🤖 AI Summary
This work addresses the security threat posed by DRAM read disturbance effects—such as RowHammer and RowPress—which can induce bit flips in non-target rows. While existing device-level models struggle to accurately explain experimental observations, this study systematically investigates three key metrics: bit-flip polarity, count, and activation-count threshold (ACmin). Through a comparative analysis of TCAD simulations and empirical measurements, the authors uncover significant inconsistencies between current models and real-world data, propose a more accurate physical error mechanism, and identify critical parameters governing simulation fidelity. The refined model successfully reproduces RowHammer and RowPress behaviors observed in actual DRAM chips, thereby establishing a solid theoretical foundation for efficient characterization methodologies and robust mitigation strategies.
📝 Abstract
DRAM read disturbance, like RowHammer and RowPress, is a critical robustness issue where accessing DRAM can cause unintended bitflips in other unaccessed DRAM locations. DRAM read disturbance bitflips significantly impact the safe, secure, and reliable operation of DRAM-based computing systems. Many prior works experimentally characterize these bitflips and propose mitigations based on empirical results. Other device-level works study their underlying physical mechanisms, but these mechanisms do not fully explain all major empirical observations.
Our goal is to bridge the gap between experimental characterization and device-level modeling and understanding of RowHammer and RowPress, providing a principled foundation for future work on understanding, characterizing, and mitigating DRAM read disturbance. We first identify and demonstrate gaps and inconsistencies between the physical mechanisms of RowHammer and RowPress described by existing device-level models and experimental characterization of their bitflips. We focus on three fundamental metrics that should map to first-order physical mechanisms: 1) bitflip directions, 2) bitflip counts, and 3) the minimum number of aggressor row activations that trigger the first bitflips (i.e., ACmin). Second, we present a comprehensive and rigorous set of TCAD simulations that match phenomena observed in experimental characterizations of RowHammer and RowPress bitflips.
From our results, we 1) summarize updated device-level error mechanisms for understanding RowHammer and RowPress bitflips, and 2) identify key modeling and simulation parameters that significantly affect whether simulation results match real-chip characterization. We discuss implications for 1) rigorous, comprehensive, and efficient experimental characterization methodologies of DRAM read disturbance bitflips, and 2) the design of DRAM read disturbance mitigation techniques.