CircuitGuard: Mitigating LLM Memorization in RTL Code Generation Against IP Leakage
Nowfel Mashnoor, Mohammad Akyash, Hadi Kamali, Kimia Azar
TL;DR
Problem: IP leakage through memorization in LLM-driven RTL code generation poses security risks for proprietary hardware designs. Approach: CircuitGuard integrates attention-steered unlearning with an RTL-aware similarity metric and a layer-wise activation-editing pipeline to suppress memorization while preserving correctness. Findings: The method identifies 275 memorization-critical features across layers 18–28 in Llama 3.1-8B, achieving up to 80% reduction in semantic similarity to proprietary patterns and 78–85% cross-domain transfer with acceptable code quality. Significance: This enables safer deployment of LLM-based RTL generation with tunable leakage-utility trade-offs and suggests directions for dynamic feature selection and formal RTL verification.
Abstract
Large Language Models (LLMs) have achieved remarkable success in generative tasks, including register-transfer level (RTL) hardware synthesis. However, their tendency to memorize training data poses critical risks when proprietary or security-sensitive designs are unintentionally exposed during inference. While prior work has examined memorization in natural language, RTL introduces unique challenges: In RTL, structurally different implementations (e.g., behavioral vs. gate-level descriptions) can realize the same hardware, leading to intellectual property (IP) leakage (full or partial) even without verbatim overlap. Conversely, even small syntactic variations (e.g., operator precedence or blocking vs. non-blocking assignments) can drastically alter circuit behavior, making correctness preservation especially challenging. In this work, we systematically study memorization in RTL code generation and propose CircuitGuard, a defense strategy that balances leakage reduction with correctness preservation. CircuitGuard (1) introduces a novel RTL-aware similarity metric that captures both structural and functional equivalence beyond surface-level overlap, and (2) develops an activation-level steering method that identifies and attenuates transformer components most responsible for memorization. Our empirical evaluation demonstrates that CircuitGuard identifies (and isolates) 275 memorization-critical features across layers 18-28 of Llama 3.1-8B model, achieving up to 80% reduction in semantic similarity to proprietary patterns while maintaining generation quality. CircuitGuard further shows 78-85% cross-domain transfer effectiveness, enabling robust memorization mitigation across circuit categories without retraining.
