arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ARMOR-IMC:通过安全内存计算实现操作鲁棒性的自适应资源映射

ARMOR-IMC: Adaptive Resource Mapping for Operational Robustness via Secure In-Memory Computing

Muhtasim Alam Chowdhury, Ramtin Zand, Soheil Salehi

arXiv 2607.10938首次发表:更新:

AI 中文总结

研究传统架构中IMC面临的双重硬件威胁,提出后训练框架,用VIS指导FOWs映射、LPI量化功率变化,在IMAC-Sim模拟器实现,能恢复准确率并减轻功率分析攻击威胁。

AI 中文摘要

传统架构中大量的数据移动开销促使采用内存计算(IMC)来进行高效节能的深度神经网络(DNN)处理。通过利用自旋轨道扭矩磁隧道结(SOT-MTJs)等新兴设备,IMC绕过了“内存墙”并降低了传统CMOS中固有的泄漏功耗。然而,这种转变带来了双重硬件威胁:制造工艺变化(PV)降低了可靠性并增加了对故障注入的脆弱性,而功率侧信道攻击(SCA)则损害了安全性。现有防御措施孤立地应对这些威胁。这项工作提出了一个后训练框架,该框架无需重新训练模型即可同时增强模拟IMC加速器抵御这两种威胁的能力。在IMAC-Sim模拟器中实现,我们的方法使用提出的变化影响分数(VIS)来指导故障观察窗口(FOWs)的映射,并引入每推理泄漏(LPI)指标来量化随机注入下与输入相关的功率变化以及由此导致的有效信噪比降低。实验表明,PV引起的故障可使准确率下降超过50%,而我们的方法可恢复接近基线的准确率并减轻基于相关性的功率分析攻击的威胁。

英文摘要

The massive data-movement overhead in traditional architectures has led to the adoption of In-Memory Computing (IMC) for energy-efficient Deep Neural Network (DNN) processing. By leveraging emerging devices like Spin-Orbit Torque Magnetic Tunnel Junctions (SOT-MTJs), IMC bypasses the "memory wall" and reduces leakage power inherent in traditional CMOS. However, this shift introduces dual hardware threats: manufacturing Process Variation (PV) degrades reliability and increases vulnerability to fault injection, while power Side-Channel Attacks (SCAs) compromise security. Existing defenses address these threats in isolation. This work presents a posttraining framework that simultaneously hardens analog IMC accelerators against both threats without retraining the model. Implemented in the IMAC-Sim simulator, our approach uses the proposed Variation Impact Score (VIS) to guide the mapping of Fault Observation Windows (FOWs) and introduces the Leakage Per Inference (LPI) metric to quantify input-dependent power variability under stochastic injection and the resulting reduction in effective signal-to-noise ratio. Experiments show that PV-induced faults can degrade accuracy by over 50%, while our method restores near-baseline accuracy and mitigates the threat of correlation-based power analysis attacks.

Comments4 pages, 5 figures. Accepted for presentation at the IEEE International Conference on Omni-Layer Intelligent Systems (COINS 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑