Communication between compute groups is bounded
On this page
Sources
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: pods with high internal and very low external bandwidth; enough for inference tokens not training gradients; implementable with modest changes, physical access and monitoring, without code access · Interconnect bandwidth limits
- BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source recordSupports: compute caps via physical limits on chip-to-chip networking; decentralised training could undermine detectability · enforcement; §3.B.1 Detectability
- BA. Douillard et al. (2024). DiLoCo: Distributed Low-Communication Training of Language Models. ICML 2024 Workshop on Advancing Neural Network Training (WANT). Source recordSupports: DiLoCo on 8 workers matched fully synchronous training while communicating 500 times less · abstract
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: fixed-set HEM restricting networking of small GPU sets · p. viii
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: front-end vs back-end bandwidth; inference bandwidth assumption; covert side-channel target in kilobits per second; egress explainable by ingress · inference vs training; open problems
- CN. Cankaya (2026). The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use. The Datacenter Lie Detector. Source recordSupports: front-end vs back-end tapping costs and feasibility; copper links and scale-up domains; encrypted interconnect · frontend vs backend; open problems
- CN. Cankaya (2026). Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses. MIRI Technical Governance Team. Source recordSupports: physical side channels can bypass network monitoring; defences; tolerable low rate · channels of concern; defences
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: retroactively confirming data-centre topology is beyond scope · open problems
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: network taps intercepting inter-chip data · §4.2
- CR. Dean (2026). Verification Plan. AI 2040. Source recordSupports: removing back-end networking to create isolated inference units · verification mechanisms
- CLucid Computing (2026). Traffic Shaping for Workload Classification. Lucid Computing (Substack). Source recordSupports: pod-level traffic cap design; not yet implemented or red-teamed · summary; status
- CAmodo Design (2026). The Tray as a Bandwidth Boundary. Amodo Design. Source recordSupports: DPU-enforced rate limiting on 400G links for weight security, with the limits set by a trusted operator's controller · whole note
- CA. Scher et al. (2026). De-risking Interconnect Limits for AI Verification. MIRI Technical Governance Team. Source recordSupports: software bandwidth-monitor prototype on AI GPUs; authors say operator-controlled measurements are trivially spoofable · Abstract; Pros and Cons analysis
- BR. Rinberg et al. (2026). Haiku to Opus in Just 10 bits: LLMs Unlock Large Compression Gains. arXiv. Source recordSupports: egress limits cap what can be stolen · §5.1
- AW. Cai et al. (2025). Shortcut-connected Expert Parallelism for Accelerating Mixture of Experts. ICML 2025, Proceedings of Machine Learning Research 267. Source recordSupports: expert-parallel MoE inference can require cross-device all-to-all communication · abstract