Mechanism · On-chip telemetry from timing, memory and performance counters
Sources
On this page
- BS. K. Monfared et al. (2026). Timing and Memory Telemetry on GPUs for AI Governance. arXiv. Source recordSupports: four timing and memory primitives, threat model, T4/H100 results, residency-test conditions, overheads, limitations · §3-§6, Figs. 5, 8, 10, 12, 15
- BJ. Petrie (2025). Guaranteeable Memory: An HBM-Based Chiplet for Verifiable AI Workloads. ICML 2025 Workshop on Technical AI Governance. Source recordSupports: guarantee chiplet under HBM observing memory traffic; HBM-standard compatibility; independence from the accelerator die · Abstract (read via ICML 2025 virtual site; OpenReview PDF not reachable)
- BR. Rahman & S. Tajdari (2026). Detecting Hidden ML Training With Zero-Overhead Telemetry. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: NVML counter classifier, trust assumptions, GPU models, accuracy and evasion results, code statement, limitations · Abstract; threat model; results; limitations
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: existing on-device counters and their use for metering · p. 19
- BA. O'Gara et al. (2025). Hardware-Enabled Mechanisms for Verifying Responsible AI Development. arXiv. Source recordSupports: candidate metering targets · §2.2.2, §2.5.2, Table 1
- CGloria Z (2026). On TEEs for Privacy-Preserving Monitoring in AI Governance. MIRI Technical Governance Team. Source recordSupports: counters as side channel; memory-residency and random challenges; completeness of workload declarations
- BNVIDIA (2025). NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper). NVIDIA documentation. Source recordSupports: performance counters disabled in full CC mode, and NVIDIA's side-channel rationale · p. 18
- AZ. Yang et al. (2024). Accurate and Convenient Energy Measurements for GPUs: A Detailed Study of NVIDIA GPU's Built-In Power Sensor. SC24: International Conference for High Performance Computing, Networking, Storage and Analysis. Source recordSupports: nvidia-smi power readings (via NVML) sample only 25% of runtime on A100 and H100; error about ±5% versus NVIDIA's claimed ±5 W · Abstract; accuracy findings
- BC. Shrauder & G. Frederick (2026). Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization. NVIDIA Technical Blog. Source recordSupports: NVIDIA Fleet Intelligence: general availability, read-only open-source host agent, telemetry collected, signed attestation evidence (provider self-description) · blog post