Mechanism · Tamper evidence for verifier devices

Evidence & limits

On this page

R2Demonstrated for detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence

Peer-reviewed tamper-detection results exist under stated adversaries, one in a running server, but no enclosure has been built or evaluated for AI verifier devices. The running-server tests are representative in hardware, satisfying R2, while an integrated AI verifier enclosure remains unbuilt 5 12.

Assessed use: detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence

Rubric assessment

  • R1 met: enclosure designs with stated attacker models are published 4 5, and the MIRI overview describes their role in protecting verification hardware in a host-controlled facility 12.
  • R2 met: published end-to-end results exist under a stated adversary. Anti-Tamper Radio reliably detected needle insertions in a running 19-inch server over a 10-day experiment 5. Immler et al. report statistics over 115 batteryless covers, plus physical attacks against a stated 300 µm penetration model and environmental tests 4. On-chip impedance sensing detected board- and package-level tampering on commercial FPGA kits 8. All three are peer-reviewed; no public code or design files are cited for them.
  • R3 not met for this use: production-grade tamper-respondent modules exist 1, PHYSEC markets a radio-based tamper sensor for infrastructure enclosures 7, and tamper-indicating enclosures are used in safeguards and arms control 9, but none has been built for AI verifier devices such as optical taps, FPGA gateways or recomputation servers. The MIRI overview says it is less established what defences "can be retrofitted at a massive scale to prevent bypassing of network taps" 12. The mechanism's only implementation, AI 2040 inference-only verification stack, is a proposed architecture at R1.
  • R4 not met: the IBM 4765 was validated at FIPS 140-2 Level 4 1, but no enclosure has been independently evaluated on AI verifier devices.

Confidence is medium, because how far the server-scale and HSM results transfer to AI verifier hardware is a judgment call.

Gaps to the next level
  • An enclosure or sensing design built for AI verifier devices (taps, gateways, recomputation servers) and deployable at data-centre scale.
  • An independent public evaluation (red team or certification) of such an enclosure in the AI verification setting.
  • Inspection protocols suited to host-controlled AI facilities.

Assessed 2026-10-08 against rubric v1.1.

Evidence

  • IBM 4765. Validated at FIPS 140-2 Level 4, overall and for physical security 1. NIST later moved the 2011 certificate to its historical list after a random-number-generator transition 2.
  • Batteryless covers. Immler et al. report statistics over 115 flexPCB covers, physical attacks and environmental testing, aiming at a physical security level comparable to FIPS 140-2 Level 3 4.
  • Anti-Tamper Radio. In a running 19-inch server over 10 days, it reliably detected 40 mm insertions of 1 mm needles 5. PHYSEC markets a product, PHYSEC SEAL, and reports that its anti-tamper radio sensor detects drilling or housing deformation in enclosures such as control cabinets 7.
  • ImpedanceVerif. It detected tampering on commercial FPGA development kits, including the proximity of contactless EM probes and a slightly polished chip package 8.
  • Tamper-indicating enclosures. They support IAEA safeguards and arms-control chain-of-custody regimes 9.

As of September 2026 no enclosure for AI verifier hardware has been evaluated in public. The MIRI overview lists "tamper-evident, rapidly mass-manufacturable and retrofittable enclosures" as an open question for side-channel defence 12.

Limitations

  • Evaluation scope. Published device and seal studies provide context; the MIRI overview leaves enclosures for AI verifier hardware as an open engineering question 12. The radio compensation attack is emulated on measured data 6.
  • Seal defeats. In 1996 a Los Alamos team defeated all 94 seals it examined, with 132 defeats using low-tech methods; one practised person needed 4.3 minutes on average 10. Johnston reports that "high-tech seals are often easier to defeat than low-tech seals" 11.
  • Batteries. Battery-backed designs add bulk, limit the operating temperature range and fail when discharged 4.
  • Inspection and power. Visual methods on large enclosures face access limits, active approaches need power, and sensor data must be authenticated 9.
  • Drift. Anti-Tamper Radio's reference measurement can drift as the environment or the measurement system ages, which the authors suggest handling by gradually renewing the reference 5.

Known flaws

Blockers

Search

Full search page