Mechanisms · category
Isolation & system architectures
Ways of arranging or constraining a facility so that other checks become possible: bandwidth limits, compartmentalization, memory wiping, secure facilities, whole verification stacks.
| Name | Type | Readiness | Verifies | Threat model |
|---|---|---|---|---|
| Bandwidth limits and compartmentalization Capping or removing network links between groups of accelerators, so that serving within each group still works but large training across groups becomes far slower. | Mechanism | R2Demonstrated | Adversarial prover | |
| Bounding unexplained information in outputs Limits the hidden information a facility's outputs can carry by measuring how much of those outputs the declared computation fails to predict. | Mechanism | R2Demonstrated | Adversarial prover | |
| Tamper evidence for verifier devices Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating. | Mechanism | R2Demonstrated | Adversarial prover | |
| AI 2040 inference-only verification stack A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs. | Implementation | R1Proposed | Adversarial prover | |
| Hardware-enabled guarantees (flexHEG) and guarantee processors Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used. | Mechanism | R1Proposed | Adversarial prover | |
| Low-trust AI compute verification system overview A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records. | Implementation | R1Proposed | Adversarial prover | |
| Memory wiping and proofs of secure erasure Overwriting a device's memory in a way a verifier can check, so that data from earlier, undeclared work cannot persist in memory the wipe reaches. | Mechanism | R1Proposed | Adversarial prover | |
| RAND secure inference data center (SIDC) design A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers. | Implementation | R1Proposed | Semi-trusted prover | |
| Side-channel suppression for isolated facilities Shielding, filtering, jamming and inspecting an AI facility to limit hidden physical communication around monitored network links. | Mechanism | R1Proposed | Adversarial prover | |
| Whole-workload recomputation (reproducible packets) Organizing all AI workloads in a facility into discrete, reproducible units, so that a verifier can recompute a random sample and check each one. | Mechanism | R1Proposed | Adversarial prover |
Includes records that list this as a secondary category. Claims in grey italics are supported rather than aimed at.