Presentation
CPA-BNN: A Secure and Efficient CIM and PUF Architecture for BNN Accelerator
DescriptionBinary neural networks (BNNs) have emerged as promising models for lightweight intelligent inference by binarizing inputs and weights. Compute in memory (CIM) architectures, which reduce data movements through in-situ operations, have become a strong candidate for BNN accelerators. However, prior works often overlook the security of the model, leaving BNN weights exposed in memory cells and vulnerable to threats such as cloning, tampering, and reverse engineering. This work proposes CPA-BNN, a secure BNN CIM architecture based on resistive random access memory (RRAM). We propose a 4T2R RRAM cell design which implements in-situ encryption and ciphertext convolution operations to protect the weights. In addition, an in-memory batch normalization (BN) scheme is proposed to optimize area overhead and improve compute density. Besides, we propose an intrinsic physical unclonable function (PUF) entropy extraction method and a current tilt-based masking stratege, enabling reliable key extraction within a unified array. The results show that CPA-BNN achieves ~100% key reliability and effectively prevents model attacks. Compared to state-of-the-art SRAM/NVM BNN schemes, CPA-BNN achieves >1.4× compute density and >1.6× storage density improvement.
Event Type
Research Manuscript
TimeTuesday, July 284:30pm - 4:42pm PDT
LocationMtg Room 203C
Similar Presentations
