Mechanism · Off-chip devices & sensors
Side-channel suppression for isolated facilities
Shielding, filtering, jamming and inspecting an AI facility so that no hidden physical channel can bypass the checks placed on its official links.
Also called Covert-channel suppression; TEMPEST-style shielding for verification; Retrofitted side-channel defences
Summary
Some verification designs watch every official network link out of an AI cluster. They only work if data cannot leave or enter by another route, such as radio emissions, sound, vibration or signals on power lines. Side-channel suppression retrofits the facility with metal enclosures, filters, jamming, vibration isolation and inspections. The aim is to push any hidden channel's capacity down to a tolerable few kilobits per second. One published design estimates the cost at about 0.1–0.5% of hardware cost. Its author calls it a first-pass study. As of September 2026 no build has been prototyped, measured or red-teamed; that validation gap is the main obstacle. The biggest known weaknesses are hardware implanted in the supply chain, which inspection may miss, and the difficulty of keeping shielding intact around airflow, cabling and optical links.
R1: one public design study with costs and assumptions; nothing has been built or measured.
Rubric assessment
- R1 met: Cankaya publicly describes a design with its goal (bounding covert capacity around a verified enclosure to a tolerable rate), the channel classes it addresses, defences, cost estimates and assumptions 1.
- R2 not met: Cankaya describes the work as a two-week research sprint that is far from conclusive, and calls for prototyping and red-teaming 1. Components such as shielded enclosures and commercial power-line filters exist as products 1, but as of September 2026 no integrated build for an AI facility, or measurement of one, has been published. The mechanism's implementations, RAND secure inference data center (SIDC) design, AI 2040 inference-only verification stack and Low-trust AI compute verification system overview, are proposed architectures at R1.
Confidence is medium: a single tier C source carries the design, but its author states plainly that nothing has been prototyped.
- A prototype enclosure for at least one AI rack or scalable unit, with measured attenuation for each channel class.
- A red-team exercise against the prototype by a stated adversary.
- Validated costs for filters, jamming and optical conversion at production scale.
How it works
Several verification designs place checks on the official links of an AI cluster, for example network taps between accelerators (Network taps and certifiers) 1. Cankaya points out that these checks only hold if the facility cannot move significant data by some other physical route 1. Side-channel suppression retrofits an untrusted facility so that any such route has negligible capacity 1.
Cankaya surveys these classes of physical channel 1:
- electromagnetic radiation, through the air and through optical fibre;
- airborne acoustics;
- acoustic signals carried through solids and through coolant water;
- signals conducted along power lines and water columns;
- physical access, such as covert devices.
Instead of eliminating every channel, the design accepts a small residual rate, in the single-digit kilobits per second, to keep defence costs manageable 1. It reasons from information theory: a channel's capacity depends on its bandwidth and its signal-to-noise ratio, so defences either weaken the signal or raise the noise 1.
The proposed defences, grouped by channel, are 1:
- Electromagnetic. Sheet-metal enclosures with bent cable conduits, metal barriers between racks, directional radio jamming, and radio sensors that monitor during or between jamming.
- Power lines. Commercial TEMPEST-grade filters.
- Optical fibre. Optical-electrical-optical conversion at the enclosure boundary, and inspection for undeclared optical components.
- Acoustic. Enclosures and air vents that do not face each other, plus air gaps and vibration isolation between and under racks.
- Inspection. Guards, unannounced inspections and destructive teardowns looking for hidden antennae.
What it establishes
If it works as designed, suppression bounds the capacity of unmonitored physical channels out of an enclosure 1. Other checks can then treat the monitored links as the only significant path for data (Bandwidth limits and compartmentalization, Bounding unexplained information in outputs) 1.
It does not establish:
- What the computation is. It only makes the other verification layers harder to bypass 1.
- Zero leakage. The design deliberately tolerates single-digit kilobits per second 1.
Side-channel attacks on verification hardware itself are a separate concern 6. Ansari notes that differential power analysis and electromagnetic attacks on compact cryptographic implementations are within reach of commercially available tooling 6.
Threat model
- Adversary. Cankaya assumes a well-resourced, nation-state adversary constrained only by physics 1. He argues that verification favours the defender because "the attacker loses if caught even once" 1.
- Physical security. Physical security involves several organizations and includes guards and unannounced inspections 1.
- Inspection. Inspections of sampled units catch any flaw present, which allows statistical bounds from sampling 1.
Evidence
Peer-reviewed attacks show that ML hardware leaks information through physical side channels:
- BarraCUDA used correlation electromagnetic analysis to recover parameters of convolutional networks running on NVIDIA Jetson devices 3.
- Kraken extracted parameters from GPU Tensor Core units, and showed that GPU electromagnetic radiation leaks even 100 cm away through a glass obstacle 4.
- DeepTheft recovered the structure of DNN models on general-purpose processors through the RAPL power interface, reporting 99.75% Levenshtein-distance accuracy 5.
These attacks show leakage, not deliberate covert signalling 3 4 5. Cankaya also surveys published covert-channel demonstrations across the channel classes above 1.
For suppression itself, the evidence is one paper design 1. It estimates $35,000–$150,000 per 8-rack scalable unit, about 0.1–0.5% of hardware cost at an assumed $4 million per rack 1. Cankaya describes it as a first-pass viability study and asks for prototypes and adversarial feedback 1.
Limitations
- Untested design. It has not been prototyped or red-teamed 1.
- Supply-chain implants. Hardware implanted in purchased components may evade inspection 1.
- Openings. Airflow, power cabling and optical links complicate shielding 1.
- Inspection limits. It is unclear whether destructive teardown favours defender or attacker 1.
- Cost uncertainty. Filter costs vary widely, and optical conversion depends on the supply of many high-performance transceivers per pod 1.
- Deterrence assumptions. Keeping sensor capabilities unknown to the prover may deter attacks, but it makes the adversary assumptions hard to test 1.
Known flaws
Published flaws, with their severity, kind and status. How flaws are rated.
Supply-chain implants may evade inspection
Cankaya identifies malicious hardware embedded deep in purchased components as a residual risk that visual inspection and disassembly may not catch. He notes that radiographic examination under high-security standards could mitigate it 1.
Openings for airflow, power and optics weaken shielding
Cankaya notes that keeping attenuation high while passing high-power airflow, cabling and optical links adds complexity beyond existing shielded-enclosure specifications 1.
Inspection assumptions may not hold
The design's statistical argument assumes that visual or disassembly inspection catches every flaw that is present in a sampled unit. Cankaya is unsure whether destructive teardowns are defence-dominant or offence-dominant 1.
Blockers
No prototype or red-team exists; the design is a first-pass viability study.
Costs of power-line filters, and supply of the transceivers needed for optical conversion, are uncertain at scale.
Technical detail
Show technical detail
- Capacity target. Cankaya frames suppression with the Shannon-Hartley limit C = B log2(1 + SNR). Defences either lower the signal power or raise the noise floor. Holding capacity to 1 kbit/s over 1 GHz of bandwidth needs an SNR of about −62 dB or less 1.
- Shielding. Enclosures built to NSA specification 94-106 are cited at −100 dB of attenuation from 100 MHz to 10 GHz 1. Cable conduits should have at least two right-angle turns, and each turn gives an estimated 15–25 dB of diffraction loss at ultrasonic wavelengths. Air vents should not face each other 1.
- Jamming and monitoring. Radio monitoring can run behind jamming using continuous or interrupted look-through, and a commodity-radio demonstration of continuous look-through is cited at 39 dB of suppression 1.
- Cost. Each 8-rack scalable unit has 64 power cables ("whips") to filter. Cankaya's bill of materials for one scalable unit totals $35,000–$150,000, about 0.1–0.5% of the hardware cost at an assumed $4 million per rack 1.
Sources
- CN. Cankaya (2026). Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses. MIRI Technical Governance Team. Source recordSupports: setting, threat framing, channel classes, Shannon-Hartley framing, defences, attenuation figures, costs, assumptions, residual risks · whole post; bill-of-materials table; residual-risk discussion
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: side-channel suppression as part of a low-trust inference verification design; covert side-channel bandwidth target · §5.3.1
- AP. Horvath et al. (2025). BarraCUDA: Edge GPUs do Leak DNN Weights. 34th USENIX Security Symposium. Source recordSupports: EM side channel leaks DNN parameters on edge GPUs · Abstract
- AP. Horvath et al. (2026). Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field. IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026). Source recordSupports: EM leakage from GPU Tensor Cores, including at 100 cm through glass · Abstract
- AY. Gao et al. (2024). DeepTheft: Stealing DNN Model Architectures through Power Side Channel. 2024 IEEE Symposium on Security and Privacy. Source recordSupports: RAPL power side channel recovers DNN architectures; 99.75% Levenshtein-distance accuracy · Abstract
- BS. Ansari (2026). Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification. arXiv. Source recordSupports: side-channel attacks on on-chip security implementations within reach of commercial tooling · §4.3