Tamper evidence for verifier devices

R2Demonstrated

Tamper evidence for verification hardware uses enclosures, seals and sensors to make physical interference visible, or to destroy the hardware's secrets when it happens.

The devices, such as network taps, gateways and recomputation servers, would sit in facilities the checked party controls. The tamper-respondent IBM 4765 module was validated at FIPS 140-2 Level 4. Nuclear safeguards and arms control use tamper-indicating enclosures.

Peer-reviewed prototypes detect probing through capacitive covers, radio waves inside server cases, or on-chip impedance sensing. As of September 2026 none has been built or evaluated for AI verifier hardware, and the MIRI overview lists retrofittable, mass-manufacturable enclosures for side-channel defence as an open problem. The main obstacles are scale, batteries and inspection burden.

The largest known weakness is that seals are often defeated with simple methods: a 1996 Los Alamos study defeated all 94 seals it examined. Any enclosure is only as good as its inspection protocol.

Readinessmedium confidence

Peer-reviewed tamper-detection results exist under stated adversaries, one in a running server, but no enclosure has been built or evaluated for AI verifier devices.

Rubric assessment

Assessed use: detecting tampering with verifier devices inside facilities the checked party controls

  • R1 met: enclosure designs with stated attacker models are published 4 5, and the MIRI overview describes their role in protecting verification hardware in a host-controlled facility 12.
  • R2 met: published end-to-end results exist under a stated adversary. Anti-Tamper Radio reliably detected needle insertions in a running 19-inch server over a 10-day experiment 5. Immler et al. report statistics over 115 batteryless covers, plus physical attacks against a stated 300 µm penetration model and environmental tests 4. On-chip impedance sensing detected board- and package-level tampering on commercial FPGA kits 8. All three are peer-reviewed; no public code or design files are cited for them.
  • R3 not met for this use: production-grade tamper-respondent modules exist 1, PHYSEC markets a radio-based tamper sensor for infrastructure enclosures 7, and tamper-indicating enclosures are used in safeguards and arms control 9, but none has been built for AI verifier devices such as optical taps, FPGA gateways or recomputation servers. The MIRI overview says it is less established what defences "can be retrofitted at a massive scale to prevent bypassing of network taps" 12. The mechanism's only implementation, AI 2040 inference-only verification stack, is a proposed architecture at R1.
  • R4 not met: the IBM 4765 was validated at FIPS 140-2 Level 4 1, but no enclosure has been independently evaluated on AI verifier devices.

Confidence is medium, because how far the server-scale and HSM results transfer to AI verifier hardware is a judgment call.

Gaps to the next level
  • An enclosure or sensing design built for AI verifier devices (taps, gateways, recomputation servers) and deployable at data-centre scale.
  • An independent public evaluation (red team or certification) of such an enclosure in the AI verification setting.
  • Inspection protocols suited to host-controlled AI facilities.

Assessed 2026-09-25 against rubric v1.1.

On this page

How it works

Verification hardware placed in a facility run by the party being checked needs protection against physical interference 12. The MIRI system overview relies on monitoring of the facility and on occasional random inspections of analog components and anti-tamper seals 12. Obermaier and Immler review enclosures from battery-backed monitoring to PUF-based designs 3. Published approaches fall into four groups:

  • Tamper-respondent modules. The IBM 4765 coprocessor uses a "protective, tamper-respondent matrix to monitor for intrusion and adverse physical conditions" 1. On a hard tamper, it actively erases its core secrets within microseconds 1.
  • Batteryless tamper-resistant covers. Immler et al. wrap the protected system in a flexible circuit-board cover with a fine electrode mesh 4. A key is derived from the mesh's capacitances, which act as a physical unclonable function (PUF), and decrypts the system's sensitive data only if the cover is intact 4.
  • System-level sensing. Anti-Tamper Radio monitors how radio waves propagate inside a metal case, so inserted objects change the measured response 5. ImpedanceVerif uses on-chip network analyzers on FPGAs to detect changes in a board's power distribution network, "without any modifications to the system" 8.
  • Tamper-indicating enclosures. In safeguards and arms control, these leave physical evidence of attack 9. They cover the case where an adversary bypasses a sealed opening, for example by drilling through a side 9.

In AI proposals, flexHEG pairs a guarantee processor with "a secure enclosure providing physical tamper protection" 14; see Hardware-enabled guarantees (flexHEG) and guarantee processors. The AI 2040 plan lists tamper-evident enclosures among physical security measures 13. The MIRI overview notes that standards exist for secure facilities (SCIFs) 12. What is less established, it says, is "what defenses can be retrofitted at a massive scale to prevent bypassing of network taps" 12.

What it establishes

Enclosures can show that a device was physically accessed 9, or can make a breach destroy the keys or data an attacker wants 1 4. They protect the integrity of other mechanisms, such as taps (Network taps and certifiers) and bandwidth shapers (Bandwidth limits and compartmentalization), rather than proving a claim on their own 12. Johnston argues that "a seal is no better than the protocols for using it" 11.

Threat model

  • Cover. Immler et al. "assume penetrations to be at least 300µm in diameter" 4. They deem cover removal impractical and do not assess chemical solvents 4.
  • Radio sensing. Anti-Tamper Radio defines success for the attacker as inserting a needle into a sensitive region without detection 5.
  • AI facilities. The host controls the facility, so the MIRI overview combines enclosures with continuous monitoring and random inspection 12.

Evidence

  • IBM 4765. Validated at FIPS 140-2 Level 4, overall and for physical security 1. NIST later moved the 2011 certificate to its historical list after a random-number-generator transition 2.
  • Batteryless covers. Immler et al. report statistics over 115 flexPCB covers, physical attacks and environmental testing, aiming at a physical security level comparable to FIPS 140-2 Level 3 4.
  • Anti-Tamper Radio. In a running 19-inch server over 10 days, it reliably detected 40 mm insertions of 1 mm needles 5. PHYSEC markets a product, PHYSEC SEAL, and reports that its anti-tamper radio sensor detects drilling or housing deformation in enclosures such as control cabinets 7.
  • ImpedanceVerif. It detected tampering on commercial FPGA development kits, including the proximity of contactless EM probes and a slightly polished chip package 8.
  • Tamper-indicating enclosures. They support IAEA safeguards and arms-control chain-of-custody regimes 9.

As of September 2026 no enclosure for AI verifier hardware has been evaluated in public. The MIRI overview lists "tamper-evident, rapidly mass-manufacturable and retrofittable enclosures" as an open question for side-channel defence 12.

Limitations

  • Seal defeats. In 1996 a Los Alamos team defeated all 94 seals it examined, with 132 defeats using low-tech methods; one practised person needed 4.3 minutes on average 10. Johnston reports that "high-tech seals are often easier to defeat than low-tech seals" 11.
  • Batteries. Battery-backed designs add bulk, limit the operating temperature range and fail when discharged 4.
  • Inspection and power. Visual methods on large enclosures face access limits, active approaches need power, and sensor data must be authenticated 9.
  • Drift. Anti-Tamper Radio's reference measurement can drift as the environment or the measurement system ages, which the authors suggest handling by gradually renewing the reference 5.

Known flaws

Published flaws, with their severity, kind and status. How flaws are rated.

  • Seals are often defeated with simple methodsSignificantDemonstrated attackOpen

    In 1996 a Los Alamos vulnerability assessment defeated all 94 security seals it examined, with 132 defeats in total, using rapid, inexpensive, low-tech methods. It found that seal cost did not predict security. In 2001 Johnston reported that high-tech seals are often easier to defeat than low-tech ones.

    Sources: [10] [11]
  • Security depends on inspection protocolsSignificantTheoretical argumentOpen

    Johnston argues that a seal is no better than the protocols for using it, and that inspectors are usually given little useful information on how to detect tampering. The Sandia survey notes that larger enclosures are hard to inspect fully and that sensor data must be authenticated.

    Sources: [9] [11]
  • Attack classes outside published modelsSignificantOpen questionOpen

    The authors of the batteryless cover say they cannot assess chemical-solvent attacks, which exceed their expertise, and deem cover removal impractical. Anti-Tamper Radio's reference can drift as the environment or measurement system ages; the authors suggest gradually renewing the reference. A 2025 follow-up by some of the same authors shows, by emulation on measured channel data, that an attacker who knows the reference channel and the needle's effect on it could inject a signal that cancels the change caused by a needle insertion. It proposes a reconfigurable intelligent surface that randomizes the channel as a countermeasure.

    Sources: [4] [5] [6]

Blockers

Technical detail

  • IBM 4765. FIPS 140-2 Level 4 overall and for physical security, validated in 2011. NIST later moved the certificate to its historical list after a random-number-generator transition 2. A tamper-respondent matrix monitors for intrusion and adverse conditions, with moderate and severe out-of-range temperature and voltage sensing. A hard tamper triggers active wiping of secrets: the high-speed-erase battery-backed RAM holding core secrets is erased within microseconds, and the module is zeroized and left inoperable 1.
  • Batteryless PUF cover. A 140 mm × 140 mm flexPCB cover with 16 × 16 electrodes (256 sensor nodes, 128 used differentially) and 100 µm line and space, checked by an STM32F303 microcontroller. After open- and short-circuit checks pass, a key is derived from the differential capacitances, about 5.2 bits of entropy per node with 10x oversampling (about 665 bits in theory). The attacker model assumes penetrations of at least 300 µm; single 0.3 mm holes made key reconstruction infeasible; a full-cover measurement with 10x oversampling takes 384 ms; power is about 0.6 W; testing spanned −20 °C to +60 °C 4.
  • Anti-Tamper Radio. Two wideband antennas inside a metal case, measured with a vector network analyzer (2–9 GHz) or ultra-wideband transceivers (2.496–7.488 GHz). In a Dell PowerEdge 2850 over 10 days, 40 mm insertions of 1 mm needles were reliably detected; in an empty aluminium box, 16 mm insertions of needles as thin as 0.1 mm were detected. UWB transceivers cost less than US$5 5.
  • ImpedanceVerif. An embedded network analyzer on an FPGA measures the frequency response of the power distribution network, and Wasserstein distance is used as the detection statistic 8.

Sources

  1. BIBM Corporation (2012). IBM 4765 Cryptographic Coprocessor Security Module: Security Policy. NIST Cryptographic Module Validation Program. Source recordSupports: FIPS 140-2 Level 4; tamper-respondent matrix; sensed conditions; zeroization · Table 1; §2 physical security; §8.1 Table 9
  2. ANational Institute of Standards and Technology (2011). Cryptographic Module Validation Program Certificate #1505: IBM 4765 Cryptographic Coprocessor Security Module. NIST Cryptographic Module Validation Program. Source recordSupports: IBM 4765 validation date and historical certificate status · certificate page
  3. AJ. Obermaier & V. Immler (2018). The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond. Journal of Hardware and Systems Security. Source recordSupports: existence of a review spanning battery-backed to PUF-based enclosures · title and abstract (full text not read)
  4. AV. Immler et al. (2019). Secure Physical Enclosures from Covers with Tamper-Resistance. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96. Source recordSupports: batteryless PUF cover design, attacker model, results, stated limitations, drawbacks of battery-backed enclosures · abstract; §2.1; §3.1; §8
  5. AP. Staat et al. (2022). Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems. 2022 IEEE Symposium on Security and Privacy. Source recordSupports: Anti-Tamper Radio concept, threat model, server experiment, costs, limitations · abstract; §III–§VI
  6. AM. S. Tabar et al. (2025). Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection. 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025). Source recordSupports: signal-injection (compensation) attack on Anti-Tamper Radio under a known-reference model; RIS countermeasure · abstract; §3.1; §4.2.1
  7. BPHYSEC GmbH (2026). PHYSEC SEAL: Change detection for maximum safety. PHYSEC website. Source recordSupports: PHYSEC reports a commercial anti-tamper radio sensor for infrastructure enclosures · product page
  8. AT. Mosavirik et al. (2023). ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325. Source recordSupports: on-chip impedance sensing for tamper detection · abstract
  9. BH. A. Smartt & Z. N. Gastelum (2015). Tamper-Indicating Enclosures, A Current Survey. Sandia National Laboratories, SAND2015-4251C. Source recordSupports: tamper-indicating enclosures in verification regimes; approaches; limitations · abstract; survey sections
  10. BR. G. Johnston & A. R. E. Garcia (1996). Physical Security and Tamper-Indicating Devices. Los Alamos National Laboratory, LA-UR-96-3827. Source recordSupports: seal vulnerability assessment results; mean defeat time for one practised person · abstract; results; Table 2
  11. AR. G. Johnston (2001). Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials. The Nonproliferation Review, Spring 2001, pp. 102–114. Source recordSupports: high-tech vs low-tech seals; role of protocols and inspector training · main text
  12. BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: enclosure needs in low-trust AI verification; open question on retrofittable enclosures for side-channel defence; inspections · §2b; §4.2; §5.3.1
  13. CR. Dean (2026). Verification Plan. AI 2040. Source recordSupports: tamper-evident enclosures among physical security measures · physical security discussion
  14. BJ. Petrie et al. (2025). Flexible Hardware-Enabled Guarantees for AI Compute. arXiv. Source recordSupports: flexHEG secure enclosure for physical tamper protection · abstract

M-0017JSONSource-checked 2026-09-25 · changed 2026-09-28Suggest an edit

Also called Tamper-evident enclosures; Tamper-respondent enclosures; Tamper-indicating enclosures; Anti-tamper sensing

Search

Full search page