REVIEW 3 major objections 5 minor 29 references
New Security Challenges Towards In-Sensor Computing Systems
T0 review · 3 major / 5 minor · reviewed 2026-08-08 · deepseek-v4-flash
Pith's one-line read This paper claims that in-sensor computing systems, by fusing sensing and computation, create new hardware security threats at board, chip, and device levels that existing digital defenses cannot catch.
desk verdict A useful first security taxonomy for in-sensor computing, but the two demos overclaim what they prove; the qualitative analysis deserves a referee. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is a three-level attack-surface decomposition of ISC systems — board, chip, and device — keyed to how sensing and computation are integrated. At each level the paper identifies what an attacker must know and what tools are needed: board-level attacks exploit the analog link between sensor and computation and the sensor's sensitivity to its environment; chip-level attacks target vertical interconnects and untrusted 3D-integration entities; device-level attacks require full understanding of the sensing material and are the hardest to detect. A comparison table against traditional sensor-involved computing carries the argument that ISC trades easier access for harder detection. The demos provide the physical anchors: a double-gate ferroelectric tunnel FET gustatory sensor shows a counterfeit-oxide-induced shift in the current-voltage characteristic that produces a wrong recognition output, and an optical sensor wired to an external classification model shows light-induced interference flipping the predicted emotion.
What would settle it
Replace the external classifier in Demo 2 with an in-sensor implementation of the same emotion-recognition function, keep the same low-cost light-controlled circuit, and compare output labels under identical illumination. If the label does not flip, the demo does not establish the board-level ISC attack.
Extended reading notes
Core claim
On its own terms, the paper's central claim is that in-sensor computing systems have a distinct security profile: compared with traditional sensor-involved computing, ISC reduces remote accessibility but demands more attacker knowledge, more customized tools, and makes attacks harder to detect. Because an ISC system's sensing and computing behavior is fixed by material properties and device mechanisms, the design and modeling stage becomes security-critical; a malicious foundry can tamper with both analog and digital parts, and counterfeit materials can shift device characteristics in ways that surface only after full data processing. At board level, environmental interference and analog-format side channels attack sensor data before digitization; at chip level, 3D-stacked interconnects create new fault-injection points; at device level, customized counterfeit attacks need full sensor knowledge and are hard to diagnose for lack of probing locations. The two demos are offered as evidence that these attacks are physically realizable and as starting points for countermeasure design.
Load-bearing premise
The second demo's setup is a conventional sensor plus external classifier, not a true in-sensor computing system; the paper's board-level attack claim rests on the assumption that the observed interference transfers to systems where computation happens inside the sensor.
Editorial extensions
If this is right
- If the paper's analysis is right, ISC design flows must treat the material and device modeling phase as a security stage, because a tampered material changes every result the device will ever produce.
- Existing digital countermeasures — probing, authentication, and validation tools — will not transfer cleanly to ISC because analog fault signals can look like sensor noise and there are few intermediate checkpoints.
- Health-monitoring ISC devices deployed in public places will need lightweight integrity checks that work without probing individual sensing elements.
- The comparison predicts a security trade-off: deeper integration shrinks the remotely accessible attack surface but pushes attacks toward physical, customized, hard-to-detect forms.
Reading between the lines
- If the trend holds, the strongest countermeasures will use the sensing physics itself — for example, fingerprinting material response or treating the sensor's characteristic curve as a tamper-evident seal — since digital authentication has no natural anchor in a fused analog device.
- A direct testable extension is to measure detection latency for a deliberately inserted counterfeit ferroelectric layer in a true device-level ISC versus an equivalent traditional chain; the paper's delayed-detection claim predicts a measurable lag.
- The board-level demo implies a broader statement the authors do not make: any system that trusts an unauthenticated analog sensor-to-computation link, ISC or not, is open to low-cost environmental manipulation; ISC matters because it deliberately removes the digitization that would otherwise bound the attack.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper surveys in-sensor computing (ISC) research, argues that ISC systems introduce new hardware security challenges at board, chip, and device levels, contrasts these with traditional sensor-involved computing (TSC), and presents two proof-of-concept demos: a counterfeit attack on a ferroelectric tunnel FET (FET) based gustatory system and an environmental interference attack on an optical sensor-based emotion recognition system. The paper claims to be the first work to analyze security challenges in ISC systems and to compare TSC and ISC security.
Significance. If the analysis is supported, the paper would make a useful contribution by systematically categorizing ISC attack surfaces and motivating countermeasure research. The structured literature review and the three-level attack taxonomy are valuable framing devices, and the paper identifies plausible threat vectors, such as analog side-channel leakage and counterfeit device-level attacks. However, the empirical substantiation is currently weak: Demo 2 does not actually implement in-sensor computation, and Demo 1 is only a conceptual simulation without quantitative results. The paper is best read as a position paper that outlines potential threats rather than a validated experimental study.
major comments (3)
- [Section IV.B and Fig. 8] Demo 2 does not implement an in-sensor computing system as defined in Section I. The setup uses a conventional CMOS sensor (OV7670) transmitting image data over a serial data bus to an external Py-Feat classifier, which is a traditional sensor-involved computing (TSC) configuration, not ISC. Since no computation occurs inside the sensor and no TSC baseline is provided, the experiment cannot establish that ISC systems are uniquely vulnerable to environmental interference at the board level, nor that the attack is new to ISC. This invalidates one of the two proof-of-concept demonstrations and weakens the central claim that the demos inspire countermeasures against unique ISC hardware security threats.
- [Section IV.A and Fig. 7] Demo 1 is described only qualitatively: the I-V characteristic change and the resulting detection output offset are depicted in Fig. 7(c) and (d) without any numerical data, simulation results, error bars, or repeatability metrics. The claim that a small change in FE-oxide thickness in a counterfeit device leads to a wrong biomolecule recognition is therefore unsupported. As this is the only demonstration of the device-level counterfeit attack, the empirical basis for that attack surface is not established.
- [Section III.A and Table I] The entries in Table I, such as 'ISC attacks require full knowledge of the entire system' and 'attack detection is complicated', are presented as established facts but are not derived from the demos or a systematic analysis. Some entries conflate limited accessibility with requiring full knowledge, and the threat models differ substantially across board-, chip-, and device-level ISC. The paper should present these comparisons explicitly as hypotheses or support them with concrete case studies and a defined attacker model.
minor comments (5)
- [Abstract and Section I] The claim 'to the best of our knowledge, this is the first work that analyzes security challenges in ISC systems' is stated twice without a systematic search of security literature in adjacent paradigms such as processing-in-memory, analog computing, or sensor security; please temper the claim to 'to our knowledge' and describe the search criteria.
- [Section IV.B and VI] The phrase 'proof-the-concept' appears twice and should be corrected to 'proof-of-concept'.
- [Figure 2] The y-axis of the 'historical progress' chart is not labeled; please clarify whether the chart plots cumulative publication counts or a different metric, and describe the search and selection methodology for the literature data in Fig. 3.
- [Reference [28]] Reference [28] is formatted as 'I. OmniVision Technologies'; the correct style is 'OmniVision Technologies' without the initial.
- [Section III.B.1] The sentence 'analog signals may reveal more details than the digital format since analog signals have frequency, magnitude, and phase' is unclear because digital signals also carry these properties; please specify which physical attributes of the analog sensor output are measurably more informative to an attacker.
Circularity Check
No circularity: the attack-surface analysis is reasoned from the ISC architecture and the demos are illustrative, not fitted predictions.
full rationale
The paper does not derive any result from fitted parameters, nor does it rename empirical patterns as predictions. The attack scenarios at board, chip, and device level are reasoned from the defining features of in-sensor computing (e.g., analog or semi-analog signals, lack of probing points, and tight integration). The two demos are presented as proof-of-concept illustrations, not as statistical predictions: Demo 1 assumes a counterfeit material change and then shows its simulated effect on I-V and frequency, while Demo 2 shows that an environmental interference circuit can alter an external classifier's output. Neither demo's conclusion is forced by construction from a fit. The authors' self-citations ([2], [5], [6]) appear only as background on wearable sensors and prior sensor-security work; the central security analysis does not depend on those citations being true. One validity concern is that Demo 2 uses a conventional CMOS sensor with an external Py-Feat model, which is not an in-sensor computing configuration; however, that is an external-validity or correctness issue, not a circularity pattern, because the paper does not claim the demo's output is predicted from a fitted model or from a self-cited theorem. Overall, the derivation chain is self-contained and non-circular.
Assumptions & free parameters
assumptions (3)
- domain assumption ISC systems integrate sensing, memory, and computation into one compact unit, with less ADC and data transmission.
- domain assumption The security categories used for traditional systems (fault attacks, side-channel, Trojan, counterfeit) apply to ISC.
- domain assumption The demos' physical setups (FE-oxide thickness change, photo-resistor bus interference) reflect plausible ISC implementation scenarios.
Cite this review
Pith. "Pith review of New Security Challenges Towards In-Sensor Computing Systems." pith.science (2026). https://pith.science/paper/KDFRY3MD
@misc{pith2026250205046,
author = {Pith},
title = {Pith review of: New Security Challenges Towards In-Sensor Computing Systems},
year = {2026},
howpublished = {\url{https://pith.science/paper/KDFRY3MD}},
note = {Machine review of arXiv:2502.05046}
}
read the original abstract
Data collection and processing in advanced health monitoring systems are experiencing revolutionary change. In-Sensor Computing (ISC) systems emerge as a promising alternative to save energy on massive data transmission, analog-to-digital conversion, and ineffective processing. While the new paradigm shift of ISC systems gains increasing attention, the highly compacted systems could incur new challenges from a hardware security perspective. This work first conducts a literature review to highlight the research trend of this topic and then performs comprehensive analyses on the root of security challenges. This is the first work that compares the security challenges of traditional sensor-involved computing systems and emerging ISC systems. Furthermore, new attack scenarios are predicted for board-, chip-, and device-level ISC systems. Two proof-of-concept demos are provided to inspire new countermeasure designs against unique hardware security threats in ISC systems.
Figures
Figures from the paper (4 more)
Reference graph
Works this paper leans on
-
[1]
The emergence of ai-based wearable sensors for digital health technology: A review,
S. Shajari, K. Kuruvinashetti, A. Komeili, and U. Sundararaj, “The emergence of ai-based wearable sensors for digital health technology: A review,” Sensors, vol. 23, no. 23, 2023
work page 2023
-
[2]
Feature- driven approximate computing for wearable health-monitoring systems,
N. Chennagouni, M. Kajol, D. Chen, D. Xu, and Q. Y u, “Feature- driven approximate computing for wearable health-monitoring systems,” in Proceedings of the Great Lakes Symposium on VLSI 2024 , GLSVLSI ’24, (New Y ork, NY , USA), p. 712–717, Association for Computing Machinery, 2024
work page 2024
-
[3]
Wearable sensors for telehealth based on emerging materials and nanoarchitecton- ics,
J. V . V aghasiya, C. C. Mayorga-Martinez, and M. Pumera, “Wearable sensors for telehealth based on emerging materials and nanoarchitecton- ics,” Npj Flexible Electronics , vol. 7, June 2023
work page 2023
-
[4]
Progress and challenges in fabrication of wearable sensors for health monitoring,
S. Nasiri and M. R. Khosravani, “Progress and challenges in fabrication of wearable sensors for health monitoring,” Sensors and Actuators A: Physical, vol. 312, p. 112105, 2020
work page 2020
-
[5]
Attack-resilient temperature sensor design,
M. A. Kajol and Q. Y u, “Attack-resilient temperature sensor design,” in 2023 IEEE International Symposium on Circuits and Systems (ISCAS) , pp. 1–5, 2023
work page 2023
-
[6]
A circuit-level solution for secure temperature sensor,
M. A. Kajol, M. M. R. Monjur, and Q. Y u, “A circuit-level solution for secure temperature sensor,” Sensors, vol. 23, no. 12, 2023
work page 2023
-
[7]
In-sensor visual perception and inference,
Y . Liu, R. Fan, J. Guo, H. Ni, and M. U. M. Bhutta, “In-sensor visual perception and inference,” Intelligent Computing , vol. 2, p. 0043, 2023
work page 2023
-
[8]
Analog circuit implementation of neural networks for in-sensor computing,
J. Zhu, B. Chen, Z. Y ang, L. Meng, and T. T. Y e, “Analog circuit implementation of neural networks for in-sensor computing,” in 2021 IEEE Computer Society Annual Symposium on VLSI (ISVLSI) , pp. 150– 156, 2021
work page 2021
Show all 29 references
-
[9]
In-sensor computing: Materials, devices, and integration technologies,
T. Wan, B. Shao, S. Ma, Y . Zhou, Q. Li, and Y . Chai, “In-sensor computing: Materials, devices, and integration technologies,” Advanced Materials, vol. 35, no. 37, p. 2203830, 2023
2023
-
[10]
Halide perovskite pho- tovoltaics for in-sensor reservoir computing,
D. Sharma, A. Luqman, S. E. Ng, N. Y antara, X. Xing, Y . B. Tay, A. Basu, A. Chattopadhyay, and N. Mathews, “Halide perovskite pho- tovoltaics for in-sensor reservoir computing,” Nano Energy , vol. 129, p. 109949, 2024
2024
-
[11]
Sensor networks for emergency response: challenges and opportunities,
K. Lorincz, D. Malan, T. Fulford-Jones, A. Nawoj, A. Clavel, V . Shnay- der, G. Mainland, M. Welsh, and S. Moulton, “Sensor networks for emergency response: challenges and opportunities,” IEEE Pervasive Computing, vol. 3, no. 4, pp. 16–23, 2004
2004
-
[12]
In- sensor neuromorphic computing using perovskites and transition metal dichalcogenides,
S.-Y . Li, J.-T. Li, K. Zhou, Y . Y an, G. Ding, S.-T. Han, and Y . Zhou, “In- sensor neuromorphic computing using perovskites and transition metal dichalcogenides,” Journal of Physics: Materials , vol. 7, p. 032002, jun 2024
2024
-
[13]
3-d in- sensor computing for real-time dvs data compression: 65-nm hardware- algorithm co-design,
G. R. Nair, P . S. Nalla, G. Krishnan, Anupreetham, J. Oh, A. Hassan, I. Y eo, K. Kasichainula, M. Seok, J.-S. Seo, and Y . Cao, “3-d in- sensor computing for real-time dvs data compression: 65-nm hardware- algorithm co-design,” IEEE Solid-State Circuits Letters , vol. 7, pp. ...
2024
-
[14]
Advances in silicon-based in-sensor computing for neuromorphic vision sensors,
Y . Liu, R. Fan, X. Wang, J. Hu, R. Ma, and Z. Zhu, “Advances in silicon-based in-sensor computing for neuromorphic vision sensors,” Microelectronics Journal, vol. 134, p. 105737, 2023
2023
-
[15]
In-sensor neuromorphic computing are all you need for energy efficient computer vision,
G. Datta, Z. Liu, M. A.-A. Kaiser, S. Kundu, J. Mathai, Z. Yin, A. P . Jacob, A. R. Jaiswal, and P . A. Beerel, “In-sensor neuromorphic computing are all you need for energy efficient computer vision,” in ICASSP 2023 - 2023 IEEE International Conference on Acoustics, Speech and...
2023
-
[16]
Pisa: A non- volatile processing-in-sensor accelerator for imaging systems,
S. Angizi, S. Tabrizchi, D. Z. Pan, and A. Roohi, “Pisa: A non- volatile processing-in-sensor accelerator for imaging systems,” IEEE Transactions on Emerging Topics in Computing , vol. 11, no. 4, pp. 962– 972, 2023
2023
-
[17]
Towards an efficient cnn inference architecture enabling in-sensor processing,
M. J. H. Pantho, P . Bhowmik, and C. Bobda, “Towards an efficient cnn inference architecture enabling in-sensor processing,” Sensors, vol. 21, no. 6, 2021
2021
-
[18]
Wear- able in-sensor reservoir computing using optoelectronic polymers with through-space charge-transport characteristics for multi-task learning,
X. Wu, S. Wang, W. Huang, Y . Dong, Z. Wang, and W. Huang, “Wear- able in-sensor reservoir computing using optoelectronic polymers with through-space charge-transport characteristics for multi-task learning,” Nature Communications , vol. 14, Jan 2023
2023
-
[19]
Invited paper: Learned in-sensor visual computing: From compression to eventifica- tion,
Y . Feng, T. Ma, A. Boloor, Y . Zhu, and X. Zhang, “Invited paper: Learned in-sensor visual computing: From compression to eventifica- tion,” in 2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD) , pp. 1–9, 2023
2023
-
[20]
Noise analysis of readout chain in fdsoi-based 1t-aps for in-sensor vector-matrix-multiplication,
Y . Xiao, Z. Zhou, Y . Wang, J. Li, G. Y u, S. Li, H. Y ang, L. Han, R. Chen, X. Liu, J. Kang, and P . Huang, “Noise analysis of readout chain in fdsoi-based 1t-aps for in-sensor vector-matrix-multiplication,” in 2024 8th IEEE Electron Devices Technology Manufacturing Conferen...
2024
-
[21]
Retinomorphic hardware for in-sensor computing,
G. Feng, X. Zhang, B. Tian, and C. Duan, “Retinomorphic hardware for in-sensor computing,” InfoMat, vol. 5, no. 9, p. e12473, 2023
2023
-
[22]
In-sensor reservoir computing for language learning via two-dimensional memristors,
L. Sun, Z. Wang, J. Jiang, Y . Kim, B. Joo, S. Zheng, S. Lee, W. J. Y u, B.-S. Kong, and H. Y ang, “In-sensor reservoir computing for language learning via two-dimensional memristors,” Science Advances , vol. 7, no. 20, p. eabg1455, 2021
2021
-
[23]
Neural networks based on in-sensor computing of optoelectronic memristor,
Z. Zhang, Q. Wang, G. Shi, Y . Ma, J. Zeng, and G. Liu, “Neural networks based on in-sensor computing of optoelectronic memristor,” Microelectronic Engineering, vol. 291, p. 112201, 2024
2024
-
[24]
Design of optoelectronic in-sensor computing circuit based on memristive crossbar array for in situ edge extraction,
J. Zhang, X. Li, P . Xiao, Z. Wei, and Q. Hong, “Design of optoelectronic in-sensor computing circuit based on memristive crossbar array for in situ edge extraction,” IEEE Transactions on Circuits and Systems I: Regular Papers, vol. 71, no. 7, pp. 3228–3241, 2024
2024
-
[25]
A vital-signs monitoring wristband with real-time in-sensor data analysis using very low-hardware resources,
Q. Mascret, D. Gurve, A. Abdou, S. Bhadra, N. Lasry, K. Mai, S. Krishnan, and B. Gosselin, “A vital-signs monitoring wristband with real-time in-sensor data analysis using very low-hardware resources,” IEEE Sensors Journal , vol. 24, no. 11, pp. 18392–18404, 2024
2024
-
[26]
Low-power anomaly detection and classification system based on a partially binarized autoencoder for in-sensor computing,
P . Vitolo, G. D. Licciardo, L. di Benedetto, R. Liguori, A. Rubino, and D. Pau, “Low-power anomaly detection and classification system based on a partially binarized autoencoder for in-sensor computing,” in 2021 28th IEEE International Conference on Electronics, Circuits, and ...
2021
-
[27]
Energy efficient artificial gustatory system for in-sensor computing,
M. A. Khanday, S. Rashid, and F. A. Khanday, “Energy efficient artificial gustatory system for in-sensor computing,” Micro and Nanostructures , vol. 191, p. 207870, 2024
2024
-
[28]
OmniVision Technologies, OV7670/OV7171 CMOS VGA (OmniPixel) CameraChip Sensor with OmniPixel Technology
I. OmniVision Technologies, OV7670/OV7171 CMOS VGA (OmniPixel) CameraChip Sensor with OmniPixel Technology . OmniVision Technolo- gies, July 2006
2006
-
[29]
Py-feat: Python facial expression analysis toolbox,
J. H. Cheong, E. Jolly, T. Xie, S. Byrne, M. Kenney, and L. Chang, “Py-feat: Python facial expression analysis toolbox,” Affective Science , vol. 4, 08 2023
2023
Reviewed August 8, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.