# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-09. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0016&implementations=M-0016:I-0020

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's development status, security evidence and findings. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and findings) and https://trustbutveri.fyi/about/readiness/ (development status).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Overview

One row per mechanism, read from its record. Open failures: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees. Findings are grouped as known failures, scope limitations and open questions. Only known failures count as failures. Counts are an inventory of published findings, not a risk score.

| Mechanism | Development | Security evidence | Prover | Attack testing | Hardware | Open failures | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Timed challenge-response and memory-occupation challenges / Data-centre memory challenging | Proposed | Published security analysis | Adversarial | Analysis | Retrofit device | 0 / 1 / 0 | unspecified | unspecified | unspecified |

## Claims

No claims chosen.

## Mechanisms

### Timed challenge-response and memory-occupation challenges

A proposed design that times answers from a data centre's memory to check that declared data is present or that no free memory remains. ([Timed challenge-response and memory-occupation challenges](https://trustbutveri.fyi/mechanisms/timed-challenge-response/))

- Assessment: selected implementation [Data-centre memory challenging](https://trustbutveri.fyi/implementations/data-centre-memory-challenging/).
- Development: Proposed (legacy code R1), assessed for confirming data presence and bounding free memory across data-centre servers.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: retrofit device. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights unspecified; inputs and outputs unspecified; training data unspecified. This Explorer has no asset-specific exposure assessment for this implementation. Check its source and deployment assumptions.


## Properties

**Built for an adversarial prover**

- Timed challenge-response and memory-occupation challenges


## Attack testing

Attack testing records published testing for this use. It does not by itself show independent review, a formal proof or that a deployed system is secure.

**Testing history**

- Timed challenge-response and memory-occupation challenges / Data-centre memory challenging: Analysis


## Limits

**Open significant failures**

- Remote memory narrows the timing margin (known failure, theoretical argument, in Data-centre memory challenging; https://trustbutveri.fyi/implementations/data-centre-memory-challenging/evidence/flaws/1/) [1]. A remote memory access round trip takes about 1–2 µs over InfiniBand or RoCE, against about 70–200 ns for a local DRAM read. The overview says verification of memory saturation depends on ruling out remote access, by response latency or by physical disconnection.

**Family finding context**

- Context for Data-centre memory challenging. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Timing-based software attestation has been broken in practice (known failure, demonstrated attack, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/1/) [2][3]. Castelluccia et al. implemented two generic attacks, one based on a return-oriented rootkit and one on code compression, together with specific attacks on SWATT and ICE-based schemes, on commodity sensor nodes. They conclude that secure time-based attestation is "very difficult, if not impossible, to design correctly". The attacks target embedded schemes, not AI accelerators.

  Response: Perrig and van Doorn, two of the designers of SWATT and ICE, replied in August 2010. They argue that the rootkit attack defeats a naive implementation, not a property the schemes claim, and that the SWATT attack was run on a re-implementation on a chip with eight times the program memory, where SWATT's own chip is almost always full of code. They accept that the attack on ICE works.
- Context for Data-centre memory challenging. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Remote memory narrows the timing margin (known failure, theoretical argument, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/2/) [1]. Data-centre remote memory access returns in about 1–2 µs, against about 70–200 ns for local DRAM. The MIRI overview says verification of memory saturation depends on ruling out remote access by latency or physical disconnection. It names pre-staging data into local memory as the remaining evasion and proposes an unpredictable, capacity-filling challenge to close it.

  Related mechanism: Bandwidth limits and compartmentalization (R2, not in the proposal). Physical disconnection is proposed to exclude remote memory between the separated groups during a challenge. It depends on the isolation boundary being enforced.
- Context for Data-centre memory challenging. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Error rates not quantified (open question, open question, in Timed challenge-response and memory-occupation challenges; https://trustbutveri.fyi/mechanisms/timed-challenge-response/evidence/flaws/3/) [4]. Monfared et al. show separable timing distributions. Their acceptance rule passes a GPU when its mean time per round stays at or below a chosen maximum, and an appendix outlines statistical tests for the proof-of-work puzzle. They leave hardware-specific threshold values to future work and report no false-positive or false-negative rates.

**Scope limitations**

- Presence does not show absence (scope limitation, theoretical argument, in Data-centre memory challenging; https://trustbutveri.fyi/implementations/data-centre-memory-challenging/evidence/flaws/2/) [1]. A check that data is present does not show that nothing else is stored. The overview names pre-staging data into local memory before a challenge as the remaining evasion, and proposes an unpredictable, capacity-filling challenge to close it.

**Not yet demonstrated**

- Timed challenge-response and memory-occupation challenges: Proposed (legacy code R1), assessed for confirming data presence and bounding free memory across data-centre servers


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open failure or a dependency. Pointers, not recommendations: each brings its own readiness level and findings, and none is claimed to close a failure.

- **Bandwidth limits and compartmentalization** (Research demonstration (legacy code R2), assessed for monitoring inter-node traffic with operator-run software on four GPUs)
  - Timed challenge-response and memory-occupation challenges waits on it: Remote memory access must be excluded during challenges.


## Dependencies

**Missing prerequisites**

- Bandwidth limits and compartmentalization (Research demonstration (legacy code R2), assessed for monitoring inter-node traffic with operator-run software on four GPUs), needed by Timed challenge-response and memory-occupation challenges

**Blockers**

- Timed challenge-response and memory-occupation challenges: No network-level probe has been shown to distinguish one server's memory contents from another's. (adversarial validation) [1]
- Timed challenge-response and memory-occupation challenges: Most of the design needs a probe in close proximity to the challenged memory. (access & governance) [1]
- Timed challenge-response and memory-occupation challenges: Filling a pod's volatile memory takes tens of minutes, and on-board SSDs take hours. (performance & compatibility) [1]
- Timed challenge-response and memory-occupation challenges: Remote memory access must be excluded during challenges. (coverage & hidden compute; waits on Bandwidth limits and compartmentalization) [1]


## What the verifier sees

- Model weights: shown by none; depends on the design for none; hidden by none; not involved in none; unspecified for Timed challenge-response and memory-occupation challenges.
- Inputs and outputs: shown by none; depends on the design for none; hidden by none; not involved in none; unspecified for Timed challenge-response and memory-occupation challenges.
- Training data: shown by none; depends on the design for none; hidden by none; not involved in none; unspecified for Timed challenge-response and memory-occupation challenges.

## Implementations

- Timed challenge-response and memory-occupation challenges: [Data-centre memory challenging](https://trustbutveri.fyi/implementations/data-centre-memory-challenging/) (R1, proposed architecture); [GPU contention probes](https://trustbutveri.fyi/implementations/gpu-contention-probes/) (R2, research prototype); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [SAGE](https://trustbutveri.fyi/implementations/sage-gpu-attestation/) (R2, research prototype); [VRAM-residency challenge](https://trustbutveri.fyi/implementations/vram-residency-challenge/) (R2, research prototype)

## Sources

1. A System Overview for Near-Term, Low-Trust AI Compute Verification, N. Cankaya (2026). https://intelligence.org/wp-content/uploads/2026/06/A-system-overview-for-near-term-low-trust-AI-compute-verification.pdf
2. On the Difficulty of Software-Based Attestation of Embedded Devices, C. Castelluccia et al. (2009). https://s3.eurecom.fr/docs/ccs09_Castelluccia.pdf
3. Refutation of "On the Difficulty of Software-Based Attestation of Embedded Devices", A. Perrig & L. van Doorn (2010). https://netsec.ethz.ch/publications/papers/perrig-ccs-refutation.pdf
4. Timing and Memory Telemetry on GPUs for AI Governance, S. K. Monfared et al. (2026). https://arxiv.org/abs/2602.09369
