Mechanism · Side-channel suppression for isolated facilities
Sources
On this page
- CN. Cankaya (2026). Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses. MIRI Technical Governance Team. Source recordSupports: setting, threat framing, channel classes, Shannon-Hartley framing, defences, attenuation figures, costs, assumptions, residual risks · whole post; bill-of-materials table; residual-risk discussion
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: side-channel suppression as part of a low-trust inference verification design; covert side-channel bandwidth target · §5.3.1
- AP. Horvath et al. (2025). BarraCUDA: Edge GPUs do Leak DNN Weights. 34th USENIX Security Symposium. Source recordSupports: EM side channel leaks DNN parameters on edge GPUs · Abstract
- AP. Horvath et al. (2026). Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field. IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026). Source recordSupports: EM leakage from GPU Tensor Cores, including at 100 cm through glass · Abstract
- AY. Gao et al. (2024). DeepTheft: Stealing DNN Model Architectures through Power Side Channel. 2024 IEEE Symposium on Security and Privacy. Source recordSupports: RAPL power side channel recovers DNN architectures; 99.75% Levenshtein-distance accuracy · Abstract
- BS. Ansari (2026). Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification. arXiv. Source recordSupports: side-channel attacks on on-chip security implementations within reach of commercial tooling · §4.3
- Cjoshc (2026). Can governments quickly and cheaply slow AI training?. AI Alignment Forum. Source recordSupports: independent public analysis of residual low-bandwidth paths and covert RL-training strategies · §2.3; §3.4; §4