Network tap

A network tap is a device that copies the traffic on a network link for inspection without disrupting normal operation 1.

Passive taps observe without interfering, for example by optically splitting the light in a fibre; active taps interact with the traffic, for instance by re-timing it or modifying headers to reduce covert channels 1. RAND's verification framework includes mutually vetted devices that intercept data exchanged between accelerators and check it for discrepancies with declared uses 2. In proposed designs such as network taps and certifiers, taps send out hashes of the traffic as cryptographic commitments instead of plaintext, so that the prover's declarations can later be checked against them 1 3. Cankaya describes taps on the front-end links between a data centre and the outside world as the most viable, because those links carry little bandwidth 1. The back-end fabric between accelerators has far higher bandwidth and strict latency requirements, and may call for random sampling rather than full capture 1.

Related

Used in

Sources

  1. CN. Cankaya (2026). The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use. The Datacenter Lie Detector. Source recordSupports: definition; passive vs active taps; taps commit to traffic by hashing; front-end links most viable; back-end fabric bandwidth, latency and sampling · sections on definitions, north-south and east-west links
  2. BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: mutually vetted devices intercept inter-chip data and check against declared uses · §4.2
  3. BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: fixed-function taps that send hashes of packet groups, not plaintext · evidence capture

Search

Full search page