Mechanism · Workload classification from telemetry and side channels

Evidence & limits

On this page

R2Demonstrated for telling training from inference and other work using genuine telemetry, including disguised workloads

Two preprints publish end-to-end results on current GPUs against stated, iterated adversaries; nobody independent has evaluated them.

Assessed use: telling training from inference and other work using genuine telemetry, including disguised workloads

Rubric assessment

  • R1 met: the claim, signals and threat model are publicly described 1 2 3.
  • R2 met: Rahman and Tajdari evaluate 9 current NVIDIA GPU models against 20 evasion strategy families over five rounds of monitor–evader iteration, with method and setup described in enough detail to repeat 1. They state that their workload source code is in the project repository, but the paper gives no link 1. Gargiulo and Kulp classify workloads on an H200 from externally measured power, test four evasion strategies and report releasing their recordings as a dataset 2.
  • R3 not met: no party other than the developers is reported to rely on these classifiers for a verification decision, and no production-grade system is available.
  • R4 not met: no independent adversarial evaluation has been published.

Confidence is medium: both results come from single machines, and the location of Rahman and Tajdari's code is not given.

Gaps to the next level
  • Reliance by a verifier other than the developers, or a production-grade, available system.
  • An independent red-team or peer-reviewed security analysis.
  • Results at multi-node cluster scale and across hardware vendors.
  • A tamper-resistant, authenticated telemetry path (see On-chip telemetry from timing, memory and performance counters), or physical sensing validated across devices.

Assessed 2026-10-08 against rubric v1.1.

Evidence

  • Software telemetry. Rahman and Tajdari ran five rounds of monitor–evader iteration over 20 evasion strategy families on 9 GPU models spanning four architecture generations 1. They report 98.2% accuracy across their corpus 1. After hardening, strategies seen in training were always detected, but white-box strategies held out from training were detected only 43–87% of the time 1.
  • External power. Gargiulo and Kulp report 97% accuracy on held-out model families from a probe on one H200 NVL 2. Their hardened detector caught three of four held-out evasion strategies at least 99% of the time, and diluted LoRA 48–88% of the time, or at least 98% with an added rule 2. They report releasing their 1,610 recordings as a dataset, and state that their attacks are not a comprehensive adversarial evaluation 2.
  • Earlier assessment. Before these papers, Ansari rated workload classification as deployable in cooperative settings and near-term in adversarial settings 3.

Limitations

  • Forged or replayed telemetry. A privileged operator can forge or replay software-read counters unless hardware protects the read path 1 2.
  • Unseen evasion strategies. Detection falls to 43–87% for held-out white-box strategies on NVML telemetry 1, and to 48–88% for diluted LoRA on external power before an added rule 2. In Gargiulo and Kulp's tests the evasion strategies cost 28.1–69.3% of throughput 2.
  • Scale. Results are single-node and NVIDIA-only 1, or from one H200 2.
  • Power sampling. Yang and colleagues found that on A100 and H100 GPUs the built-in power reading, which nvidia-smi obtains through NVML, samples only 25% of runtime. The GPU can draw very different power in the other 75% without the reading showing it 11. They also found the reading's error to be within about ±5% in most cases, against the ±5 W that NVIDIA claims 11.
  • Distributed training. Ansari reports that classification accuracy degrades when training is distributed across providers 3. Seferis and Fist propose that cloud providers classify each workload, then add up the compute of one customer's workloads that run in sequence or exchange data above a bandwidth threshold, and flag totals above a regulatory threshold 10. Their proposal is an analysis without empirical tests, and they note that it fails if decentralized training becomes possible with very little data exchange 10.
  • Blurring categories. The training-inference distinction may lose governance value 3.
  • Spoofed power monitoring. Amodo expects that power monitoring can likely be spoofed, but still sees value in it as a complement to other verification systems 4.

Known flaws

Blockers

Search

Full search page