Implementation · SASH confidential network logger

Evidence & limits

On this page

R1Proposed for telling inference from training on a mutually inspected cluster

Public code exists, but it runs a toy model through a software proxy with no stated adversary.

Assessed use: telling inference from training on a mutually inspected cluster

Rubric assessment

  • R1 met: SASH publicly describes the design (a traffic-splitting logger plus sampled recomputation on a mutually inspected cluster), the claim (inference rather than training) and its stated limitations 1. Public code exists 2.
  • R2 not met: the implementation does not run under conditions representative of the verification use in any key respect. The model is Gemma 3 270M on a CPU inference image, and the logger is a software proxy 2. The hardware demonstration used DGX Spark GPUs and Raspberry Pis 1. The only adversary is a demo switch that replaces outputs with random characters 2. As of September 2026 no evaluation by others has been published.

Confidence is medium: the code can be read directly, but the hardware demonstration is known only from SASH's blog post.

Gaps to the next level
  • A hardware logger (the planned FPGA version) on a real data-centre link, with realistic model size or traffic volume.
  • A stated adversary and threat model, with testing against it.
  • Random sampling and hashed or certified traffic records, as described in the blog post, implemented in the public code.

Assessed 2026-09-25 against rubric v1.1.

Evidence

  • Hardware demonstration. In SASH's demonstration, "a pair of DGX Spark GPUs sit in for the audited datacenter and recomputation cluster", and Raspberry Pis stand in for the logger and the data-centre frontend 1.
  • Public code. The code's container setup serves the Gemma 3 270M instruction-tuned model on a CPU inference image, and a demo switch simulates covert training by replacing output with random characters 2.
  • Next prototype. SASH says a further prototype with an FPGA is planned 1. In July 2026 it said it plans a v2 of the logger based on a zero-knowledge proof system 3.

Limitations

SASH lists the following 1:

  • "There is no means to monitor the security of the recomputation cluster" 1.
  • Using a Raspberry Pi 5 as the logger locks the design into Broadcom and Arm supply chains 1.
  • Future versions would add zero-knowledge proofs to the recomputation method, eliminate a wider range of side-channel vulnerabilities, and scale the design to production traffic volumes 1.

The general limitations of network taps, such as covert capacity in model outputs and line-rate hashing, are covered in Network taps and certifiers.

Known flaws

Blockers

Search

Full search page