Mechanisms · category

Off-chip devices & sensors

Retrofittable devices outside the accelerator: network taps and certifiers, power and analog sensors, tamper-evident enclosures.

NameTypeReadinessVerifiesThreat model
Bandwidth limits and compartmentalization
Capping or removing network links between groups of accelerators, so that serving within each group still works but large training across groups becomes far slower.
MechanismR2DemonstratedAdversarial prover
Tamper evidence for verifier devices
Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating.
MechanismR2DemonstratedAdversarial prover
Workload classification from telemetry and side channels
Telling whether chips are training, serving or doing non-AI work from GPU counters or power draw, signals that do not read weights or data.
MechanismR2DemonstratedAdversarial prover
AI 2040 inference-only verification stack
A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs.
ImplementationR1ProposedAdversarial prover
Low-trust AI compute verification system overview
A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records.
ImplementationR1ProposedAdversarial prover
Network taps and certifiers
Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work.
MechanismR1ProposedAdversarial prover
RAND secure inference data center (SIDC) design
A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.
ImplementationR1ProposedSemi-trusted prover
SASH confidential network logger
An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference.
ImplementationR1ProposedSemi-trusted prover
Side-channel suppression for isolated facilities
Shielding, filtering, jamming and inspecting an AI facility to limit hidden physical communication around monitored network links.
MechanismR1ProposedAdversarial prover

Includes records that list this as a secondary category. Claims in grey italics are supported rather than aimed at.

Search

Full search page