[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86084-en":3,"doc-seo-86084-105":30,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86084,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","ARMOR-IMC: Adaptive Resource Mapping for Operational Robustness via Secure In-Memory Computing","In-memory computing (IMC) reduces the data-movement overhead of traditional architectures for energy-efficient deep neural network (DNN) processing, especially with emerging SOT-MTJ based devices. This shift, however, creates dual risks: process variation (PV) that triggers reliability loss and fault injection susceptibility, and data-dependent power side-channel attacks (SCAs) that threaten confidentiality. ARMOR-IMC introduces a posttraining framework that hardens analog IMC accelerators against both threats without retraining, using VIS and LPI to guide adaptive mapping and quantify leakage-driven signal-noise degradation.","ARMOR-IMC: Adaptive Resource Mapping for Operational Robustness  \nvia Secure In-Memory Computing  \nMuhtasim Alam Chowdhury∗ , Ramtin Zand†, Soheil Salehi∗  \n†Department of Computer Science and Engineering, University of South Carolina, Columbia, SC, USA  \n∗ Department of Electrical and Computer Engineering, University of Arizona, Tucson, AZ, USA  \n{mmc7, [ssalehi](ssalehi}@arizona.edu)[}](ssalehi}@arizona.edu)[@arizona.edu](ssalehi}@arizona.edu)∗ , [ramtin@cse.sc.edu](ramtin@cse.sc.edu)†  \narXiv :2607 . 10938v 1 [ cs .CR] 12 Jul 2026  \nAbstract—The massive data-movement overhead in traditional architectures has led to the adoption of In-Memory Computing (IMC) for energy-efficient Deep Neural Network (DNN) processing. By leveraging emerging devices like Spin-Orbit Torque Magnetic Tunnel Junctions (SOT-MTJs), IMC bypasses the“memory wall” and reduces leakage power inherent in traditional CMOS. However, this shift introduces dual hardware threats: manufacturing Process Variation (PV) degrades reliability and increases vulnerability to fault injection, while power SideChannel Attacks (SCAs) compromise security. Existing defenses address these threats in isolation. This work presents a posttraining framework that simultaneously hardens analog IMC accelerators against both threats without retraining the model. Implemented in the IMAC-Sim simulator, our approach uses the proposed Variation Impact Score (VIS) to guide the mapping of Fault Observation Windows (FOWs) and introduces the Leakage Per Inference (LPI) metric to quantify input-dependent power variability under stochastic injection and the resulting reduction in effective signal-to-noise ratio. Experiments show that PVinduced faults can degrade accuracy by over 50%, while our method restores near-baseline accuracy and mitigates the threat of correlation-based power analysis attacks.  \nKeywords—Secure In-Memory Computing, Robust AI Accelerators, Emerging Devices, Side-Channel Mitigation  \nI. INTRODUCTION  \nDeep Neural Networks (DNNs) are now integral to missioncritical systems, placing immense strain on conventional hardware. To overcome the resulting von Neumann bottleneck, the underlying hardware is shifting towards In-Memory Computing (IMC) architectures that leverage emerging devices like Spin-Orbit Torque Magnetic Tunnel Junction (SOT-MTJ) based Magnetic Random Access Memories (MRAMs) [1] . However, this transition introduces significant hardware security and reliability challenges that threaten the integrity and confidentiality of AI workloads. The first major threat is reliability degradation caused by manufacturing Process Variation (PV) . Our prior work demonstrated that subtle, adversarial, or unintentional variations in physical parameters, such as the SOT-MTJ device’s oxide thickness (tox ), can alter its resistive states, inducing systemic bit-flips in the MRAM weight arrays that significantly degrade the inference accuracy of the deployed DNN model [2], [3] . The second major threat is physical Side-Channel Attacks (SCAs) . It is wellestablished that DNN accelerators are vulnerable to attacks where an adversary with physical proximity measures the device’s power consumption to infer secret data. Since the power consumed by a circuit is data-dependent, attackers can  \nFig. 1. Overview of the ARMOR-IMC framework, illustrating the overall scope and highlighting the dual-metric analysis and adaptive mapping flow for improving both reliability and side-channel resilience in IMC accelerators.  \nleverage statistical techniques such as Correlation Power Analysis (CPA) and Differential Power Analysis (DPA) to recover the secret parameters of the model, potentially compromising its Intellectual Property (IP) [4] . While some defenses exist, they typically address these reliability and security threatsin isolation, leaving a critical gap where a system hardened against one threat remains vulnerable to the other.  \nTo address this gap, we propose ARMOR-IMC, illustrated in Fig","cbCaigCFecjoQHMq","https://ap.wps.com/l/cbCaigCFecjoQHMq","pdf",1381558,2,1,4,"English","en",105,"# Introduction\n## In-Memory Computing (IMC) and Process Variation\n# Background and Motivation\n## Threat Model and Security Risks\n# ARMOR-IMC Framework Overview\n## Variation Impact Score (VIS)\n## Leakage Per Inference (LPI)","[{\"question\":\"What security and reliability threats does ARMOR-IMC address in analog IMC accelerators?\",\"answer\":\"ARMOR-IMC simultaneously targets process-variation-induced reliability degradation and physical side-channel attacks that exploit input-dependent power consumption.\"},{\"question\":\"How does ARMOR-IMC reduce the need for costly model retraining?\",\"answer\":\"It is implemented as a posttraining framework that hardens the analog IMC accelerators without retraining the DNN model.\"},{\"question\":\"What are VIS and LPI, and what roles do they play in the framework?\",\"answer\":\"Variation Impact Score (VIS) guides mapping decisions by quantifying reliability risk from fault injection over Fault Observation Windows (FOWs). Leakage Per Inference (LPI) measures input-dependent power variability and the resulting reduction in effective signal-to-noise ratio under stochastic injection.\"}]",1784208405,10,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":28},"armor-imc-adaptive-resource-mapping-for-operational-robustness-via-secure-in-memory-computing","",{"@graph":36,"@context":84},[37,52,67],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":22},"https://docshare.wps.com/document/armor-imc-adaptive-resource-mapping-for-operational-robustness-via-secure-in-memory-computing/86084/",{"url":51,"name":13,"@type":53,"author":54,"headline":13,"publisher":56,"fileFormat":59,"inLanguage":24,"description":14,"dateModified":60,"datePublished":61,"encodingFormat":59,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":55},"Person",{"url":41,"name":57,"@type":58},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":64,"interactionType":65,"userInteractionCount":20},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What security and reliability threats does ARMOR-IMC address in analog IMC accelerators?","Question",{"text":74,"@type":75},"ARMOR-IMC simultaneously targets process-variation-induced reliability degradation and physical side-channel attacks that exploit input-dependent power consumption.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does ARMOR-IMC reduce the need for costly model retraining?",{"text":79,"@type":75},"It is implemented as a posttraining framework that hardens the analog IMC accelerators without retraining the DNN model.",{"name":81,"@type":72,"acceptedAnswer":82},"What are VIS and LPI, and what roles do they play in the framework?",{"text":83,"@type":75},"Variation Impact Score (VIS) guides mapping decisions by quantifying reliability risk from fault injection over Fault Observation Windows (FOWs). Leakage Per Inference (LPI) measures input-dependent power variability and the resulting reduction in effective signal-to-noise ratio under stochastic injection.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":57,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,133],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":29,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":29,"slug":132},"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]