1 of 25

Doubt and Redundancy Kill Soft Errors �Towards Detection and Correction of Silent Data Corruption in Task-based Numerical Software

Philipp Samfass1, Tobias Weinzierl2, Anne Reinarz2, Michael Bader1

1Technical University of Munich, Germany�2Durham University, UK

This project has received funding from the ExCALIBUR grants ExaClaw (EP/V00154X/1) and the project Exposing Parallelism: Task Parallelism (grant ESA 10 CDEL).

2 of 25

Motivation

  • Decreasing reliability with increasing system scale
  • Undetected soft errors: silent data corruption (SDC)
  • Problem for numerical simulations: SDC hard to spot
  • Replication possible, but typically expensive
  • Non-functional requirements for resilience:
    • Little synchronization
    • Little additional computation and communication
    • Little I/O
    • Little additional memory consumption

2

Reinarz et al.,

Influence of A-Posteriori Subcell Limiting on Fault Frequency in Higher-Order DG Schemes, FTXS ‘18

3 of 25

Context and Research Goal

  • ChEESE flagship code ExaHyPE
  • ExaHyPE:
    • Engine for solving systems of hyperbolic PDEs:
    • Explicit global time stepping on tree-structured adaptive meshes
    • ADER-DG numerical algorithm
    • MPI+TBB parallel, task-based implementation
  • Goal: detect and correct silent errors at as little as possible performance costs

3

4 of 25

Outline and Main Ingredients

  • Transparent process replication (two-fold) as asynchronously running teams with teaMPI1
  • Task-based error criteria: how likely?
  • Task outcome sharing1 between replica ranks
  • Comparisons between „dubious“ and redundantly computed task outcomes

4

TeaMPI‘s logo

1 Samfass et al., TeaMPI—Replication-Based Resilience Without the (Performance) Pain, ISC ‘20

Combine these ingredients

for task-based error detection and correction

without full overhead of redundant computation!

5 of 25

TeaMPI

5

  • PMPI wrapper library for application-transparent replication as teams
  • Teams:
    • Group of ranks
    • Run single application instance
    • Independent of each other
    • No synchronization between teams, no lock-stepping
    • Asynchronous communication between teams for outcome sharing

6 of 25

Task Outcome Sharing

6

7 of 25

Algorithmic framework

  • Independent tasks
  • Yield task outcome for some input data
  • Silent error yields flawed outcome
  • Error criterion :
    • : no error
    • : outcome likely correct
    • : outcome is clearly wrong
    • : is more likely correct

You audience will listen to you or read the content, but won’t do both.

7

8 of 25

Algorithmic framework (cnt’d)

  • Combine multiple error criteria with tolerances
  • Error indicator (boolean): is outcome dubious?
  • Local cache of task outcomes and error criterion values:
    • Buffers task outcomes from other team
    • Buffers local task outcomes until we know they are valid (i.e., no SDC has occurred)

8

9 of 25

Task Execution Control Flow

  • Case 1: matching outcome not available from other team

9

execute

compute error criteria

share

dubious?

check against other outcome and correct

valid

yes

no

10 of 25

Task Execution Control Flow

  • Case 2: matching outcome is available from other team

10

remote outcome dubious

copy and skip computation

valid

execute

compute error criteria

share

check against other outcome and correct

yes

no

11 of 25

Checking and Correcting Task Outcomes

11

outcomes agree

valid

compare error criteria

select and keep more likely outcome

valid

no

yes

12 of 25

Realization in ExaHyPE

  • ADER-DG in a nutshell:
    • Space-time predictor (STP): polynomial solution approximation locally per cell
    • Riemann solves: influence between neighbouring cells
    • Corrector: combines Riemann + STP to new solution
  • Focus on resilience for STP tasks only:
    • Compute-intense
    • Consume bulk part of CPU time
    • Independent tasks
    • Not immediately time-critical

12

13 of 25

Benchmark1: Warm Rising Bubble (Compressible Navier Stokes)

  • Perturbation in the potential temperature field over a background state in hydrostatic balance

13

1 Krenz et al.: A High-Order Discontinuous Galerkin Solver with Dynamic Adaptive Mesh Refinement to Simulate Cloud Formation Processes, PPAM ‘19

14 of 25

Error criteria

  • Arithmetic corruption ( ):
    • Checks for NaN values
    • Boolean criterion
    • Define if outcome contains NaN values
    • otherwise
  • Physical admissibility ( ):
    • Checks for physical plausibility (e.g., negative density)
    • Boolean criterion
    • Define if outcome violates these checks
    • otherwise

14

15 of 25

Error criteria (2)

  • Dubious time step size changes ( ):
    • Time step size depends on maximum eigenvalue
    • Detects drastic changes in time step sizes/eigenvalue

15

16 of 25

Error criteria (3)

  • Solution smoothness ( ):
    • Based on second derivatives in interpolation points

    • Summed up over directions:
    • Large changes are suspicious
    • Can happen “normally” for wave stiffening but is rare

16

17 of 25

Error Indicators & Combination of Error Criteria

  • Rigorous evaluation
    • Computes all criteria
    • Dubious (i.e., ) if any criterion surpasses tolerance

  • Lazy evaluation
    • Evaluate lazily if any of the other “pre-filtering“ criteria are violated
    • Dubious only if at least one pre-filtering criterion and are violated

17

  • Prioritized comparison for selecting more likely outcome

18 of 25

Error Injection

  • Manual error injection for deterministic studies
  • Usually one error per run in random cell and time step
  • Alter one randomly chosen coefficient in Lagrangian polynomial (i.e., in random sample point)
  • Obtain flawed outcome
  • Test different sizes of errors (positive and negative values)
  • Sensitivity = #corrected runs / #total runs

18

19 of 25

Sensitivity

19

20 of 25

Sensitivity

20

21 of 25

Sensitivity

21

22 of 25

Sensitivity – Combined Criteria

22

23 of 25

Performance-Sensitivity Tradeoff

23

24 of 25

Upscaling of Different Configurations

24

25 of 25

Conclusion & Outlook

  • Resilience with task-based error detection and correction
    • Error criteria and indicators
    • Only requires two-fold redundancy
    • Local recovery
    • Replication of data but only partially replicated computations
  • Outlook
    • Offload checking to smart NICs
    • Dynamic tuning of tolerances

25