Mechanism · Side-channel suppression for isolated facilities
Evidence & limits
On this page
R1Proposed for bounding physical covert channels out of a verified enclosure
One public design study gives costs and assumptions. Nothing has been built or measured.
Assessed use: bounding physical covert channels out of a verified enclosure
Rubric assessment
- R1 met: Cankaya publicly describes a design with its goal (bounding covert capacity around a verified enclosure to a tolerable rate), the channel classes it addresses, defences, cost estimates and assumptions 1.
- R2 not met: Cankaya describes the work as a two-week research sprint that is far from conclusive, and calls for prototyping and red-teaming 1. Components such as shielded enclosures and commercial power-line filters exist as products 1, but as of September 2026 no integrated build for an AI facility, or measurement of one, has been published. The mechanism's implementations, RAND secure inference data center (SIDC) design, AI 2040 inference-only verification stack and Low-trust AI compute verification system overview, are proposed architectures at R1.
Confidence is medium: a single tier C source carries the design, but its author states plainly that nothing has been prototyped.
- A prototype enclosure for at least one AI rack or scalable unit, with measured attenuation for each channel class.
- A red-team exercise against the prototype by a stated adversary.
- Validated costs for filters, jamming and optical conversion at production scale.
Assessed 2026-09-25 against rubric v1.1.
Mechanism properties
| Threat model | Adversarial prover |
|---|---|
| Adversarial evaluation | Analysis |
| Hardware needed | Retrofit device |
| Prover cooperation | Partial |
| Confidentiality | Preserving |
Evidence
Peer-reviewed attacks show that ML hardware leaks information through physical side channels:
- BarraCUDA used correlation electromagnetic analysis to recover parameters of convolutional networks running on NVIDIA Jetson devices 3.
- Kraken extracted parameters from GPU Tensor Core units, and showed that GPU electromagnetic radiation leaks even 100 cm away through a glass obstacle 4.
- DeepTheft recovered the structure of DNN models on general-purpose processors through the RAPL power interface, reporting 99.75% Levenshtein-distance accuracy 5.
These attacks show leakage, not deliberate covert signalling 3 4 5. Cankaya also surveys published covert-channel demonstrations across the channel classes above 1.
For suppression itself, the evidence is one paper design 1. It estimates $35,000–$150,000 per 8-rack scalable unit, about 0.1–0.5% of hardware cost at an assumed $4 million per rack 1. Cankaya describes it as a first-pass viability study and asks for prototypes and adversarial feedback 1.
Limitations
- Untested design. It has not been prototyped or red-teamed 1.
- Supply-chain implants. Hardware implanted in purchased components may evade inspection 1.
- Openings. Airflow, power cabling and optical links complicate shielding 1.
- Inspection limits. It is unclear whether destructive teardown favours defender or attacker 1.
- Cost uncertainty. Volume costs of power-line filters are hard to estimate, because existing products are mostly made to order 1. For pre-training, optical conversion would need hundreds of high-performance transceivers per pod, which Cankaya puts within single-digit percent of the cost of the monitored servers 1.
- Deterrence. Part of the defence rests on psychological deterrence, created by keeping the sensors' exact capabilities unknown to the prover 1.
Known flaws
Blockers
No prototype or red-team exists; the design is a first-pass viability study.
Volume costs of TEMPEST-grade power-line filters are uncertain, because existing products are mostly made to order.