# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-09. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0016,M-0020&implementations=M-0016:I-0018

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's development status, security evidence and findings. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and findings) and https://trustbutveri.fyi/about/readiness/ (development status).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Overview

One row per mechanism, read from its record. Open failures: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees. Findings are grouped as known failures, scope limitations and open questions. Only known failures count as failures. Counts are an inventory of published findings, not a risk score.

| Mechanism | Development | Security evidence | Prover | Attack testing | Hardware | Open failures | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Timed challenge-response and memory-occupation challenges / GPU contention probes | Research demonstration | Published security analysis | Adversarial | Analysis | None | 0 / 0 / 0 | unspecified | unspecified | unspecified |
| Remote detection of data centres | Proposed | Published security analysis | Adversarial | Analysis | None | 0 / 0 / 0 | not involved | not involved | not involved |

## Claims

No claims chosen.

## Mechanisms

### Timed challenge-response and memory-occupation challenges

Three timed GPU puzzles whose solve times lengthen when another workload shares the device, a heuristic sign to a verifier that the GPU is shared. ([Timed challenge-response and memory-occupation challenges](https://trustbutveri.fyi/mechanisms/timed-challenge-response/))

- Assessment: selected implementation [GPU contention probes](https://trustbutveri.fyi/implementations/gpu-contention-probes/).
- Development: Research demonstration (legacy code R2), assessed for detecting another workload running on the same GPU.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights unspecified; inputs and outputs unspecified; training data unspecified. This Explorer has no asset-specific exposure assessment for this implementation. Check its source and deployment assumptions.

### Remote detection of data centres

Remote detection locates large data centres and estimates their power capacity without site access, using satellite imagery, heat signatures and public records such as permits. ([Remote detection of data centres](https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/))

- Assessment: mechanism family.
- Development: Proposed (legacy code R1), assessed for finding undeclared data centres above an agreed compute threshold.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: not required. Attack testing: analysis. Category: Remote & side-channel sensing.
- What the verifier sees: model weights not involved; inputs and outputs not involved; training data not involved. Works from outside the facility; it does not handle model data.


## Properties

**Built for an adversarial prover**

- Timed challenge-response and memory-occupation challenges
- Remote detection of data centres

**No new hardware needed**

- Timed challenge-response and memory-occupation challenges
- Remote detection of data centres


## Attack testing

Attack testing records published testing for this use. It does not by itself show independent review, a formal proof or that a deployed system is secure.

**Testing history**

- Timed challenge-response and memory-occupation challenges / GPU contention probes: Analysis
- Remote detection of data centres: Analysis


## Limits

**Family finding context**

- Context for GPU contention probes. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Timing-based software attestation has been broken in practice (known failure, demonstrated attack, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/1/) [2][3]. Castelluccia et al. implemented two generic attacks, one based on a return-oriented rootkit and one on code compression, together with specific attacks on SWATT and ICE-based schemes, on commodity sensor nodes. They conclude that secure time-based attestation is "very difficult, if not impossible, to design correctly". The attacks target embedded schemes, not AI accelerators.

  Response: Perrig and van Doorn, two of the designers of SWATT and ICE, replied in August 2010. They argue that the rootkit attack defeats a naive implementation, not a property the schemes claim, and that the SWATT attack was run on a re-implementation on a chip with eight times the program memory, where SWATT's own chip is almost always full of code. They accept that the attack on ICE works.
- Context for GPU contention probes. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Remote memory narrows the timing margin (known failure, theoretical argument, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/2/) [4]. Data-centre remote memory access returns in about 1–2 µs, against about 70–200 ns for local DRAM. The MIRI overview says verification of memory saturation depends on ruling out remote access by latency or physical disconnection. It names pre-staging data into local memory as the remaining evasion and proposes an unpredictable, capacity-filling challenge to close it.

  Related mechanism: Bandwidth limits and compartmentalization (R2, not in the proposal). Physical disconnection is proposed to exclude remote memory between the separated groups during a challenge. It depends on the isolation boundary being enforced.
- Context for GPU contention probes. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Error rates not quantified (open question, open question, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/3/) [1]. Monfared et al. show separable timing distributions. Their acceptance rule passes a GPU when its mean time per round stays at or below a chosen maximum, and an appendix outlines statistical tests for the proof-of-work puzzle. They leave hardware-specific threshold values to future work and report no false-positive or false-negative rates.

**Scope limitations**

- Answers are not tied to one GPU (scope limitation, theoretical argument, in GPU contention probes; https://trustbutveri.fyi/implementations/gpu-contention-probes/evidence/flaws/2/) [1]. The paper's floating-point fingerprint characterises a GPU model. The authors state that it does not distinguish individual GPUs, so a probe answer does not show which device of that model produced it.
- Facilities can be disguised or hidden (scope limitation, theoretical argument, in Remote detection of data centres; https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/evidence/flaws/1/) [5]. Halstead and Larsen discuss two ways to hide a facility. One is to disguise it as a legitimate industrial site. The other is to build it underground, with cooling that avoids visible heat plumes. They note that the underground option requires bespoke engineering.
- Small sites may not be detectable (scope limitation, theoretical argument, in Remote detection of data centres; https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/evidence/flaws/2/) [5][7]. Halstead and Larsen conclude that a sufficiently small covert project could not be ruled out with confidence. In their estimates, the chance of detection is lower for smaller sites. Krawec notes that small data centres in existing buildings may lack the distinctive features of large facilities.

  Related mechanism: Chip registries and manufacturing records (R1, not in the proposal). Accounts for chips from the fab onwards, which does not depend on a site being visible.

**Open questions**

- Error rates not quantified (open question, open question, in GPU contention probes; https://trustbutveri.fyi/implementations/gpu-contention-probes/evidence/flaws/1/) [1]. Monfared et al. show timing distributions that shift under contention, but leave hardware-specific thresholds to future work and state that false-positive and false-negative rates are not quantified.
- Search for unknown sites is undemonstrated (open question, open question, in Remote detection of data centres; https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/evidence/flaws/3/) [7]. Krawec reports that telling data centres apart from other industrial facilities systematically is difficult. Automating detection would need large amounts of training imagery and a purpose-trained model. In Krawec's words, automated data-centre detection "remains primarily conceptual at present".

**Not yet demonstrated**

- Remote detection of data centres: Proposed (legacy code R1), assessed for finding undeclared data centres above an agreed compute threshold


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open failure or a dependency. Pointers, not recommendations: each brings its own readiness level and findings, and none is claimed to close a failure.

None found.



## Dependencies

**Blockers**

- Timed challenge-response and memory-occupation challenges: Continuous probes add power draw, occupy GPU memory and reduce inference throughput. (performance & compatibility) [1]
- Timed challenge-response and memory-occupation challenges: The paper gives an acceptance rule but no hardware-specific threshold values or measured error rates, so it does not settle when a timing shift counts as a detection. (adversarial validation) [1]
- Remote detection of data centres: Wide-area, automated detection of data centres is not yet practical and needs large training datasets. (coverage & hidden compute) [7]
- Remote detection of data centres: No measured detection or false-alarm rates for finding undeclared facilities have been published. (adversarial validation) [5][7]
- Remote detection of data centres: Recent high-resolution imagery is costly, is limited by weather and needs trained analysts. (access & governance) [7]


## What the verifier sees

- Model weights: shown by none; depends on the design for none; hidden by none; not involved in Remote detection of data centres; unspecified for Timed challenge-response and memory-occupation challenges.
- Inputs and outputs: shown by none; depends on the design for none; hidden by none; not involved in Remote detection of data centres; unspecified for Timed challenge-response and memory-occupation challenges.
- Training data: shown by none; depends on the design for none; hidden by none; not involved in Remote detection of data centres; unspecified for Timed challenge-response and memory-occupation challenges.

## Implementations

- Timed challenge-response and memory-occupation challenges: [Data-centre memory challenging](https://trustbutveri.fyi/implementations/data-centre-memory-challenging/) (R1, proposed architecture); [GPU contention probes](https://trustbutveri.fyi/implementations/gpu-contention-probes/) (R2, research prototype); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [SAGE](https://trustbutveri.fyi/implementations/sage-gpu-attestation/) (R2, research prototype); [VRAM-residency challenge](https://trustbutveri.fyi/implementations/vram-residency-challenge/) (R2, research prototype)
- Remote detection of data centres: none on the map

## Sources

1. Timing and Memory Telemetry on GPUs for AI Governance, S. K. Monfared et al. (2026). https://arxiv.org/abs/2602.09369
2. On the Difficulty of Software-Based Attestation of Embedded Devices, C. Castelluccia et al. (2009). https://s3.eurecom.fr/docs/ccs09_Castelluccia.pdf
3. Refutation of "On the Difficulty of Software-Based Attestation of Embedded Devices", A. Perrig & L. van Doorn (2010). https://netsec.ethz.ch/publications/papers/perrig-ccs-refutation.pdf
4. A System Overview for Near-Term, Low-Trust AI Compute Verification, N. Cankaya (2026). https://intelligence.org/wp-content/uploads/2026/06/A-system-overview-for-near-term-low-trust-AI-compute-verification.pdf
5. Covert AI Projects, B. Halstead & T. Larsen (2026). https://ai-2040.com/supplements/covert-ai-projects
6. Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment, M. Baker et al. (2025). https://www.rand.org/pubs/working_papers/WRA4077-1.html
7. Tracking Hyperscale AI Data Center Growth with Satellite Imagery, C. Krawec (2026). https://fas.org/publication/tracking-hyperscale/
8. Introducing the Frontier Data Centers Hub, Epoch AI (2025). https://epoch.ai/latest/introducing-the-frontier-data-centers-hub
9. AI Data Centers Documentation – Methodology, Epoch AI (2026). https://epoch.ai/data/data-centers-documentation/methodology
