Mechanism · Workload classification from telemetry and side channels

Sources

On this page
  1. BR. Rahman & S. Tajdari (2026). Detecting Hidden ML Training With Zero-Overhead Telemetry. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: NVML-based classifier, corpus, cross-validated accuracy, evasion families and rounds, hardened detection of unseen strategies, threat model, trust assumption, code statement, limitations · Abstract; §2.1, §2.2, §4.1-4.3, §5.1-5.2 and Table 5, §6.5; App. F
  2. BS. Gargiulo & G. Kulp (2026). Workload Identification with Physical Side Channels for AI Governance. arXiv. Source recordSupports: external power-probe classifier, accuracy on unseen model families, evasion strategies, hardened detection and costs, dataset release, NVML spoofing argument, limitations · Abstract; §2-4; limitations
  3. BS. Ansari (2026). Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification. arXiv. Source recordSupports: workload-classification and power-monitoring feasibility; training-inference boundary · §3.1 (M2, M4); §4.6
  4. CAmodo Design (2026). Understanding Data Center Power Delivery. Amodo Design. Source recordSupports: power delivery hierarchy filters signals; low-level monitoring harder to spoof · whole note
  5. AI. Latif et al. (2025). Single-Node Power Demand During AI Training: Measurements on an 8-GPU NVIDIA H100 System. IEEE Access, vol. 13, pp. 61740–61747. Source recordSupports: measured training power of an 8-GPU H100 node · Abstract
  6. BT. Gregersen et al. (2024). Input-Dependent Power Usage in GPUs. SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis (Sustainable Supercomputing workshop), pp. 1872–1877. Source recordSupports: input data changes GEMM power draw · Abstract
  7. AA. Gangwal et al. (2020). Detecting Covert Cryptomining Using HPC. Cryptology and Network Security – CANS 2020, LNCS 12579, pp. 344–364. Source recordSupports: precedent: counter-based detection of covert cryptomining · Abstract; evaluation
  8. BZ. Chen et al. (2025). Detecting Anomalies in Machine Learning Infrastructure via Hardware Telemetry. arXiv. Source recordSupports: precedent: operator-accessible hardware signals for workload-agnostic anomaly detection · Abstract; §3, §4.1
  9. AY. Gao et al. (2024). DeepTheft: Stealing DNN Model Architectures through Power Side Channel. 2024 IEEE Symposium on Security and Privacy. Source recordSupports: power traces can leak model architecture · Abstract
  10. AE. Seferis & T. Fist (2026). Detecting Compute Structuring in AI Governance Is Likely Feasible. Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment). Source recordSupports: compute-structuring detection: per-workload classification, aggregation of a customer's sequential or data-exchanging workloads against thresholds; analysis only; failure mode with very low data exchange · threat models; Algorithms 1–2; limitations
  11. AZ. Yang et al. (2024). Accurate and Convenient Energy Measurements for GPUs: A Detailed Study of NVIDIA GPU's Built-In Power Sensor. SC24: International Conference for High Performance Computing, Networking, Storage and Analysis. Source recordSupports: nvidia-smi power readings (via NVML) sample only 25% of runtime on A100 and H100; error about ±5% versus NVIDIA's claimed ±5 W · Abstract; accuracy findings

Search

Full search page