Mechanisms · category

Off-chip devices & sensors

Retrofittable devices outside the accelerator: network taps and certifiers, power and analog sensors, tamper-evident enclosures.

NameTypeReadinessVerifiesThreat model
Tamper evidence for verifier devices
Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating.
MechanismR2DemonstratedAdversarial prover
Workload classification from telemetry and side channels
Telling whether chips are training, serving or doing non-AI work from GPU counters or power draw, signals that do not read weights or data.
MechanismR2DemonstratedThis compute runs inference, not trainingAdversarial prover
AI 2040 inference-only verification stack
A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs.
ImplementationR1ProposedThis compute runs inference, not trainingAdversarial prover
Bandwidth limits and compartmentalization
Capping or removing the network links between groups of accelerators, so that serving models still works but large training runs become impractically slow.
MechanismR1ProposedCommunication between compute groups is boundedAdversarial prover
Low-trust AI compute verification system overview
A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records.
ImplementationR1ProposedThis compute runs inference, not trainingAdversarial prover
Network taps and certifiers
Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work.
MechanismR1ProposedThis compute runs inference, not trainingAdversarial prover
RAND secure inference data center (SIDC) design
A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.
ImplementationR1ProposedModel weights or data have not left the facilitySemi-trusted prover
SASH confidential network logger
An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference.
ImplementationR1ProposedThis compute runs inference, not trainingSemi-trusted prover
Side-channel suppression for isolated facilities
Shielding, filtering, jamming and inspecting an AI facility so that no hidden physical channel can bypass the checks placed on its official links.
MechanismR1ProposedCommunication between compute groups is boundedAdversarial prover

Includes records that list this as a secondary category.