0x020APhD project · Horizon Europe

NeuroSoC: security assessment of a PCM-based in-memory computing system-on-chip

September 2022 – February 2026 · 42 months · grant agreement 101070634 · 14 partners in nine countries.

What the consortium built

NeuroSoC set out to build a flexible computing system in which an analog in-memory-computing neural processing unit is integrated into a multi-processor, functionally safe and secure system-on-chip. The prototype combines a phase-change-memory (PCM) based analog in-memory computing unit with RISC-V processors in 28 nm FD-SOI technology, targeting more than a hundred-fold gains in energy efficiency and compute density for edge-AI workloads.

Leiden’s part, and mine

Leiden University was responsible for the security assessment of the system-on-chip. That work sat in the same work package as IBM and STMicroelectronics, with ST teams in France and Italy, and the closest day-to-day collaboration on the security task was with STMicroelectronics France. My PhD work covers the physical side of the assessment: what the analog compute tiles and their data converters leak through power consumption, how far model weights can be reconstructed from that leakage, and what this means for protecting machine-learning models on the chip.

  1. 01

    ADC power side-channel analysis of analog in-memory computing tiles

    Built the measurement and analysis pipeline for oscillator-based ADCs, the interface between analog compute tiles and the digital system, and showed that their power traces carry the digital output values.

  2. 02

    Weight extraction with Transformers (TraceFormer)

    Combined a Transformer that maps ADC power traces to output values with an input-controlled weight-isolation technique that exposes one stored weight at a time. Published at Euromicro DSD 2025.

  3. 03

    Power traces as transferable knowledge (P2W)

    Showed that power traces captured from an embedded SoC can be translated into an approximate weight matrix that gives a new model a head start when training data is scarce. Published at ACM SAC 2026.

  4. 04

    Security of distributed CNN inference at the edge

    Co-authored an evaluation of how CNN partitioning strategies expose input data to an eavesdropper on the link between edge devices. Published at SPACE 2025.

Publications from the project

The project in three minutes

Official NeuroSoC video. It loads from YouTube only when you press play.

Consortium

14 beneficiaries, listed as on the project website. The security assessment was Leiden University’s responsibility; security assessment work package, shared with IBM and STMicroelectronics (France and Italy). Closest collaboration on the security task: STMicroelectronics France.

Industry

  • IBM
  • STMicroelectronics
  • Bosch
  • Thales
  • Ubotica
  • Benkei
  • Software Competence Center Hagenberg (SCCH)

Academia

  • ETH Zurich
  • Leiden University
  • University of Bologna
  • University of Patras
  • University of Pavia
  • King's College London
  • Northeastern University London

Timeline

  1. Sept 2022Project start (42-month Horizon Europe action)
  2. Nov 2022Joined Leiden University as PhD candidate on the security work package
  3. Feb 2025P2W preprint released on arXiv
  4. Sept 2025TraceFormer presented at Euromicro DSD, Salerno
  5. Dec 2025CNN partitioning security study presented at SPACE, Guwahati
  6. Feb 2026Project end
  7. Mar 2026P2W presented at ACM SAC, Thessaloniki