Author ORCID Identifier

0009-0000-9932-1733

Document Type

Dissertation

Date of Award

5-31-2026

Degree Name

Doctor of Philosophy in Electrical Engineering - (Ph.D.)

Department

Electrical and Computer Engineering

First Advisor

Shaahin Angizi

Second Advisor

Durgamadhab Misra

Third Advisor

Ghosh Arnob

Fourth Advisor

Philip Pong

Fifth Advisor

Adnan Siraj Rakin

Abstract

Dynamic Random-Access Memory (DRAM) is both the performance bottleneck and a critical security boundary of modern computing systems. Its physical properties make it an attractive substrate for near-data computation—yet those same properties expose it to disturbance-based hardware attacks. This dissertation argues that these two dimensions are not independent: the architectural choices that make DRAM efficient also reshape its threat landscape. Addressing both requires a unified approach to memory architecture and security co-design.

The first part of this dissertation attacks the memory wall through four processing-in-DRAM (PIM) frameworks. ReD-LUT and LT-PIM unify lookup-table arithmetic with charge-sharing logic, achieving up to 37.8x speedup over CPU baselines on quantized DNN inference while embedding RowHammer self-tracking directly into existing DRAM primitives. FlexiDRAM and P-PIM generalize in-DRAM computation to arbitrary Boolean logic, with P-PIM delivering 72% higher energy efficiency than the fastest prior charge-sharing design and sub-1% worst-case performance overhead.

The second part establishes that PIM deployment fundamentally reshapes the RowHammer threat. Elevating row activation into an architectural execution primitive creates activation hot spots far denser than those in conventional workloads—making RowHammer a first-class PIM design concern, not merely an external threat.

The third part develops advanced hardware attacks against deployed AI systems. RowPress, a temporal disturbance mechanism exploiting prolonged row activation, induces up to 20 x more bit flips than RowHammer and requires 3.6 x fewer faults to compromise DNN accuracy. Deep-PTA introduces the first page-table-targeted weight-replacement attack: a single bit-flip in a page frame number silently redirects 128 consecutive weight parameters to an adversary-controlled row, collapsing DNN accuracy 42 x more efficiently than prior attacks while bypassing all weight-level integrity defenses. LLWRA extends this primitive to Large Language Models, reducing billion-parameter models to incoherence in fewer than nine hardware iterations.

The fourth part closes the loop with defenses embedded directly in the memory substrate. DNN-Defender's priority-aware row-swap mechanism raises the cost of a white-box attack to approximately 1,180 days without accuracy loss or retraining overhead. DRAM-Locker provides the first comprehensive defense against both direct bit-flip and page-table-based weight replacement attacks. EIM-TRNG inverts the RowHammer threat entirely, harvesting the non-determinism of metastable DRAM cells to generate one-time 256-bit encryption keys embedded within DNN weight storage—rendering stolen weights computationally indistinguishable from random noise without exposing any key material in accessible memory.

Together, these contributions reframe DRAM as a physically rich substrate that can be simultaneously exploited for efficient computation, targeted by sophisticated hardware adversaries, and secured through principled co-design. This dissertation provides a unified framework for understanding the memory—security interface and lays architectural foundations for the next generation of efficient, secure, and intelligent memory-centric computing systems.

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.