Mechanism · Hardware-enabled guarantees (flexHEG) and guarantee processors
Sources
On this page
- BJ. Petrie et al. (2025). Flexible Hardware-Enabled Guarantees for AI Compute. arXiv. Source recordSupports: flexHEG definition, components, verifiable claims, rulesets, update restriction, limitations, relation to confidential computing · Executive Summary; Conceptual Overview; Appendix A-B
- BJ. Petrie & O. Aarne (2025). Technical Options for Flexible Hardware-Enabled Guarantees. arXiv. Source recordSupports: Interlock, secure enclosure, integration options, update authorization, overhead estimates (including the 1/192 SM estimate and its 192-SM assumption), timelines, prototype mention, attacks · sections on Interlock-Based Design, Secure Enclosure, Potential Accelerator Modifications
- BS. Nassernia (2025). Boost GPU Memory Performance with No Code Changes Using NVIDIA CUDA MPS. NVIDIA Technical Blog. Source recordSupports: NVIDIA states that the Blackwell GPUs in an HGX B200 system normally have 148 SMs · MLOPart section
- BO. Aarne & J. Petrie (2025). International Security Applications of Flexible Hardware-Enabled Guarantees. arXiv. Source recordSupports: verification- vs ruleset-based agreements, states as primary attackers, redundant processors, manufacturing oversight and sampling, coverage limits, algorithmic efficiency · Creating an Internationally Trustworthy FlexHEG Ecosystem; Overseeing Production
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: HEM definition, offline licensing and fixed set, threat actor tiers, attack classes, anti-tamper limits · pp. viii-x, 4, 19-27
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordSupports: on-chip governance with existing features, hardening need, 18 months to 4 years estimate · Key findings
- BA. O'Gara et al. (2025). Hardware-Enabled Mechanisms for Verifying Responsible AI Development. arXiv. Source recordSupports: workshop agenda on HEMs (four uses) and open questions on licensing and pod attestation · §2; §2.3.4, §2.5.4
- BD. Reber Jr. (2025). No Backdoors. No Kill Switches. No Spyware.. NVIDIA Blog. Source recordSupports: NVIDIA's stated position that its GPUs do not and should not have kill switches, and its distinction for optional user-controlled features · blog post