VLDB 2026 Research / reviewers in the wild / expert
Annachiara Ruospo
dblp:236/3337
· DBLP profile ↗
37ranked-venue papers
6as first author
30since 2021 · last 2026
0000-0003-2040-9762ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 37 · 6 first-author · 30 since 2021Software engineering, systems software and programming languages · 11 · 2 first-author · 9 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Off-Chip Super-Resolution AI Model to Support Embedded Memory Diagnosis
Simone Anedda, Paolo Bernardi 0002, Matteo Coppetta, Giorgio Insinga, Tommaso Montedoro, Annachiara Ruospo, Rudolf Ullmann, Felix Tengler |
ETS | 6 |
| 2026 | Advances in Testing and Reliability Benchmarks
Francesco Angione, Paolo Bernardi 0002, Nicola Di Gruttola Giardino, Gabriele Filipponi, Giusy Iaria, Giacomo Perlo, Irith Pomeranz, Antonio Porsia, Annachiara Ruospo, Ernesto Sánchez 0001, Vittorio Turco |
ETS | 9 |
| 2026 | VeriSide-II: Structure-Aware Power Modeling for Side-Channel Analysis at Register Transfer Level
Behnam Farnaghinejad, Annachiara Ruospo, Alessandro Savino 0001, Stefano Di Carlo, Ernesto Sánchez 0001 |
IOLTS | 2 |
| 2026 | Vectorized in-Place CRC: a Zero Memory-Overhead Fault Detection Scheme for QNNs on RISC-V
Giacomo Perlo, Annachiara Ruospo, Ernesto Sánchez 0001 |
IOLTS | 2 |
| 2026 | Efficiently Mitigating Model Extraction Attacks against Neural Networks on Edge Devices
Antonio Porsia, Giuseppe Monteasi, Annachiara Ruospo, Domenico Galdiero, Ernesto Sánchez 0001 |
IOLTS | 3 |
| 2026 | Special Session: Reliability Assessment of DNN Models and Inference on Systolic Arrays
Natalia Cherezova, Salvatore Pappalardo, Annachiara Ruospo, Bastien Deveautour, Lorenzo Fezza, Artur Jutman, Ernesto Sánchez 0001, Alberto Bosio, Matteo Sonza Reorda, Maksim Jenihhin |
VTS | 3 |
| 2026 | Benchmark Suite for Resilience Assessment of Deep Learning ModelsabstractThe reliability assessment of systems powered by artificial intelligence (AI) is becoming a crucial step prior to their deployment in safety and mission-critical systems. Recently, many efforts have been made to develop sophisticated techniques to evaluate and improve the resilience of AI models against the occurrence of random hardware faults. However, due to the intrinsic nature of such models, the comparison of the results obtained in state-of-the-art works is crucial, as reference models are missing. Moreover, their resilience is strongly influenced by the training process, the adopted framework and data representation, and so on. To enable a common ground for future research targeting CNN resilience analysis/hardening, this work proposes a first benchmark suite of DL models commonly adopted in this context, providing the models, the training/test data, and the resilience-related information (fault list, coverage, etc.) that can be used as a baseline for fair comparison. To this end, this research identifies a set of axes that have an impact on the resilience and classifies some popular CNN models, in both PyTorch and TensorFlow. Some final considerations are drawn, showing the relevance of a benchmark suite tailored for the resilience context. Cristiana Bolchini, Alberto Bosio, Luca Cassano, Antonio Miele, Salvatore Pappalardo, Dario Passarello, Annachiara Ruospo, Ernesto Sánchez 0001, Matteo Sonza Reorda, Vittorio Turco |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2025 | DEAR-CNN: Data-Efficient Assessment of Resiliency in Convolutional Neural NetworksabstractConvolutional Neural Networks (CNNs) are widely employed in various domains, including safety-critical applications such as autonomous driving. In these scenarios, the reliability of CNNs can be compromised by hardware faults occurring during inference, potentially leading to severe consequences. Evaluating the resilience of CNNs to hardware faults is primarily conducted through Fault Injection (FI) campaigns. However, a significant challenge lies in selecting an appropriate workload. Typically, the entire test set is applied for every injected fault, making the process highly time-consuming and posing difficulties for timely assessments. This paper investigates image selection strategies to rank inputs from the test dataset based on their difficulty in being classified by the CNN. The objective is to identify a minimal subset of test data that enables reliable CNN assessment while reducing computational overhead. By prioritizing challenging samples, the proposed method focuses on inputs that are more likely to reveal network vulnerabilities under fault conditions, enhancing the efficiency of the reliability evaluation process. Experimental results demonstrate that using such a subset of the test data suffices to estimate the number of critical faults for at least one image. This approach not only accelerates the reliability evaluation but also provides novel insights into CNN reliability, offering a practical framework for continuous assessments. Nicolò Bellarmino, Alberto Bosio, Riccardo Cantoro, Annachiara Ruospo, Ernesto Sánchez 0001 |
DDECS | 4 |
| 2025 | AI-Based Classification of Adversarial Attacks vs. Hardware Fault Corruptions in the Split Computing ContextabstractSplit Computing has emerged as a promising paradigm for deploying Deep Neural Networks in Edge and Inter-net of Things systems, enabling inference tasks to be distributed between resource-constrained edge devices and cloud servers. This approach is particularly attractive for autonomous systems, where security and reliability may be critical. However, interme-diate feature maps transmitted between devices are vulnerable to corruption, which may result from intentional adversarial attacks or unintentional hardware faults. Distinguishing whether corruption originates from an external adversary or an inherent system fault is crucial for implementing appropriate counter-measures-reinforcing security mechanisms against attacks or improving system reliability to mitigate the effects of hardware-related faults. To the best of our knowledge, this work is the first to propose a machine learning-based classification mechanism capable of differentiating adversarial attacks from hardware defects in Split Computing systems. The proposed approach analyzes the intermediate feature maps transmitted from the edge device to the server, classifying the source of corruption to guide appropriate responses. Experimental results demonstrate that one of the proposed classifiers can distinguish between intentional and unintentional feature map corruptions with an accuracy of 93.91 %. Giuseppe Esposito, Enrico Magliano, Nicola Scarano, Tamer Eltaras, Juan-David Guerrero-Balaguera, Luca Mannella, Josie E. Rodriguez Condia, Annachiara Ruospo, Stefano Di Carlo, Marco Levorato, Alessandro Savino 0001, Matteo Sonza Reorda |
IOLTS | 8 |
| 2025 | Minimal Supervision, Maximum Accuracy: TabPFN for Microcontroller Performance PredictionabstractMicrocontroller (MCU) performance screening ensures devices meet the maximum operating frequency Fmaxspecification. Speed Monitors (SMONs), implemented as ring oscillators, are used to estimate Fmax. Traditional machine learning (ML) models have been explored for this task but require extensive feature engineering and tuning. This work investigates Tabular Foundation Models, specifically TabPFN, for MCU performance prediction. TabPFN leverages in-context learning, enabling accurate inference without dataset-specific training. We evaluate its performance on a composite dataset combining four distinct MCU product families. Results show that TabPFN matches or exceeds baseline ML models while eliminating the need for manual optimization, offering a promising direction for efficient screening in semiconductor manufacturing with minimal human supervision Nicolò Bellarmino, Riccardo Cantoro, Martin Huch, Tobias Kilian, Annachiara Ruospo |
ITC | 5 |
| 2025 | A Benchmark Suite to Evaluate DNN's ResilienceabstractAssessing AI systems reliability is essential before deploying them in safety-critical applications. While recent efforts have focused on improving model resilience to random hardware faults, meaningful comparison remains difficult due to the lack of standardized reference models. Different authors use different implementations, which makes comparisons unfair and biased: resilience is influenced by the training processes, the software framework, and data representations. To address these issues, this work introduces a benchmark suite of CNN models to test the resilience of DNNs. The benchmark is structured on different axes: software framework, hardware platform, data representation, task and dataset. It is aimed at providing a shared foundation for fair and reproducible resilience evaluation. Cristiana Bolchini, Alberto Bosio, Luca Cassano, Antonio Miele, Salvatore Pappalardo, Dario Passariello, Annachiara Ruospo, Ernesto Sánchez 0001, Matteo Sonza Reorda, Vittorio Turco |
ITC | 7 |
| 2025 | Power Side-Channel Vulnerabilities of a RISC-V Cryptography Accelerator Integrated into CVA6 via Core-V eXtension Interface (CV-X-IF)abstractModern RISC-V designs are increasingly integrating cryptographic accelerators to provide better security features while enhancing performance; however, their vulnerability to power side-channel attacks remains insufficiently investigated. This paper presents a comprehensive evaluation of such vulnerabilities in a RISCV-based AES accelerator connected via the Core-V eXtension Interface (CV-X-IF). The analysis begins at the RTL using simulated power traces, employing KL (Kullback–Leibler) divergence alongside established statistical attacks such as Correlation Power Analysis (CPA) and Differential Power Analysis (DPA). Although the former serves as an early indicator of potential leakage, simulation results highlight its limitations compared to CPA and DPA. To validate these findings, leakage trends are further examined through FPGA-based power measurement. The proposed methodology is designed to be broadly applicable to a range of cryptographic workloads and accelerator architectures. It is demonstrated on an AES accelerator implementing the scalar cryptographic extension (Zk) with pre-expanded keys. Our findings reveal that side-channel vulnerabilities can persist even in tightly integrated instruction pipelines, underscoring the importance of early-stage leakage assessment. Notably, the close alignment between RTL-level simulations and FPGA-based measurements highlights the effectiveness of the approach and its practical value for guiding secure hardware design in RISC-V ecosystems. In particular, AES serves only as a case of study; the proposed RTL and FPGA validation flow is generic and can be applied to any cryptographic accelerator. Behnam Farnaghinejad, Davide Bellizia, Alessandra Dolmeta, Guido Masera, Antonio Porsia, Annachiara Ruospo, Stefano Di Carlo, Alessandro Savino 0001, Ernesto Sánchez 0001 |
ITC | 6 |
| 2025 | Special Session: Trustworthy Hardware-AI at the CloudabstractNowadays, AI applications are becoming extremely popular in our everyday life as well as for the industry. Recent incidents involving hyperscalers have revealed that even cloud-based datacenter hardware can experience failures leading to Silent Data Corruptions (SDCs), also called Silent Data Errors (SDEs). This Special Session delves into the implications of such failures on AI workloads, both during training and inference, and explores methodologies for efficiently detecting SDCs or SDEs through dedicated monitoring phases. Francesco Angione, Paolo Bernardi 0002, Alberto Bosio, Harish Dattatraya Dixit, Salvatore Pappalardo, Annachiara Ruospo, Ernesto Sánchez 0001, Arani Sinha, Vittorio Turco |
VTS | 6 |
| 2025 | An Effective Iterative Statistical Fault Injection Methodology for Deep Neural NetworksabstractThe complexity of the state-of-the-art devices makes reliability assessments approaches extremely complex and, sometimes, out of the timing constraints and computational capabilities. Fault Injections (FIs) are one of the most used approaches for evaluating the dependability of safety-critical systems. With billion-transistor hardware devices running trillion-parameter deep neural networks, injecting the entire fault universe is unfeasible. A widespread solution consists in performing statistical fault injections (SFIs), injecting a subset of faults to estimate a characteristic with an error margin and a confidence level. This research work presents an iterative SFI approach to estimate failure rates in convolutional neural networks (CNNs), i.e., the percentage of wrong predictions caused by random hardware faults affecting synaptic weights. SFIs at different granularities have been performed with margin of errors equal to 1%, 0.1%, and 0.01%. Results for two CNNs (ResNet20 and MobileNetV2) are presented and experimentally and statistically demonstrate the effectiveness of the proposed approach. For instance, to estimate the network-wise failure rate with an error margin of 0.01%, the proposed approach reduces the total injected faults by about 66% and 90% compared to conservative methods, and by 1.94% and 1.65% compared to iterative SFI methods in the literature, for ResNet20 and MobileNetV2, respectively. Annachiara Ruospo, Matteo Sonza Reorda, Riccardo Mariani, Ernesto Sánchez 0001 |
IEEE Trans. Computers | 1 |
| 2024 | Early Detection of Permanent Faults in DNNs Through the Application of Tensor-Related MetricsabstractComputational models based on deep learning are today integrated in many safety-critical domains. These algorithms, such as deep neural networks (DNNs), are rapidly growing in size, reaching billions or even trillions of parameters. This factor brings big challenges not only for performance goals but also for dependability aspects such as reliability. The larger the model, the more challenging the reliability assessment becomes. It is now crucial to develop new test approaches supported by acceptable computational costs for the detection of random-hardware faults such as permanent faults, which may change the predictions of DNNs. The aim of this paper is to leverage tensor-related metrics to early detect faulty behaviors during the inference of DNNs. This involves calculating metrics applied to tensors across various domains (such as image processing, audio analysis, and regression) on the Output Feature Maps (OFMs) of a layer. This analysis allows knowing in advance the effect that a permanent fault will have on the output of the DNN application. The effectiveness of the approach has been experimentally demonstrated by means of software fault injection campaigns considering faults affecting weights of Convolutional Neural Networks (CNNs), i.e., ResNet20 and MobileNetV2. The quality of the metrics is discussed in terms of the trade-off between energy consumption and the ability to differentiate between critical and non-critical faults. Vittorio Turco, Annachiara Ruospo, Ernesto Sánchez 0001, Matteo Sonza Reorda |
DDECS | 2 |
| 2024 | Reliability and Security of AI HardwareabstractIn recent years, Artificial Intelligence (AI) systems have achieved revolutionary capabilities, providing intelligent solutions that surpass human skills in many cases. However, such capabilities come with power-hungry computation workloads. Therefore, the implementation of hardware acceleration becomes as fundamental as the software design to improve energy efficiency, silicon area, and latency of AI systems. Thus, innovative hardware platforms, architectures, and compiler-level approaches have been used to accelerate AI workloads. Crucially, innovative AI acceleration platforms are being adopted in application domains for which dependability must be paramount, such as autonomous driving, healthcare, banking, space exploration, and industry 4.0. Unfortunately, the complexity of both AI software and hardware makes the dependability evaluation and improvement extremely challenging. Studies have been conducted on both the security and reliability of AI systems, such as vulnerability assessments and countermeasures to random faults and analysis for side-channel attacks. This paper describes and discusses various reliability and security threats in AI systems, and presents representative case studies along with corresponding efficient countermeasures. Dennis Gnad, Martin Gotthard, Jonas Krautter, Angeliki Kritikakou, Vincent Meyers, Paolo Rech, Josie E. Rodriguez Condia, Annachiara Ruospo, Ernesto Sánchez 0001, Fernando Santos 0001, Olivier Sentieys, Mehdi Baradaran Tahoori, Russell Tessier, Marcello Traiola |
ETS | 8 |
| 2024 | Approximate Fault-Tolerant Neural Network SystemsabstractThis paper aims to comprehensively explore challenges and opportunities to design highly efficient Neural Network (NN) systems through Approximate Computing (AxC) techniques while ensuring fault tolerance properties. By highlighting the intrinsic conflicting goals of AxC and fault tolerance principles, the study aims to stimulate and contribute to a deeper understanding of how important it is to consider fault tolerance requirements while designing approximate-computing-based systems. This is key to developing highly efficient fault-tolerant architectures for Neural Networks. Marcello Traiola, Salvatore Pappalardo, Ali Piri, Annachiara Ruospo, Bastien Deveautour, Ernesto Sánchez 0001, Alberto Bosio, Sepide Saeedi, Alessio Carpegna, Anil Bayram Gogebakan, Enrico Magliano, Alessandro Savino 0001 |
ETS | 4 |
| 2024 | SpikingJET: Enhancing Fault Injection for Fully and Convolutional Spiking Neural NetworksabstractAs artificial neural networks have become increasingly integrated into safety-critical systems such as autonomous vehicles, devices for medical diagnosis, and industrial automation, ensuring their reliability in the face of random hardware faults becomes paramount. This paper introduces SpikingJET, a novel fault injector designed specifically for fully connected and convolutional Spiking Neural Networks (SNNs). Our work underscores the critical need to evaluate the resilience of SNNs to hardware faults, considering their growing prominence in real-world applications. SpikingJET provides a comprehensive platform for assessing the resilience of SNNs by inducing errors and injecting faults into critical components such as synaptic weights, neuron model parameters, internal states, and activation functions. This paper demonstrates the effectiveness of SpikingJET through extensive software-level experiments on various SNN architectures, revealing insights into their vulnerability and resilience to hardware faults. Moreover, highlighting the importance of fault resilience in SNNs contributes to the ongoing effort to enhance the reliability and safety of Neural Network (NN)-powered systems in diverse domains. Anil Bayram Gogebakan, Enrico Magliano, Alessio Carpegna, Annachiara Ruospo, Alessandro Savino 0001, Stefano Di Carlo |
IOLTS | 4 |
| 2023 | Assessing Convolutional Neural Networks Reliability through Statistical Fault InjectionsabstractAssessing the reliability of modern devices running CNN algorithms is a very difficult task. Actually, the complexity of the state-of-the-art devices makes exhaustive Fault Injection (FI) campaigns impractical and typically out of the computational capabilities. A possible solution consists of resorting to statistical FI campaigns that allow a reduction in the number of needed experiments by injecting only a carefully selected small part of it. Under specific hypothesis, statistical FIs guarantee an accurate picture of the problem, albeit selecting a reduced sample size. The main problems today are related to the choice of the sample size, the location of the faults, and the correct understanding of the statistical assumptions. The intent of this paper is twofold: first, we describe how to correctly specify statistical FIs for Convolutional Neural Networks; second, we propose a data analysis on the CNN parameters that drastically reduces the number of FIs needed to achieve statistically significant results without compromising the validity of the proposed method. The methodology is experimentally validated on two CNNs, ResNet-20 and MobileNetV2, and the results show that a statistical FI campaign on about 1.21% and 0.55% of the possible faults, provides very precise information of the CNN reliability. The statistical results have been confirmed by the exhaustive FI campaigns on the same cases of study. Annachiara Ruospo, Gabriele Gavarini, Corrado De Sio, Juan-David Guerrero-Balaguera, Luca Sterpone, Matteo Sonza Reorda, Ernesto Sánchez 0001, Riccardo Mariani, Joseph Aribido, Jyotika Athavale |
DATE | 1 |
| 2023 | Resilience-Performance Tradeoff Analysis of a Deep Neural Network AcceleratorabstractNowadays, Deep Neural Networks (DNNs) are one of the most computationally-intensive algorithms because of the (i) huge amount of data to be transferred from/to the memory, and (ii) the huge amount of matrix multiplications to compute. These issues motivate the design of custom DNN hardware accelerators. These accelerators are widely used for low-latency safety-critical applications such as object detection in autonomous cars. Safety-critical applications have to be resilient with respect to hardware faults and Deep Learning (DL) accelerators are subjected to hardware faults that can cause functional failures, potentially leading to catastrophic consequences. Although DNNs possess a certain level of intrinsic resilience, it varies depending on the hardware on which they are run. The intent of the paper is to assess the resilience of a systolic-array-based DNN accelerator in the presence of hardware faults, in order to identify the architectural parameters that may mainly impact the DNN resilience. Salvatore Pappalardo, Annachiara Ruospo, Ian O'Connor, Bastien Deveautour, Ernesto Sánchez 0001, Alberto Bosio |
DDECS | 2 |
| 2023 | SCI-FI: a Smart, aCcurate and unIntrusive Fault-Injector for Deep Neural NetworksabstractIn recent years, the reliability of Deep Neural Networks (DNN) has become the focus of an increasing number of research activities. In particular, researchers have focused on understanding how a DNN behaves when the underlying hardware is affected by a fault. This is a challenging task: slight changes in a network architecture can significantly impact how the network reacts to faults. There are several approaches to simulate the behaviour of a faulty network: the most accurate one is to perform low-level fault simulations. Nonetheless, this task is very time-consuming and costly to be implemented. Even though the injection time can be reduced by injecting faults at the application level, for sufficiently large networks, this time is still very high, requiring weeks to complete a single simulation. This work aims at providing a fast and accurate solution for injecting software-level faults in a DNN that is independent of its architecture and does not require any modification to its structure. For this reason, this paper introduces SCI-FI, a Smart, aCcurate and unIntrusive Fault-Injector. SCI-FI smartly reduces the fault injection time required for a complete fault simulation of the network by taking advantage of two fundamental mechanisms: Fault Dropping and Delayed Start. Experimental results from various ResNet, DenseNet and EfficientNet architectures targeting the CIFAR-10 and ImageNet datasets show that combining these techniques drastically reduces the simulation time, which can last up to 70% less. Gabriele Gavarini, Annachiara Ruospo, Ernesto Sánchez 0001 |
ETS | 2 |
| 2023 | Image Test Libraries for the on-line self-test of functional units in GPUs running CNNsabstractThe widespread use of artificial intelligence (AI)-based systems has raised several concerns about their deployment in safety-critical systems. Industry standards, such as ISO26262 for automotive, require detecting hardware faults during the mission of the device. Similarly, new standards are being released concerning the functional safety of AI systems (e.g., ISO/IEC CD TR 5469). Hardware solutions have been proposed for the infield testing of the hardware executing AI applications; however, when used in applications such as Convolutional Neural Networks (CNNs) in image processing tasks, their usage may increase the hardware cost and affect the application performances. In this paper, for the very first time, a methodology to develop high-quality test images, to be interleaved with the normal inference process of the CNN application is proposed. An Image Test Library (ITL) is developed targeting the on-line test of GPU functional units. The proposed approach does not require changing the actual CNN (thus incurring in costly memory loading operations) since it is able to exploit the actual CNN structure. Experimental results show that a 6-image ITL is able to achieve about 95% of stuck-at test coverage on the floating-point multipliers in a GPU. The obtained ITL requires a very low test application time, as well as a very low memory space for storing the test images and the golden test responses. Annachiara Ruospo, Gabriele Gavarini, Antonio Porsia, Matteo Sonza Reorda, Ernesto Sánchez 0001, Riccardo Mariani, Joseph Aribido, Jyotika Athavale |
ETS | 1 |
| 2023 | Evaluation and Mitigation of Faults Affecting Swin TransformersabstractIn the last decade, a huge effort has been spent on assessing the reliability of Convolutional Neural networks (CNNs), probably the most popular architecture for image classification tasks. However, modern Deep Neural Networks (DNNs) are rapidly overtaking CNNs, as state-of-the-art results for many tasks are achieved with the Transformers, innovative DNN models. Transformers' architecture introduces the concept of attention as an alternative to the classical convolution operation. The aim of this work is to propose a reliability analysis of the Swin Transformer, one of the most accurate DNN used for Image Classification, that greatly improves the results obtained by traditional CNNs. In particular, this paper shows that, similar to CNNs, Transformers are susceptible to single faults affecting weights and neurons. Furthermore, it is shown how output ranging, a well-known technique to reduce the impact of a fault in CNNs, is not as effective for the Transformer. The alternative solution proposed by this work is to introduce a ranging not only on the output, but also on the input and on the weight of the fully connected layers. Results show that, on average, the number of critical faults (i.e., that modify the network's output) affecting neurons decreases by a factor of 1.91, while for faults affecting the network's weights this value decreases by a factor of$1\cdot 10^{5}$. Gabriele Gavarini, Annachiara Ruospo, Ernesto Sánchez 0001 |
IOLTS | 2 |
| 2023 | Special Session: Approximation and Fault Resiliency of DNN AcceleratorsabstractDeep Learning, and in particular, Deep Neural Network (DNN) is nowadays widely used in many scenarios, including safety-critical applications such as autonomous driving. In this context, besides energy efficiency and performance, reliability plays a crucial role since a system failure can jeopardize human life. As with any other device, the reliability of hardware architectures running DNNs has to be evaluated, usually through costly fault injection campaigns. This paper explores approximation and fault resiliency of DNN accelerators. We propose to use approximate (AxC) arithmetic circuits to agilely emulate errors in hardware without performing fault injection on the DNN. To allow fast evaluation of AxC DNN, we developed an efficient GPU-based simulation framework. Further, we propose a fine-grain analysis of fault resiliency by examining fault propagation and masking in networks. Mohammad Hasan Ahmadilivani, Mario Barbareschi, Salvatore Barone, Alberto Bosio, Masoud Daneshtalab, Salvatore Della Torca, Gabriele Gavarini, Maksim Jenihhin, Jaan Raik, Annachiara Ruospo, Ernesto Sánchez 0001, Mahdi Taheri |
VTS | 10 |
| 2022 | Selective Hardening of Critical Neurons in Deep Neural NetworksabstractIn the literature, it is argued that Deep Neural Networks (DNNs) possess a certain degree of robustness mainly for two reasons: their distributed and parallel architecture, and their redundancy introduced due to over provisioning. Indeed, they are made, as a matter of fact, of more neurons with respect to the minimal number required to perform the computations. It means that they could withstand errors in a bounded number of neurons and continue to function properly. However, it is also known that different neurons in DNNs have divergent fault tolerance capabilities. Neurons that contribute the least to the final prediction accuracy are less sensitive to errors. Conversely, the neurons that contribute most are considered critical because errors within them could seriously compromise the correct functionality of the DNN. This paper presents a software methodology based on a Triple Modular Redundancy technique, which aims at improving the overall reliability of the DNN, by selectively protecting a reduced set of critical neurons. Our findings indicate that the robustness of the DNNs can be enhanced, clearly, at the cost of a larger memory footprint and a small increase in the total execution time. The trade-offs as well as the improvements are discussed in the work by exploiting two DNN architectures: ResNet and DenseNet trained and tested on CIFAR-10. Annachiara Ruospo, Gabriele Gavarini, Ilaria Bragaglia, Marcello Traiola, Alberto Bosio, Ernesto Sánchez 0001 |
DDECS | 1 |
| 2022 | Test, Reliability and Functional Safety Trends for Automotive System-on-ChipabstractThis paper encompasses three contributions by industry professionals and university researchers. The contributions describe different trends in automotive products, including both manufacturing test and run-time reliability strategies. The subjects considered in this session deal with critical factors, from optimizing the final test before shipment to market to in-field reliability during operative life. Francesco Angione, Davide Appello, Joseph Aribido, Jyotika Athavale, Nicolò Bellarmino, Paolo Bernardi 0002, Riccardo Cantoro, Corrado De Sio, Tommaso Foscale, Gabriele Gavarini, Juan-David Guerrero-Balaguera, Martin Huch, Giusy Iaria, Tobias Kilian, Riccardo Mariani, Raffaele Martone, Annachiara Ruospo, Ernesto Sánchez 0001, Ulf Schlichtmann, Giovanni Squillero, Matteo Sonza Reorda, Luca Sterpone, Vincenzo Tancorre, Roberto Ugioli |
ETS | 17 |
| 2022 | Open-Set Recognition: an Inexpensive Strategy to Increase DNN ReliabilityabstractDeep Neural Networks (DNNs) are nowadays widely used in low-cost accelerators, characterized by limited computational resources. These models, and in particular DNNs for image classification, are becoming increasingly popular in safety-critical applications, where they are required to be highly reliable. Unfortunately, increasing DNNs reliability without computational overheads, which might not be affordable in low-power devices, is a non-trivial task. Our intuition is to detect network executions affected by faults as outliers with respect to the distribution of normal network’s output. To this purpose, we propose to exploit Open-Set Recognition (OSR) techniques to perform Fault Detection in an extremely low-cost manner. In particuar, we analyze the Maximum Logit Score (MLS), which is an established Open-Set Recognition technique, and compare it against other well-known OSR methods, namely OpenMax, energy-based outof-distribution detection and ODIN. Our experiments, performed on a ResNet-20 classifier trained on CIFAR-10 and SVHN datasets, demonstrate that MLS guarantees satisfactory detection performance while adding a negligible computational overhead. Most remarkably, MLS is extremely convenient to conFigure and deploy, as it does not require any modification or re-training of the existing network. A discussion of the advantages and limitations of the analysed solutions concludes the paper. Gabriele Gavarini, Diego Stucchi, Annachiara Ruospo, Giacomo Boracchi, Ernesto Sánchez 0001 |
IOLTS | 3 |
| 2021 | A Benchmark Suite of RT-level Hardware Trojans for Pipelined Microprocessor CoresabstractRecent trends in integrated circuits industry include decentralization of the production flow by involving different integration teams, third-party IP vendors and other untrusted entities. As a result, this is opening up a door to new types of attacks that may lead to devastating consequences, such as denial of service or data leakage. Therefore, the problem of ensuring hardware security has gained much attention in the last years, especially early in the design cycle, when an attacker may insert malicious circuitry at register transfer (RT) or gate level. Due to the increased complexity of modern devices, the research community is spending a lot of effort in developing more sophisticated detection methodologies and smarter attacks. However, the main problem is that they are validated on the existing benchmarks that do not reflect the real complexity. Trying to fill this gap, this paper proposes a set of RT-Level Hardware Trojan benchmarks injected in a RISC-based pipelined microprocessor core. To prove the viability, the impacts on area, power and frequency are presented and discussed. For any proposed Hardware Trojan, the functional description, the implementation details and the effects once activated are provided. Aleksa Damljanovic, Annachiara Ruospo, Ernesto Sánchez 0001, Giovanni Squillero |
DDECS | 2 |
| 2021 | A Model-Based Framework to Assess the Reliability of Safety-Critical ApplicationsabstractSolutions based on artificial intelligence and brain-inspired computations like Artificial Neural Networks (ANNs) are suited to deal with the growing computational complexity required by state-of-the-art electronic devices. Many applications that are being deployed using these computational models are considered safety-critical (e.g., self-driving cars), producing a pressing need to evaluate their reliability. Besides, state-of-theart ANNs require significant memory resources to store their parameters (e.g., weights, activation values), which goes outside the possibility of many resource-constrained embedded systems. In this light, Approximate Computing (AxC) has become a significant field of research to improve memory footprint, speed, and energy consumption in embedded and high-performance systems. The use of AxC can significantly reduce the cost of ANN implementations, but it may also reduce the inherent resiliency of this kind of application. On this scope, reliability assessments are carried out by performing fault injection test campaigns. The intent of the paper is to propose a framework that, relying on the results of radiation tests in Commercial-Off-The-Shelf (COTS) devices, is able to assess the reliability of a given application. To this end, a set of different radiation-induced errors in COTS memories is presented. Upon these, specific fault models are extracted to drive emulation-based fault injections. Lucas M. Luza, Annachiara Ruospo, Alberto Bosio, Ernesto Sánchez 0001, Luigi Dilillo |
DDECS | 2 |
| 2021 | A Suitability Analysis of Software Based Testing Strategies for the On-line Testing of Artificial Neural Networks Applications in Embedded DevicesabstractElectronic devices based on artificial intelligence solutions are pervading our everyday life. Nowadays, human decision processes are supported by real-time data gathered from intelligent systems. Artificial Neural Networks (ANNs) are one of the most used deep learning predictive models due to their outstanding computational capabilities. However, assessing their reliability is still an open issue faced by both the academic and industrial worlds, especially when ANNs are deployed on safety-critical systems, such as self-driving cars in the automotive world. In these systems, a strategy for identifying hardware faults is required by industry standards (e.g., ISO26262 for automotive, and DO254 for avionics). Among the existing in-field test strategies, the periodic scheduling of on-line Software Test Library (STL) is a wide strategy adopted; STL allows to reach an acceptable fault coverage without the need for additional hardware. However, when dealing with ANN-based applications, the execution of on-line tests interleaving the ANN inferences may jeopardise the strive for performance maximization. The paper presents a comprehensive analysis of six possible scenarios concerning the execution of on-line self-test programs in embedded devices running ANN-based applications. In the proposed scenarios, the impact of the STL execution on the ANN performance is analyzed; in particular, the execution times of an inference and the Fault Detection Time (FDT) of the STL are discussed and compared. Experimental analyses are provided by relying on: an open-source RISC-V platform running two different convolutional neural networks; a STL for RISC-V cores with a maximum achievable fault coverage of 90%. Annachiara Ruospo, Davide Piumatti, Andrea Floridia, Ernesto Sánchez 0001 |
IOLTS | 1 |
| 2020 | Deterministic Cache-based Execution of On-line Self-Test Routines in Multi-core Automotive System-on-ChipsabstractTraditionally, the usage of caches and deterministic execution of on-line self-test procedures have been considered two mutually exclusive concepts. At the same time, software executed in a multi-core context suffers of a limited timing predictability due to the higher system bus contention. When dealing with selftest procedures, this higher contention might lead to a fluctuating fault coverage or even the failure of some test programs. This paper presents a cache-based strategy for achieving both deterministic behaviour and stable fault coverage from the execution of self-test procedures in multi-core systems. The proposed strategy is applied to two representative modules negatively affected by a multi-core execution: synchronous imprecise interrupts logic and pipeline hazard detection unit. The experiments illustrate that it is possible to achieve a stable execution while also improving the state-of-the-art approaches for the on-line testing of embedded microprocessors. The effectiveness of the methodology was assessed on all the three cores of a multi-core industrial System- on-Chip intended for automotive ASIL D applications. Andrea Floridia, Tzamn Melendez Carmona, Davide Piumatti, Annachiara Ruospo, Ernesto Sánchez 0001, Sergio de Luca, Rosario Martorana, Mose Alessandro Pernice |
DATE | 4 |
| 2020 | Evaluating Convolutional Neural Networks Reliability depending on their Data RepresentationabstractSafety-critical applications are frequently based on deep learning algorithms. In particular, Convolutional Neural Networks (CNNs) are commonly deployed in autonomous driving applications to fulfil complex tasks such as object recognition and image classification. Ensuring the reliability of CNNs is thus becoming an urgent requirement since they constantly behave in human environments. A common and recent trend is to replace the full-precision CNNs to make way for more optimized models exploiting approximation paradigms such as reduced bit-width data type. If from one hand this is poised to become a sound solution for reducing the memory footprint as well as the computing requirements, it may negatively affect the CNNs resilience. The intent of this work is to assess the reliability of a CNN-based system when reduced bit-widths are used for the network parameters (i.e., synaptic weights). The approach evaluates the impact of permanent faults in CNNs by adopting several bit-width schemes and data types, i.e., floating-point and fixed-point. This determines the trade-off between the CNN accuracy and the bits required to represent network weights. The characterization is performed through a fault injection environment built on the darknet open source framework. Experimental results show the effects of permanent fault injections on the weights of LeNet-5 CNN. Annachiara Ruospo, Alberto Bosio, Alessandro Ianne, Ernesto Sánchez 0001 |
DSD | 1 |
| 2020 | Simulation and Formal: The Best of Both Domains for Instruction Set Verification of RISC-V Based ProcessorsabstractThe instruction set architecture (ISA) specifies a contract between hardware and software; it covers all possible operations that have to be performed by a processor, regardless of the implemented architecture. Verifying the instruction execution against a golden execution model following the ISA is becoming a common practice to verify processors. Despite many potential applications, existing verification frameworks require an extensive test set to cover most of the processor states. In this paper, we suggest a verification scheme combining two different domains, simulation- and formal-verification, establishing a methodology for exclusive error detection. The first approach drives automatic program generation using genetic algorithms to maximize coverage of the test and the contrast against an instruction set simulator. The second is a formal verification approach, where an interface carries specific processor states according to the ISA specification. By combining these two, we present a reliable way to perform more accurate instruction verification by increasing processor state coverage and formal assertions to detect different kinds of errors. Compared to extensive torture test sets, this approach reaches a more significant number of internal states by taking advantage of the exercised abstractions. Among remarkable results to highlight, the proposed approach detected a RISC-V ISA specification gap revealing ambiguity from two different verification perspectives. Ckristian Duran, Hanssel Morales, Annachiara Ruospo, Ernesto Sánchez 0001, Elkim Roa |
ISCAS | 4 |
| 2020 | Special Session: AutoSoC - A Suite of Open-Source Automotive SoC BenchmarksabstractThe current demands for autonomous driving generated momentum for an increase in research in the different technologies required for these applications. Nonetheless, the limited access to representative designs and industrial methodologies poses a challenge to the research community. Considering this scenario, there is a high demand for an open-source solution that could support development of research targeting automotive applications. This paper presents the current status of AutoSoC, an automotive SoC benchmark suite that includes hardware and software elements and is entirely open-source. The objective is to provide researchers with an industrial-grade automotive SoC that includes all essential components, is fully customizable, and enables analysis of functional safety solutions and automotive SoC configurations. This paper describes the available configurations of the benchmark including an initial assessment for ASIL B to D configurations. Felipe Augusto da Silva, Ahmet Cagri Bagbaba, Annachiara Ruospo, Riccardo Mariani, Ghani Kanawati, Ernesto Sánchez 0001, Matteo Sonza Reorda, Maksim Jenihhin, Said Hamdioui, Christian Sauer 0001 |
VTS | 3 |
| 2019 | Non-Intrusive Self-Test Library for Automotive Critical Applications: Constraints and SolutionsabstractToday, safety-critical applications require self-tests and self-diagnosis approaches to be applied during the lifetime of the device. In general, the fault coverage values required by the standards (like ISO 26262) in the whole System-on-Chip (SoC) are very high. Therefore, different strategies are adopted. In the case of the processor core, the required fault coverage can be achieved by scheduling the periodical execution of a set of test programs or Software-Test Library (STL). However, the STL for infield testing should be able to comply with the operating system specifications without affecting the mission operation of the device application. In this paper, the most relevant problems for the development of the STL are first discussed. Then, it presents a set of strategies and solutions oriented to produce an efficient and non-intrusive STL to be used exclusively during the in-field testing of automotive processor cores. The proposed approach was experimented on an automotive SoC developed by STMicroelectronics. Paolo Bernardi 0002, Riccardo Cantoro, Andrea Floridia, Davide Piumatti, C. Pogonea, Annachiara Ruospo, Ernesto Sánchez 0001, Sergio de Luca, Alessandro Sansonetti |
DATE | 6 |
| 2019 | A Decentralized Scheduler for On-line Self-test Routines in Multi-core Automotive System-on-ChipsabstractModern System-on-Chips (SoCs) deployed for safety-critical applications typically embed one or more processing cores along with a variable number of peripherals. The compliance of such designs with functional safety standards is achieved by a combination of different techniques based on hardware redundancy and in-field test mechanisms. Among these, Software Test Libraries (STLs) are rapidly becoming adopted for testing the CPU and peripherals modules. The STL is usually composed of two sets of self-test procedures: boot-time and runtime tests. The former set is typically executed during the boot or power-on phase of the SoC since it requires full access to the available hardware (e.g., these programs need to manipulate the Interrupt Vector Table and to access the system RAM). The latter set instead, is designed to coexist with the user application and can be executed without requiring special constraints. When the STL is intended for testing the different cores within a multi-core SoC, the concurrent execution of the boot-time self-tests becomes an issue since this could lead to a longer power-up phase and excessive utilization of system resources. The main intent of this work is to present the architecture of a decentralized software scheduler, conceived for the concurrent execution of the STL on the available cores. The proposed solution considers the typical constraints of an STL in a multi-core scenario when deployed in field, namely minimum system resources usage (i.e., code and data memory). The effectiveness of the proposed scheduler was experimentally evaluated on an industrial STL developed for a multi-core SoC manufactured by STMicroelectronics. Andrea Floridia, Davide Piumatti, Annachiara Ruospo, Ernesto Sánchez 0001, Sergio de Luca, Rosario Martorana |
ITC | 3 |
| 2018 | An Open-Source Verification Framework for Open-Source Cores: A RISC-V Case StudyabstractThe complexity and heterogeneity of digital devices used in embedded systems is increasing everyday and delivering a bug-free design is still a very complex task. The interest for open-source hardware in real products is demanding for tools and advanced methodologies for verification to provide high reliability to open and free IPs. In this work, an open-source evolutionary optimizer has been used to create functional test programs that improve the verification test set for an open-source microprocessor, enhancing in this way, the verification level of the device. The verification programs are generated to optimize code coverage metrics and are tested against a high-level model to find device incorrectnesses during the generation time. A perturbation mechanism has been included in the verification framework to cover parts of the device under verification not reachable with only software stimuli such as interrupts or memory stalls. The proposed methodology uncovered 10 bugs still present in the RTL description of the analyzed device and demonstrated the effectiveness of open-source verification tools for the next generation of open-source RISC-V microprocessors. Pasquale Davide Schiavone, Ernesto Sánchez 0001, Annachiara Ruospo, Francesco Minervini, Florian Zaruba, Germain Haugou, Luca Benini |
VLSI-SoC | 3 |