J. Semicond. >  In Press

NEWS AND VIEWS

Secure compute-in-memory for model protection and federated learning

Li Ni1, Jinwei Pu1, Jiaxuan Xie1, Zhengxun Lai1 and You Meng1,

+ Author Affiliations
DOI: 10.1088/1674-4926/26070042CSTR: 32376.14.1674-4926.26070042

PDF

Turn off MathJax



[1]
Wang Z Y, Wu Y T, Park Y, et al. Safe, secure and trustworthy compute-in-memory accelerators. Nat Electron, 2024, 7(12): 1086 doi: 10.1038/s41928-024-01312-y
[2]
Wan W, Kubendran R, Schaefer C, et al. A compute-in-memory chip based on resistive random-access memory. Nature, 2022, 608(7923): 504 doi: 10.1038/s41586-022-04992-8
[3]
Ambrogio S, Narayanan P, Okazaki A, et al. An analog-AI chip for energy-efficient speech recognition and transcription. Nature, 2023, 620(7975): 768 doi: 10.1038/s41586-023-06337-5
[4]
Ni L, Pu J, Huang X J, et al. CPA-BNN: A secure and efficient CIM and PUF architecture for BNN accelerator. Proceedings of the 63rd ACM/IEEE Design Automation Conference, 2026: 1
[5]
Woo K S, Han J, Yi S I, et al. Tunable stochastic memristors for energy-efficient encryption and computing. Nat Commun, 2024, 15(1): 3245 doi: 10.1038/s41467-024-47488-x
[6]
Ni L, Wu S Y, Pu J, et al. Highly reliable RRAM-based physical unclonable function with auto-write technique. IEEE Trans Very Large Scale Integr Syst, 2026, 34(6): 2000 doi: 10.1109/TVLSI.2026.3670888
[7]
Ni L, Xie J X, Pu J, et al. R3 PUF: A reliable RRAM-based PUF resilient to machine learning attacks. IEEE Trans Very Large Scale Integr Syst, 2026, Early access; pagination forthcoming
[8]
Zhou Z Y, Li G, Zhang Y J, et al. A strong PUF-based security protocol to protect AI model parameters against privacy information leakage. IEEE Internet Things J, 2025, 12(12): 20815 doi: 10.1109/JIOT.2025.3544555
[9]
Gao Y S, Al-Sarawi S F, Abbott D. Physical unclonable functions. Nat Electron, 2020, 3(2): 81 doi: 10.1038/s41928-020-0372-5
[10]
Li X Q, Lin B, Gao B, et al. A memristor-based unified PUF and TRNG chip with a concealable ability for advanced edge security. Sci Adv, 2025, 11(13)” eadr0112
[11]
Ni L, Huang X J, Chen X H, et al. In-memory unified TRNG and PUF based on RRAM random switching time. IEEE Trans Electron Devices, 2025, 72(12): 6729 doi: 10.1109/TED.2025.3627172
[12]
Chen Z J, Wu M, Zhou Y F, et al. PUF-CIM: SRAM-based compute-in-memory with zero bit-error-rate physical unclonable function for lightweight secure edge computing. IEEE Trans Very Large Scale Integr Syst, 2023, 31(8): 1234 doi: 10.1109/TVLSI.2023.3277517
[13]
Yue W S, Wu K, Li Z Y, et al. Physical unclonable in-memory computing for simultaneous protecting private data and deep learning models. Nat Commun, 2025, 16(1): 1031 doi: 10.1038/s41467-025-56412-w
[14]
Li X Q, Gao B, Qin Q, et al. Federated learning using a memristor compute-in-memory chip with in situ physical unclonable function and true random number generator. Nat Electron, 2025, 8(6): 518-528 doi: 10.1038/s41928-025-01390-6
[15]
Chiu Y C, Khwa W S, Yang C S, et al. A CMOS-integrated spintronic compute-in-memory macro for secure AI edge devices. Nat Electron, 2023, 6(7): 534 doi: 10.1038/s41928-023-00994-0
Fig. 1.  (Color online) RePACK distributes a chip-specific PUF response across the inference path.

Fig. 2.  (Color online) CPTIN co-locates the trust functions required for encrypted federated learning.

Table 1.   Reported quantitative benchmarks of RePACK.

MetricReported benchmark
Technology and implementation40-nm ReRAM CIM test chip; 13 modules (one PUF array and 12 CIM arrays)
Security and task performanceFake-core Dice accuracy: 0.000–39.236%; wrong PUF responses drove accuracy towards zero
Robustness and error handling6.25% missing bits caused sharp accuracy loss; two or more affected layers reduced accuracy to approximately zero
Hardware cost and efficiencyBS-code reconstruction: 3032.0 μm2, 0.4596 mW, 1.6% area, 7% power, and no additional MAC cycle
DownLoad: CSV

Table 2.   Reported quantitative benchmarks of CPTIN.

MetricReported benchmark
Technology and implementation130-nm, 128-kb one-transistor-one-resistor chip; in situ PUF, TRNG, key storage, CIM, and encryption–decryption
Security and task performance10,000 PUF keys evaluated; four-client sepsis prediction showed 0.12% lower accuracy than centralized software learning
Robustness and error handlingRRNS: 1/64 incorrect results after three iterations versus 12/64 for binary encoding; 2.24% MVM error
Hardware cost and efficiency245.76 μs and 163.16 μJ, versus ASIC estimates of 1576.96 μs and 9418.34 μJ
DownLoad: CSV
[1]
Wang Z Y, Wu Y T, Park Y, et al. Safe, secure and trustworthy compute-in-memory accelerators. Nat Electron, 2024, 7(12): 1086 doi: 10.1038/s41928-024-01312-y
[2]
Wan W, Kubendran R, Schaefer C, et al. A compute-in-memory chip based on resistive random-access memory. Nature, 2022, 608(7923): 504 doi: 10.1038/s41586-022-04992-8
[3]
Ambrogio S, Narayanan P, Okazaki A, et al. An analog-AI chip for energy-efficient speech recognition and transcription. Nature, 2023, 620(7975): 768 doi: 10.1038/s41586-023-06337-5
[4]
Ni L, Pu J, Huang X J, et al. CPA-BNN: A secure and efficient CIM and PUF architecture for BNN accelerator. Proceedings of the 63rd ACM/IEEE Design Automation Conference, 2026: 1
[5]
Woo K S, Han J, Yi S I, et al. Tunable stochastic memristors for energy-efficient encryption and computing. Nat Commun, 2024, 15(1): 3245 doi: 10.1038/s41467-024-47488-x
[6]
Ni L, Wu S Y, Pu J, et al. Highly reliable RRAM-based physical unclonable function with auto-write technique. IEEE Trans Very Large Scale Integr Syst, 2026, 34(6): 2000 doi: 10.1109/TVLSI.2026.3670888
[7]
Ni L, Xie J X, Pu J, et al. R3 PUF: A reliable RRAM-based PUF resilient to machine learning attacks. IEEE Trans Very Large Scale Integr Syst, 2026, Early access; pagination forthcoming
[8]
Zhou Z Y, Li G, Zhang Y J, et al. A strong PUF-based security protocol to protect AI model parameters against privacy information leakage. IEEE Internet Things J, 2025, 12(12): 20815 doi: 10.1109/JIOT.2025.3544555
[9]
Gao Y S, Al-Sarawi S F, Abbott D. Physical unclonable functions. Nat Electron, 2020, 3(2): 81 doi: 10.1038/s41928-020-0372-5
[10]
Li X Q, Lin B, Gao B, et al. A memristor-based unified PUF and TRNG chip with a concealable ability for advanced edge security. Sci Adv, 2025, 11(13)” eadr0112
[11]
Ni L, Huang X J, Chen X H, et al. In-memory unified TRNG and PUF based on RRAM random switching time. IEEE Trans Electron Devices, 2025, 72(12): 6729 doi: 10.1109/TED.2025.3627172
[12]
Chen Z J, Wu M, Zhou Y F, et al. PUF-CIM: SRAM-based compute-in-memory with zero bit-error-rate physical unclonable function for lightweight secure edge computing. IEEE Trans Very Large Scale Integr Syst, 2023, 31(8): 1234 doi: 10.1109/TVLSI.2023.3277517
[13]
Yue W S, Wu K, Li Z Y, et al. Physical unclonable in-memory computing for simultaneous protecting private data and deep learning models. Nat Commun, 2025, 16(1): 1031 doi: 10.1038/s41467-025-56412-w
[14]
Li X Q, Gao B, Qin Q, et al. Federated learning using a memristor compute-in-memory chip with in situ physical unclonable function and true random number generator. Nat Electron, 2025, 8(6): 518-528 doi: 10.1038/s41928-025-01390-6
[15]
Chiu Y C, Khwa W S, Yang C S, et al. A CMOS-integrated spintronic compute-in-memory macro for secure AI edge devices. Nat Electron, 2023, 6(7): 534 doi: 10.1038/s41928-023-00994-0
  • Search

    Advanced Search >>

    GET CITATION

    shu

    Export: BibTex EndNote

    Article Metrics

    Article views: 9 Times PDF downloads: 5 Times Cited by: 0 Times

    History

    Received: 26 July 2026 Revised: Online: Uncorrected proof: 17 September 2026

    Catalog

      Email This Article

      User name:
      Email:*请输入正确邮箱
      Code:*验证码错误
      Li Ni, Jinwei Pu, Jiaxuan Xie, Zhengxun Lai, You Meng. Secure compute-in-memory for model protection and federated learning[J]. Journal of Semiconductors, 2026, In Press. doi: 10.1088/1674-4926/26070042 ****L Ni, J W Pu, J X Xie, Z X Lai, and Y Meng, Secure compute-in-memory for model protection and federated learning[J]. J. Semicond., 2026, accepted doi: 10.1088/1674-4926/26070042
      Citation:
      Li Ni, Jinwei Pu, Jiaxuan Xie, Zhengxun Lai, You Meng. Secure compute-in-memory for model protection and federated learning[J]. Journal of Semiconductors, 2026, In Press. doi: 10.1088/1674-4926/26070042 ****
      L Ni, J W Pu, J X Xie, Z X Lai, and Y Meng, Secure compute-in-memory for model protection and federated learning[J]. J. Semicond., 2026, accepted doi: 10.1088/1674-4926/26070042

      Secure compute-in-memory for model protection and federated learning

      DOI: 10.1088/1674-4926/26070042
      CSTR: 32376.14.1674-4926.26070042
      More Information
      • Li Ni is a Ph.D. candidate at the College of Semiconductors (College of Integrated Circuits), Hunan University. His research interests include hardware security primitives, compute-in-memory and neuromorphic computing
      • Jinwei Pu is a Ph.D. candidate at the College of Semiconductors (College of Integrated Circuits), Hunan University. His current research interests include digital circuit design and post-quantum cryptographic hardware
      • Jiaxuan Xie is currently a Master’s student at the College of Semiconductors (College of Integrated Circuits), Hunan University. His current research focuses on the fabrication of nanoelectronic devices, transistor performance characterization, and their applications in hardware security primitives
      • Zhengxun Lai received his Ph.D. degree from the Department of Materials Science and Engineering, City University of Hong Kong, in 2023. He is currently an associate professor at the College of Semiconductors (College of Integrated Circuits), Hunan University. His research interests include halide-perovskite electronic and optoelectronic devices
      • You Meng is a professor at the College of Semiconductors (College of Integrated Circuits), Hunan University. He received his B.S. degree in Applied Physics and M.S. degree in Physics from Qingdao University in 2015 and 2018, respectively, and his Ph.D. degree in Materials Science and Engineering from City University of Hong Kong in 2021. His research interests include nanomaterials-based electronics and circuits
      • Received Date: 2026-07-26
        Available Online: 2026-09-17

      Catalog

        /

        DownLoad:  Full-Size Img  PowerPoint
        Return
        Return