similar Articles

111-120 of 259

You may also start an advanced similarity search for this article.