Mechanism · Hardware performance throttling and licensing
Evidence & limits
On this page
R1Proposed for performance limits a verifier can rely on, against an operator trying to bypass them
The designs are published, but the only quantitative results are kernel-level simulations and the only public code is a simulated proof of concept.
Assessed use: performance limits a verifier can rely on, against an operator trying to bypass them
Rubric assessment
- R1 met: RAND and O'Gara et al. describe offline licensing, including its claims and threats 2 3. Ma et al. describe microarchitectural throttles with a stated adversary 1. Petrie describes a license-gated off-switch with a threat model up to states with physical access 7. The flexHEG reports describe license-gated operation 6.
- R2 not met. The quantitative evidence is one cycle-accurate simulation of a modelled A100, at the level of kernels rather than end-to-end workloads 1. The paper announces no code or hardware release; code is not required, but the results are not end-to-end. Petrie's public proof of concept gates an example Int8 adder in simulation. It leaves out the redundant blocks and constant-time arithmetic that the design's threat model relies on, so it does not test resistance to the attacks those features address 8. The existing features that sources mention, thermal and power clock throttling and Intel On Demand feature licensing, were not built or evaluated for this use 2 3.
- A public hardware or FPGA prototype, or end-to-end results described in enough detail to repeat (released simulator changes and scripts would also serve).
- End-to-end evaluation on training and inference workloads on current architectures.
- A trigger or licensing path that is cryptographically validated and shown to resist interception.
- Attestation by which a remote verifier can confirm the throttle state.
Assessed 2026-09-25 against rubric v1.1.
Evidence
- Ma et al. They simulate an NVIDIA A100 in AccelSim on GEMM and attention kernels shaped like those of recent large models. Performance fell by up to 80% at one-eighth of resource availability, and settled 5–80K cycles after a throttle was applied. Each mechanism needs fewer than about 10K flip-flops. The paper announces no code or hardware release 1.
- Licensing designs. RAND and O'Gara et al. present designs and open questions, not prototypes 2 3.
- Embedded off-switch. Petrie's area estimate comes from gate counts, and the paper reports no built or measured hardware 7. A public SystemVerilog proof of concept gates an example Int8 adder in simulation. Its README lists omitted production features, including constant-time arithmetic and redundant blocks 8.
- Development effort. CNAS estimates that adequate hardware security for on-chip mechanisms, particularly tamper evidence and tamper-proofing, could take as little as 18 months, and up to 4 years, of technical effort by leading firms 4.
Limitations
The weaknesses the sources recognize are:
- the security of the trigger or license path 1 3;
- physical, firmware and supply-chain attacks on the enforcing hardware 2;
- sensitivity that varies by architecture, including non-monotonic L2 behaviour 1;
- workloads adapting to the throttle 1.
Ma et al. ran their experiments only on A100-like configurations, and expect the trends to hold on newer GPUs 1. Secure boot and voltage-glitching risks for license-checking firmware are discussed under Hardware-enabled guarantees (flexHEG) and guarantee processors 6.
Ma et al. present their throttles as mechanisms for GPU vendors to adopt 1. An August 2025 NVIDIA blog post states that NVIDIA GPUs "do not and should not have kill switches and backdoors". It distinguishes optional software features controlled by the user from a kill switch hardwired into a chip 9.
Known flaws
Blockers
The throttles need new microarchitecture in future chips, and chipmakers would have to adopt it.
Secure licensing and trigger infrastructure is missing, such as a guarantee processor that issues or checks licenses.
Licenses denominated in work need secure meters for the licensed quantities.
No throttle has been evaluated on real hardware or against red-team attempts at bypass.