WEBVTT

1
00:00:00.000 --> 00:00:03.407
A simulated fault target has engineering
value only when it

2
00:00:03.407 --> 00:00:04.882
maps to physical behavior.

3
00:00:04.882 --> 00:00:09.026
Calibration is not tuning RTL parameters
until a fault “looks successful”;

4
00:00:09.026 --> 00:00:12.302
it compares target, window, effect,
repeatability, and residual

5
00:00:12.302 --> 00:00:14.467
mismatch against traceable measurements.

6
00:00:14.467 --> 00:00:18.694
A clinical thermometer needs comparison
against a traceable standard;

7
00:00:18.694 --> 00:00:20.765
smooth readings do not prove accuracy.

8
00:00:20.765 --> 00:00:26.344
Voltage/clock glitches, laser, or EM
injection likewise require instrument

9
00:00:26.344 --> 00:00:31.210
settings, probe/location,
voltage/temperature, trigger timing, chip

10
00:00:31.210 --> 00:00:32.779
revision, and repeats.

11
00:00:32.779 --> 00:00:38.104
The analogy motivates traceability; it does
not claim any injection method necessarily

12
00:00:38.104 --> 00:00:40.096
causes a particular RTL flip.

13
00:00:40.375 --> 00:00:46.437
Classify physical outcomes as invalidated,
reset, skipped, delayed, corrupted data,

14
00:00:46.437 --> 00:00:50.240
checker alert, permanent damage, or no
observed effect.

15
00:00:50.240 --> 00:00:55.993
Map them conditionally to the digital model:
under settings X, location Y, and window Z,

16
00:00:55.993 --> 00:00:59.248
estimate the frequency and interval for each
effect.

17
00:00:59.248 --> 00:01:03.155
One successful attempt does not imply a
deterministic bit flip.

18
00:01:03.155 --> 00:01:08.448
Place measurements and models in a layered
table: physical stimulus, observable chip

19
00:01:08.448 --> 00:01:10.995
response, netlist effect, RTL abstraction.

20
00:01:10.995 --> 00:01:14.347
Report sample count, misses,
non-repeatability, spatial

21
00:01:14.347 --> 00:01:16.626
resolution, and confidence intervals.

22
00:01:16.626 --> 00:01:22.479
If the setup sees only reset and not
internal nodes, mark that observability

23
00:01:22.479 --> 00:01:26.067
limit; do not infer an internal state
change.

24
00:01:26.333 --> 00:01:29.384
Separate calibration and validation sets.

25
00:01:29.384 --> 00:01:34.855
Estimate the model on one set and check
predictive coverage on independent windows;

26
00:01:34.855 --> 00:01:38.169
stratify by chip, lot, environment, and
revision.

27
00:01:38.169 --> 00:01:41.482
Do not extrapolate to untested locations or
tools.

28
00:01:41.482 --> 00:01:46.586
The interactive page compares synthetic
observations and model predictions.

29
00:01:46.586 --> 00:01:48.902
It contains no physical measurements.

30
00:01:48.902 --> 00:01:53.622
Compare physical outcomes with model
predictions using a confusion matrix,

31
00:01:53.622 --> 00:01:58.140
especially false negatives: effects seen
physically but absent from the model.

32
00:01:58.140 --> 00:02:01.397
Version and hash every revision, then rerun
the campaign.

33
00:02:01.397 --> 00:02:05.003
Conclusions cover only the calibration
domain;

34
00:02:05.003 --> 00:02:09.653
few samples or zero observations do not make
an event impossible.

35
00:02:09.917 --> 00:02:15.778
Calibration should state the conditions
under which a model represents measurements.

36
00:02:15.778 --> 00:02:21.746
For every physical attempt, record stimulus
settings, location, timing, environment, and

37
00:02:21.746 --> 00:02:26.720
chip revision, then record the response that
the setup can actually observe.

38
00:02:26.720 --> 00:02:30.613
If internal nodes are hidden, mark them
unknown;

39
00:02:30.613 --> 00:02:35.470
a reset response does not prove that a
particular register flipped.

40
00:02:35.470 --> 00:02:41.434
Fit the mapping on one sample set and check
it on independent samples, stratified by

41
00:02:41.434 --> 00:02:43.479
chip, lot, and environment.

42
00:02:43.479 --> 00:02:48.762
Keep false negatives visible in the
confusion matrix: effects observed

43
00:02:48.762 --> 00:02:54.285
physically but omitted by the model can make
a later campaign look safer than it is.

44
00:02:54.285 --> 00:02:57.917
Conclusions stay inside the calibrated
domain.

45
00:02:58.167 --> 00:03:02.429
A physical campaign records traceable
stimulus settings and chip responses.

46
00:03:02.429 --> 00:03:05.629
Digital targets and effects remain
calibration hypotheses.

47
00:03:05.629 --> 00:03:08.337
One hit does not establish a deterministic
bit flip.

48
00:03:08.337 --> 00:03:13.299
Without observing an internal node, do not
infer that a particular register changed.

49
00:03:13.299 --> 00:03:16.087
Map effects by layer and retain misses and
unknowns.

50
00:03:16.087 --> 00:03:19.699
Check model predictions on independent data
and report intervals.

51
00:03:19.699 --> 00:03:24.335
Preserve sample and location records with
timing, environment, revision, and

52
00:03:24.335 --> 00:03:29.014
instrument settings. Keep false negatives in
the confusion matrix and hash every model

53
00:03:29.014 --> 00:03:32.113
revision. Conclusions cover only the
calibrated domain.

54
00:03:32.113 --> 00:03:41.629
Small samples, hidden internal nodes, and
other dies, packages, or tools limit

55
00:03:41.629 --> 00:03:49.657
extrapolation. Record analog coupling and
unmodeled faults as well.

56
00:03:49.657 --> 00:03:56.733
Choose one out-of-model effect and define a
new test stratum.

57
00:03:56.733 --> 00:04:00.104
Which sensing method and samples would
support adding it?

58
00:04:00.104 --> 00:04:04.349
If new data exposes a missed effect, retain
it as unknown before updating the model.

59
00:04:04.349 --> 00:04:09.187
State the physical conditions covered by
calibration whenever you present the result.
