
Single-pass argmax / top-k / sample decode sampler turning transformer logits into a token for on-device edge-AI inference, ASIL-B. It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
lm_head is the LLM final-projection / logits stage (#A-6) — the decode sampler that turns a transformer’s output logit vector into the next emitted token for on-device edge-AI inference.
AMBA AXI4-Stream logit ingress; APB4-lite control/status slave; ISO 26262 ASIL-B SEooC (SPFM 96.19%, LFM 100.00%, PMHF 4.96×10⁻⁹/h)
ASIL-B target (SEooC) · SPFM 96.19% · LFM 100.00% · Informational — not gated
Informational FMEDA — this IP is reported but NOT gated. The SPFM/LFM figures above are engineering estimates from a model that is not held to the ASIL metric gates (QM, safety-by-composition, a vendor-core overlay, or a pre-sign-off Technology Preview, depending on the IP). They are not a certification claim and must not be relied on as one. See the safety manual for this IP’s exact status, assumptions of use, and any open items.
ISO 26262:2018 · FMEDA available · Safety Manual included
| Offset | Register | Description |
|---|---|---|
0x00 | CTRL | RW [0]=EN, [2:1]=MODE (0 argmax/1 topk/2 sample), [7:3]=K (1..MAXK) |
0x04 | TEMP | RW [3:0]=TEMP_LOG2 (temperature = 2^TEMP_LOG2; 0 = no scaling) |
0x08 | SEED | RW [31:0] LFSR seed for SAMPLE mode (nonzero; reloaded at vector start) |
0x0C | STATUS | RO [0]=DONE, [1]=CFG_ERR, [2]=MAX_ERR, [3]=FSM_ERR, [4]=ERR_VALID, [8:5]=ERR_CODE |
0x10 | TOKEN | RO [LOGIDX_W-1:0] emitted token index (valid when DONE) |
…3 more registers — see datasheet for the full table.
// Minimal instantiation
lm_head #(
.ADDR_W(6)
) u_lm_head (
.clk (clk),
.rst_n (rst_n),
// APB4
.p_paddr (paddr),
.p_psel (psel),
.p_penable (penable),
.p_pwrite (pwrite),
.p_pwdata (pwdata),
.p_prdata (prdata),
.p_pready (pready),
// Safety
.err_clear (1'b0),
.err_valid (err_valid),
.err_code (err_code)
);Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Typically deployed in safety-critical edge inference — ADAS, autonomous robotics, and machine vision.
Pricing, the per-IP FMEDA, safety manual, and RTL data room are shared under a mutual NDA.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.
circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space