Mechanism · Off-chip devices & sensors
Network taps and certifiers
Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work.
Also called Secure network taps; Cluster I/O fingerprinting; Secure Gateway Device
Summary
Network taps copy the traffic on a data centre's cables. In verification proposals, a tap or "secure gateway" hashes everything entering and leaving a cluster. The verifier later asks the operator to reveal randomly chosen records, which are recomputed and checked. The aim is to show that outputs came from declared work, and that results of undeclared work cannot leave covertly through the tapped links. Designs, cost estimates and covert-channel analyses are public. Amodo's small tests have tapped 1–10 Gbps links; as of September 2026 no tap has been demonstrated at production link rates or red-teamed. The main obstacles are hashing at line rate on 400G-class links, and tapping copper or encrypted fabrics. The largest known weakness is covert signalling in model outputs: one design estimates about 40 Mbit/s for a 200,000-GPU inference cluster, even with replay checks, unless inference becomes deterministic.
R1: the Secure Gateway Device and related designs are public, but no tapped prototype has run at production link rates or with an active warden.
Rubric assessment
- R1 met: the Secure Gateway Device paper specifies the architecture, its goal (no covert exfiltration of results through tapped wires), its assumptions (physical monitoring, prover-held plaintext) and covert-channel estimates 1. Feasibility and cost analyses cover north-south, storage and compute-fabric taps 2. The MIRI overview places taps in a full reference architecture 3, and the AI 2040 plan relies on them 4.
- R2 not met: Amodo reports a passive fibre tap on a 1 Gbps uplink, with all 800 test inferences tapped and verified during a flood of non-whitelisted traffic 8. That result is provider-reported on a blog, at link rates far below production frontend links, and Amodo says the passive tap must become active to close side channels 8. No code is linked. The most mature Implementation, SASH's confidential network logger, has public code, but it runs a toy model through an inline software proxy that computes no hashes 9 10. AI 2040 inference-only verification stack and Low-trust AI compute verification system overview are proposed architectures assessed R1. The Secure Gateway Device paper states that empirical validation and red-teaming are still required 1.
Confidence is low because the Amodo result (real tap hardware, a stated adversarial load) could reasonably be read as meeting R2 in one key respect.
- An end-to-end tapped prototype with public code, or with results described in enough detail for an independent team to repeat.
- Hashing and tapping demonstrated at production frontend link rates (400 Gbps class), including minimum-size frames.
- A built active warden or Secure Gateway Device, with measured residual covert bandwidth.
- Red-teaming of tap bypass, covert channels and physical security.
How it works
A network tap is a device that "mirror[s] network traffic without disrupting normal operation" 2. Verification proposals use taps to build a record of what crossed a link, which the verifier can check later 2 3. The MIRI system overview states the principle as "capture everything, challenge and audit random samples after" 3.
In the most detailed designs, the verifier never receives plaintext 3 1. The tap hashes payloads over groups of packets, without knowing where objects such as prompts begin or end, and sends only hashes out; the operator (the prover) keeps the plaintext 3 1. Later the verifier picks stored hashes at random, the prover supplies the matching data, and a verification facility replays the computation and checks that the hashes match 1. A missing or mismatching preimage is a failure; a replay that does not reproduce points to false metadata or a technical fault 3.
The AI 2040 plan proposes a simpler variant: passive taps on the frontend network copy all input and output traffic to a recomputation server (Sampled inference recomputation, Reproducible computation packets) 4.
Taps can sit at three levels 2:
- North-south (frontend) links to the outside world, at an estimated material cost under 0.01% of the monitored data centre 2.
- The storage fabric, which carries model loads, dataset reads and checkpoint saves, at an estimated 0.3–0.5% of data-centre cost 2.
- The compute (east-west) fabric, at an estimated 0.2–1.5% of data-centre cost for its optical levels. Volumes there are so high that the note proposes sampling, for example 0.01% of traffic, about 20 Gb/s, through an optical circuit switch 2.
For inference, the monitored perimeter could be as small as pods of a few hundred accelerators; monitoring training needs larger perimeters or taps on the compute and storage fabrics 3.
A key aim of the "Secure Gateway Device" design is that no processor has to be trusted by both sides 1. It uses passive optical splitters, so that each party can watch the signals it must check, and coin-flip protocols to generate shared random values 1. It also acts as an "active warden", rewriting free header fields and re-timing packets to close timing, analogue and header channels that checks on hashes cannot address 1.
SASH's planned next prototype would place an FPGA between the cluster and its gateway to issue "cryptographic certificates attesting to the encrypted traffic it has seen" 10; see SASH confidential network logger.
What it establishes
The Secure Gateway Device paper aims to make it "infeasible to covertly exfiltrate the results of undisclosed workloads in the cluster through the tapped wires" 1. Combined with replay, it would show that recorded outputs match declared workloads 1 4; see This compute runs inference, not training and Model weights or data have not left the facility.
It does not establish:
- Device state. Taps capture flows, not device state; the MIRI overview treats memory probes as complementary 3.
- Absence of covert compute. A north-south tap does not directly prevent covert workloads, only the exfiltration of their results 1. The paper judges it futile to block every single-bit leak. It argues that the residual risk, covert computation plus low-bandwidth signalling of results, needs other checks such as east-west taps and throughput accounting 1.
- Permissibility or compliance. The paper does not decide which workloads should be allowed, or whether declared workloads comply 1.
Threat model
- The operator and the verifier distrust each other. The operator must not hide information in the traffic, and the verifier must learn nothing beyond hashes 1.
- The facility is physically monitored, so that all traffic passes through the gateway 1.
- The operator stores all hashed data for the agreement's duration 1.
- Replay needs reproducible inference (Deterministic and bit-exact inference) 3 1.
- The MIRI overview models a covert adversary, deterred when the likelihood of detection times the cost of being caught exceeds the expected gain 3.
Evidence
- Designs and analysis. The Secure Gateway Device paper, Cankaya's feasibility note and the MIRI overview are design studies 1 2 3. The paper states that empirical validation is still required and calls for red-teaming by specialists 1.
- Commercial precedent. Taps are used for stock-exchange monitoring, packet capture, defence networks and lawful intercept 3. The MIRI overview says AI use needs changes for a nation-state covert adversary 3.
- Amodo's first tap test (March 2026). A passive multimode splitter on a link of about 10 Gbps copied both directions of traffic to a monitoring machine 5.
- Amodo's tap survey (May 2026). Commodity taps exist for 26 GBaud links, but none are advertised for 53 GBaud 6.
- Amodo's hashing benchmarks (July 2026). On an AMD EPYC server CPU, no tested hash algorithm reached line rate with 64-byte frames, and the tested DPU fell short of the 400 Gbps target 7.
- Amodo's tapped prototype (September 2026). A passive fibre tap on the 1 Gbps uplink of its inference-verification prototype fed a frame processor, which rebuilt inference requests and checked all other traffic against a whitelist 8. Amodo reports that all 800 test inferences were tapped and verified during a flood of about 1 Gbps of non-whitelisted traffic 8.
- SASH logger. SASH's public prototype passes every request through an inline software logger and re-runs it on a 270-million-parameter model; it computes no hashes of the traffic 9. See SASH confidential network logger.
Limitations
- Output steganography. The paper estimates about 40 Mbit/s of covert egress from output nondeterminism for a 200k-GPU cluster, even with replay checks 1. An attacker who chooses the prompts roughly doubles per-token leakage under Gumbel-based verification 11; see Deterministic and bit-exact inference and Bounding unexplained information in outputs.
- Line rate. On tested CPUs, no hash algorithm kept up with minimum-size frames, and the tested DPU was insufficient 7.
- Optics and copper. Passive taps are impractical on 400GBASE-SR8 multimode links, and copper-connected racks are much harder to tap 2. For 53 and 106 GBaud links, Amodo says a new ASIC may be needed 6.
- Encryption. TEE-protected fabrics would hide plaintext from both parties 2.
- Passive-tap side channels. Amodo concludes that its passive tap must become active 8.
- Bypass. Physical monitoring, and radio, power-line and thermal channels, are outside the network design 1; see Tamper evidence for verifier devices and Side-channel suppression for isolated facilities.
Known flaws
Published flaws, with their severity, kind and status. How flaws are rated.
Output nondeterminism leaves covert capacity
Hashing cannot remove information hidden in the outputs themselves. The Secure Gateway Device paper estimates that about 0.1 bit per token remains even with seed-synchronized replay checks. For a 200k-GPU inference cluster at full load (2,000 tokens per GPU per second), that is about 40 Mbit/s of covert egress, enough to move a 1 TB model in under three days. The paper names this the core remaining challenge and points to deterministic replay or active scrubbing of hardware-induced entropy 1. An independent study found that an adversary who chooses the prompts roughly doubles the bits leaked per token under Gumbel-based inference verification 11; see Bounding unexplained information in outputs.
Some links cannot be passively tapped
Encrypted fabrics hide plaintext from both parties
Cankaya notes that with TEE-protected sessions, neither the operator nor the manufacturer can recover session keys after the session, so tapped traffic could not be opened for recomputation. For other encrypted fabrics, the operator can retain keys 2.
Residual side channels in simple passive setups
Amodo's analysis of its own tapped prototype lists unvalidated header fields, timing of permitted traffic and variation in response formatting as residual channels, and concludes that the passive tap must be replaced by an active one 8.
Completeness rests on physical monitoring left out of scope
The Secure Gateway Device paper assumes the facility is physically monitored, and states that the whole architecture depends on the device being the only communication channel. It names radio emanation, power-line signalling and thermal channels as covert channels beyond that scope 1.
Verifier dictionary attacks on hashes
Hashes of very short outputs could be brute-forced by the verifier. The paper recommends hashing at least 5 tokens together, or at least 10 if the attacker filters for likely tokens 1.
Blockers
No tap or hashing hardware has been shown at production frontend link rates; on tested CPUs, no algorithm kept up with minimum-size frames.
Nondeterministic inference leaves covert capacity in outputs that hashing cannot remove.
Taps and gateway devices need tamper-evident housing and physical monitoring so that traffic cannot bypass them.
Radio, power-line and thermal channels are not addressed by network-level designs.
Red-teaming by specialists is called for but has not been reported.
Technical detail
Show technical detail
Secure Gateway Device (SeGaDev) 1:
- Placement. The device sits on the north-south boundary, between TLS termination at the frontend gateway and the internal fabric. If traffic is end-to-end encrypted internally, the device hashes ciphertext and the prover stores session keys 1.
- Pipeline. (1) Sanitization by an active warden, which replaces exploitable header fields (ephemeral source ports, TCP initial sequence numbers, session IDs) with pseudorandom values, keeps connection-tracking tables, and releases buffered packets on a fixed schedule to suppress timing and analogue modulation; (2) hashing of a configurable group of packets (the "hashing boundary") over payloads only; (3) transmission of hashes alone to the verifier on a dedicated fibre, with a passive splitter giving the prover a copy and a prover-controlled "timing warden" re-timing the hash stream 1.
- Shared randomness and timestamps. Shared pseudorandom values come from a commit-then-reveal coin flip between prover- and verifier-supplied generators, precomputed in bulk and consumed in FIFO order. Timestamps are taken by both parties on receipt of hashes, not by the tap 1 3.
- Audit. The verifier selects stored hashes; the prover returns preimages (prompt, output, token start index, token count) to a verification facility that replays the computation and compares hashes. With k random challenges, a misreported fraction p is detected with probability 1 − (1 − p)^k; k = 3,200 detects 0.1% misreporting at 96% confidence 1.
- Storage. A pessimistic upper bound (100k Hopper GPUs at 2,000 tokens/s each, one token per streaming frame) is about 200 PB of SHA-256 hashes and 1,260 PB of prover-held plaintext per year, about €22.5 million in drives 1.
- Dictionary attacks. Against verifier dictionary attacks on hashes of short outputs, the paper recommends at least 5 tokens per hashed template, or at least 10 if the attacker filters for likely tokens 1.
- Residual covert channels. A 10 ms re-timing window at 100 Gbps holds up to about 625k packets, so packet-count modulation must be fixed per connection per window. Output nondeterminism leaves about 0.1 bit per token even with seed-synchronized replay, which gives about 40 Mbit/s for 200k GPUs at 2,000 tokens/GPU/s. Feigned hardware failures give about 1 kbit/day 1.
- Line-rate hashing (Amodo). On an AMD EPYC 9354P with DPDK, all tested algorithms except BLAKE3 reached the receive baseline at 1500-byte frames once enough threads were used; at 64-byte frames none reached line rate within the CPU's physical core count. Offloading to the tested DPU did not reach the target. SipHash-1-3-128 was the leading candidate, and FPGA or ASIC hashing is expected to be needed for some plans 7.
- Passive optics (Amodo). Amodo computes a 1.45 dB link margin for a representative 53 GBaud link; a 95/5 split costs about 0.25 dB on the live leg and about 13 dB on the monitor leg 6.
Sources
- BN. Cankaya et al. (2026). Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors. arXiv. Source recordSupports: Secure Gateway Device architecture, goal, assumptions, scope, covert-channel estimates, storage, dictionary attacks, need for validation · abstract; §1; §3; §4.1–4.2; §5.1–5.3; §6; appendices A–C
- CN. Cankaya (2026). The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use. The Datacenter Lie Detector. Source recordSupports: tap definition; placement options and cost fractions; copper, multimode and encryption limits · sections on north-south, storage and compute-fabric taps; open problems
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: capture-everything principle; hashing over packet groups; failure conditions; perimeter size; commercial precedents; physical monitoring · §2b; §3.1–3.2; §5.1.1
- CR. Dean (2026). Verification Plan. AI 2040. Source recordSupports: passive frontend taps feeding a recomputation server · inference-only retrofitting proposal
- CAmodo Design (2026). Network Taps — A First Test. Amodo Design. Source recordSupports: first passive optical tap test at about 10 Gbps · whole note
- CAmodo Design (2026). Network Tapping for AI Verification: A Technical Assessment. Amodo Design. Source recordSupports: COTS tap availability by baud rate; optical budget; possible need for a new ASIC · BLUF; passive and active tap sections
- CAmodo Design (2026). Network Traffic Hashing. Amodo Design. Source recordSupports: line-rate hashing benchmarks on CPU and DPU · results and conclusions
- CAmodo Design (2026). Fitting a Network TAP to our Inference Verification Prototype. Amodo Design. Source recordSupports: tapped 1 Gbps prototype, whitelist, flood test result, residual side channels, need for active tap · setup, results and side-channel sections
- BSingapore AI Safety Hub (SASH) (2026). inference-verification: Inference Verification Prototype. GitHub. Source recordSupports: public prototype code of a network-logger demo: inline proxy, no hashing, 270M model · README; components/
- CSingapore AI Safety Hub (SASH) (2026). Internationalising AI Verification. SASH blog. Source recordSupports: confidential network logger prototype and planned FPGA certificates · whole post
- BN. Kezins (2026). Adversarial Entropy Inflation Against Gumbel-Based Inference Verification. arXiv. Source recordSupports: prompt-controlled attack roughly doubling per-token leakage under Gumbel-based inference verification · abstract