# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-09. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0020,M-0016&implementations=M-0016:I-0019

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's development status, security evidence and findings. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and findings) and https://trustbutveri.fyi/about/readiness/ (development status).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Overview

One row per mechanism, read from its record. Open failures: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees. Findings are grouped as known failures, scope limitations and open questions. Only known failures count as failures. Counts are an inventory of published findings, not a risk score.

| Mechanism | Development | Security evidence | Prover | Attack testing | Hardware | Open failures | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Remote detection of data centres | Proposed | Published security analysis | Adversarial | Analysis | None | 0 / 0 / 0 | not involved | not involved | not involved |
| Timed challenge-response and memory-occupation challenges / VRAM-residency challenge | Research demonstration | Published security analysis | Adversarial | Analysis | None | 0 / 0 / 0 | unspecified | unspecified | unspecified |

## Claims

No claims chosen.

## Mechanisms

### Remote detection of data centres

Remote detection locates large data centres and estimates their power capacity without site access, using satellite imagery, heat signatures and public records such as permits. ([Remote detection of data centres](https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/))

- Assessment: mechanism family.
- Development: Proposed (legacy code R1), assessed for finding undeclared data centres above an agreed compute threshold.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: not required. Attack testing: analysis. Category: Remote & side-channel sensing.
- What the verifier sees: model weights not involved; inputs and outputs not involved; training data not involved. Works from outside the facility; it does not handle model data.

### Timed challenge-response and memory-occupation challenges

A timed challenge that tests whether verifier-supplied data is still held in a GPU's on-board memory or has moved to host memory. ([Timed challenge-response and memory-occupation challenges](https://trustbutveri.fyi/mechanisms/timed-challenge-response/))

- Assessment: selected implementation [VRAM-residency challenge](https://trustbutveri.fyi/implementations/vram-residency-challenge/).
- Development: Research demonstration (legacy code R2), assessed for detecting whether verifier-supplied data remains in a single GPU's memory.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights unspecified; inputs and outputs unspecified; training data unspecified. This Explorer has no asset-specific exposure assessment for this implementation. Check its source and deployment assumptions.


## Properties

**Built for an adversarial prover**

- Remote detection of data centres
- Timed challenge-response and memory-occupation challenges

**No new hardware needed**

- Remote detection of data centres
- Timed challenge-response and memory-occupation challenges


## Attack testing

Attack testing records published testing for this use. It does not by itself show independent review, a formal proof or that a deployed system is secure.

**Testing history**

- Remote detection of data centres: Analysis
- Timed challenge-response and memory-occupation challenges / VRAM-residency challenge: Analysis


## Limits

**Family finding context**

- Context for VRAM-residency challenge. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Timing-based software attestation has been broken in practice (known failure, demonstrated attack, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/1/) [7][8]. Castelluccia et al. implemented two generic attacks, one based on a return-oriented rootkit and one on code compression, together with specific attacks on SWATT and ICE-based schemes, on commodity sensor nodes. They conclude that secure time-based attestation is "very difficult, if not impossible, to design correctly". The attacks target embedded schemes, not AI accelerators.

  Response: Perrig and van Doorn, two of the designers of SWATT and ICE, replied in August 2010. They argue that the rootkit attack defeats a naive implementation, not a property the schemes claim, and that the SWATT attack was run on a re-implementation on a chip with eight times the program memory, where SWATT's own chip is almost always full of code. They accept that the attack on ICE works.
- Context for VRAM-residency challenge. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Remote memory narrows the timing margin (known failure, theoretical argument, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/2/) [9]. Data-centre remote memory access returns in about 1–2 µs, against about 70–200 ns for local DRAM. The MIRI overview says verification of memory saturation depends on ruling out remote access by latency or physical disconnection. It names pre-staging data into local memory as the remaining evasion and proposes an unpredictable, capacity-filling challenge to close it.

  Related mechanism: Bandwidth limits and compartmentalization (R2, not in the proposal). Physical disconnection is proposed to exclude remote memory between the separated groups during a challenge. It depends on the isolation boundary being enforced.
- Context for VRAM-residency challenge. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Error rates not quantified (open question, open question, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/3/) [6]. Monfared et al. show separable timing distributions. Their acceptance rule passes a GPU when its mean time per round stays at or below a chosen maximum, and an appendix outlines statistical tests for the proof-of-work puzzle. They leave hardware-specific threshold values to future work and report no false-positive or false-negative rates.

**Scope limitations**

- Facilities can be disguised or hidden (scope limitation, theoretical argument, in Remote detection of data centres; https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/evidence/flaws/1/) [1]. Halstead and Larsen discuss two ways to hide a facility. One is to disguise it as a legitimate industrial site. The other is to build it underground, with cooling that avoids visible heat plumes. They note that the underground option requires bespoke engineering.
- Small sites may not be detectable (scope limitation, theoretical argument, in Remote detection of data centres; https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/evidence/flaws/2/) [1][3]. Halstead and Larsen conclude that a sufficiently small covert project could not be ruled out with confidence. In their estimates, the chance of detection is lower for smaller sites. Krawec notes that small data centres in existing buildings may lack the distinctive features of large facilities.

  Related mechanism: Chip registries and manufacturing records (R1, not in the proposal). Accounts for chips from the fab onwards, which does not depend on a site being visible.
- Answers are not tied to one GPU (scope limitation, theoretical argument, in VRAM-residency challenge; https://trustbutveri.fyi/implementations/vram-residency-challenge/evidence/flaws/2/) [6]. The paper's floating-point fingerprint characterises a GPU model. The authors state that it does not distinguish individual GPUs, so a timely answer does not show which device of that model held the data.

**Open questions**

- Search for unknown sites is undemonstrated (open question, open question, in Remote detection of data centres; https://trustbutveri.fyi/mechanisms/remote-detection-of-data-centres/evidence/flaws/3/) [3]. Krawec reports that telling data centres apart from other industrial facilities systematically is difficult. Automating detection would need large amounts of training imagery and a purpose-trained model. In Krawec's words, automated data-centre detection "remains primarily conceptual at present".
- Error rates not quantified (open question, open question, in VRAM-residency challenge; https://trustbutveri.fyi/implementations/vram-residency-challenge/evidence/flaws/1/) [6]. Monfared et al. report a timing gap of more than 350 ms but leave hardware-specific thresholds to future work and state that false-positive and false-negative rates are not quantified.

**Not yet demonstrated**

- Remote detection of data centres: Proposed (legacy code R1), assessed for finding undeclared data centres above an agreed compute threshold


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open failure or a dependency. Pointers, not recommendations: each brings its own readiness level and findings, and none is claimed to close a failure.

None found.



## Dependencies

**Blockers**

- Remote detection of data centres: Wide-area, automated detection of data centres is not yet practical and needs large training datasets. (coverage & hidden compute) [3]
- Remote detection of data centres: No measured detection or false-alarm rates for finding undeclared facilities have been published. (adversarial validation) [1][3]
- Remote detection of data centres: Recent high-resolution imagery is costly, is limited by weather and needs trained analysts. (access & governance) [3]
- Timed challenge-response and memory-occupation challenges: The challenge data occupies a large part of GPU memory for as long as the test runs. (performance & compatibility) [6]
- Timed challenge-response and memory-occupation challenges: No test across servers has been reported, and the MIRI overview lists network-level probing of memory contents as undemonstrated. (adversarial validation) [6][9]


## What the verifier sees

- Model weights: shown by none; depends on the design for none; hidden by none; not involved in Remote detection of data centres; unspecified for Timed challenge-response and memory-occupation challenges.
- Inputs and outputs: shown by none; depends on the design for none; hidden by none; not involved in Remote detection of data centres; unspecified for Timed challenge-response and memory-occupation challenges.
- Training data: shown by none; depends on the design for none; hidden by none; not involved in Remote detection of data centres; unspecified for Timed challenge-response and memory-occupation challenges.

## Implementations

- Remote detection of data centres: none on the map
- Timed challenge-response and memory-occupation challenges: [Data-centre memory challenging](https://trustbutveri.fyi/implementations/data-centre-memory-challenging/) (R1, proposed architecture); [GPU contention probes](https://trustbutveri.fyi/implementations/gpu-contention-probes/) (R2, research prototype); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [SAGE](https://trustbutveri.fyi/implementations/sage-gpu-attestation/) (R2, research prototype); [VRAM-residency challenge](https://trustbutveri.fyi/implementations/vram-residency-challenge/) (R2, research prototype)

## Sources

1. Covert AI Projects, B. Halstead & T. Larsen (2026). https://ai-2040.com/supplements/covert-ai-projects
2. Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment, M. Baker et al. (2025). https://www.rand.org/pubs/working_papers/WRA4077-1.html
3. Tracking Hyperscale AI Data Center Growth with Satellite Imagery, C. Krawec (2026). https://fas.org/publication/tracking-hyperscale/
4. Introducing the Frontier Data Centers Hub, Epoch AI (2025). https://epoch.ai/latest/introducing-the-frontier-data-centers-hub
5. AI Data Centers Documentation – Methodology, Epoch AI (2026). https://epoch.ai/data/data-centers-documentation/methodology
6. Timing and Memory Telemetry on GPUs for AI Governance, S. K. Monfared et al. (2026). https://arxiv.org/abs/2602.09369
7. On the Difficulty of Software-Based Attestation of Embedded Devices, C. Castelluccia et al. (2009). https://s3.eurecom.fr/docs/ccs09_Castelluccia.pdf
8. Refutation of "On the Difficulty of Software-Based Attestation of Embedded Devices", A. Perrig & L. van Doorn (2010). https://netsec.ethz.ch/publications/papers/perrig-ccs-refutation.pdf
9. A System Overview for Near-Term, Low-Trust AI Compute Verification, N. Cankaya (2026). https://intelligence.org/wp-content/uploads/2026/06/A-system-overview-for-near-term-low-trust-AI-compute-verification.pdf
