Sensitivity Analysis of SOT-MTJs to Manufacturing Process Variation: A Hardware Security Perspective
Mousam Hossain, Muhtasim Alam Chowdhury, Ronald F. DeMara, Soheil Salehi · 2024
Hardware-based acceleration approaches for Machine Learning (ML) workloads have been embracing the significant potential of post-CMOS switching devices to attain reduced footprint and/or energy-efficient execution relative to transistor-based GPU and/or TPU-based accelerator architectures. Meanwhile, the promulgation of fabless IC chip manufacturing paradigms has heightened the hardware security concerns inherent in such approaches. Specifically, ML recognition outputs can be significantly swayed via unauthorized access in fabrication stage resulting in global modification of oxide thickness (Tox) leading to bit-flips of the weights in the crossbar array. Evaluation results on the MNIST dataset indicates that just 0.05% of bits in crossbar having a flipped resistance state, digits ‘4’ and ‘5’ show highest overall error rates and digit ‘9’ exhibit the lowest impact, with recognition accuracy of digits ‘2’, ‘3’, and ‘8’, unaffected by changing the oxide thickness of SOT-MTJs uniformly from 0.75 nm to 1.2 nm without modifying the netlist nor even having access to the circuit design itself. Furthermore, mitigation approaches to such novel and potentially damaging manufacturing-side intrusions are identified.