01 / The mechanism and its boundary
What the technique establishes
Network taps copy the traffic on a data centre's cables. In verification proposals, a tap or "secure gateway" hashes everything entering and leaving a cluster. The verifier later asks the operator to reveal randomly chosen records, which are recomputed and checked. The aim is to show that outputs came from declared work, and that results of undeclared work cannot leave covertly through the tapped links. Designs, cost estimates and covert-channel analyses are public. Amodo's tests have copied traffic from 1–10 Gbps links without hashing it. As of September 2026 no tap has been demonstrated at production link rates or red-teamed. The main obstacles are hashing minimum-size frames at line rate on 400G-class links, and tapping copper or encrypted fabrics. The largest known weakness is covert signalling in model outputs: one design estimates about 40 Mbit/s for a 200,000-GPU inference cluster, even with replay checks, unless inference becomes deterministic.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- Retrofit device
- Prover cooperation
- Required
- Confidentiality
- Partial
- Category
- Off chip devices & sensors
Technical detail and cited results
Secure Gateway Device (SeGaDev) S-1300:
- Placement. The device sits on the north-south boundary, between TLS termination at the frontend gateway and the internal fabric. If traffic is end-to-end encrypted internally, the device hashes ciphertext and the prover stores session keys S-1300.
- Pipeline. (1) Sanitization by an active warden, which replaces exploitable header fields (ephemeral source ports, TCP initial sequence numbers, session IDs) with pseudorandom values, keeps connection-tracking tables, and releases buffered packets on a fixed schedule to suppress timing and analogue modulation; (2) hashing of a configurable group of packets (the "hashing boundary") over payloads only; (3) transmission of hashes alone to the verifier on a dedicated fibre, with a passive splitter giving the prover a copy and a prover-controlled "timing warden" re-timing the hash stream S-1300.
- Shared randomness and timestamps. Shared pseudorandom values come from a commit-then-reveal coin flip between prover- and verifier-supplied generators, precomputed in bulk and consumed in FIFO order. Timestamps are taken by both parties on receipt of hashes, not by the tap S-1300 S-0018.
- Audit. The verifier selects stored hashes; the prover returns preimages (prompt, output, token start index, token count) to a verification facility that replays the computation and compares hashes. With k random challenges, a misreported fraction p is detected with probability 1 − (1 − p)^k; k = 3,200 detects 0.1% misreporting at 96% confidence S-1300.
- Storage. A pessimistic upper bound (100k Hopper GPUs at 2,000 tokens/s each, one token per streaming frame) is about 200 PB of SHA-256 hashes and 1,260 PB of prover-held plaintext per year, about €22.5 million in drives S-1300.
- Dictionary attacks. Against verifier dictionary attacks on hashes of short outputs, the paper recommends at least 5 tokens per hashed template, or at least 10 if the attacker filters for likely tokens S-1300.
- Residual covert channels. A 10 ms re-timing window at 100 Gbps holds up to about 625k packets, so packet-count modulation must be fixed per connection per window. Output nondeterminism leaves about 0.1 bit per token even with seed-synchronized replay, which gives about 40 Mbit/s for 200k GPUs at 2,000 tokens/GPU/s. Feigned hardware failures give about 1 kbit/day S-1300.
- Line-rate hashing (Amodo). On an AMD EPYC 9354P with DPDK, all tested algorithms except BLAKE3 reached the receive baseline at 1500-byte frames once enough threads were used; at 64-byte frames none reached line rate within the CPU's physical core count. Offloading to the tested DPU did not reach the target. SipHash-1-3-128 was the leading candidate, and FPGA or ASIC hashing is expected to be needed for some plans S-1311.
- Passive optics (Amodo). Amodo computes a 1.45 dB link margin, which it calls tight, for an example 53 GBaud link; a 95/5 split costs about 0.25 dB on the live leg and about 13 dB on the monitor leg S-1310.
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
This compute runs inference, not training
Supplies the committed record of cluster I/O that recomputation checks against declared inference (S-0067, S-1300).
Model weights have not left the facility
Aims to make covert exfiltration of results through tapped links infeasible (S-1300).
The declared model is the one being served
Replaying challenged records with the declared model checks which model produced outputs (S-1300, S-0067).
Readiness for a stated use
Assessed use: committing a complete record of cluster traffic, so declared inference can be checked
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
The Secure Gateway Device and related designs are public, but no tapped prototype has run at production link rates or with an active warden.
- R1 met: the Secure Gateway Device paper specifies the architecture, its goal (no covert exfiltration of results through tapped wires), its assumptions (physical monitoring, prover-held plaintext) and covert-channel estimates S-1300. Feasibility and cost analyses cover north-south, storage and compute-fabric taps S-0031. The MIRI overview places taps in a full reference architecture S-0018, and the AI 2040 plan relies on them S-0067.
- R2 not met: Amodo reports a passive fibre tap on a 1 Gbps lab link, with all 800 test inferences tapped and verified during a throughput stress test that flooded the link with non-whitelisted traffic S-1312. That result is provider-reported on a blog, at link rates far below production frontend links, with no hashing of traffic contents and no test against an adversary S-1312. Amodo says the passive tap must become active to close side channels S-1312. Amodo's code is public at tag v0.2.0 and includes the tap's frame processor S-1007 S-1312. The most mature Implementation, SASH's confidential network logger, has public code, but it runs a toy model through an inline software proxy that computes no hashes S-1319 S-1320. AI 2040 inference-only verification stack and Low-trust AI compute verification system overview are proposed architectures assessed R1. The Secure Gateway Device paper states that empirical validation and red-teaming are still required S-1300.
Confidence is medium: the Amodo test uses real passive tap hardware, but at 1 Gbps, as a stress test rather than against an adversary, and without the hashed record the designs rely on.
Evidence needed for the next level
Hashing and tapping demonstrated at production frontend link rates (400 Gbps class), including minimum-size frames.
A built active warden or Secure Gateway Device, with measured residual covert bandwidth.
Red-teaming of tap bypass, covert channels and physical security.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / theoretical argument
Output nondeterminism leaves covert capacity
Hashing cannot remove information hidden in the outputs themselves. The Secure Gateway Device paper estimates that about 0.1 bit per token remains even with seed-synchronized replay checks. For a 200k-GPU inference cluster at full load (2,000 tokens per GPU per second), that is about 40 Mbit/s of covert egress, enough to move a 1 TB model in under three days. The paper names this the core remaining challenge and points to deterministic replay or active scrubbing of hardware-induced entropy S-1300. An independent study found that an adversary who chooses the prompts roughly doubles the bits leaked per token under Gumbel-based inference verification S-1507; see Bounding unexplained information in outputs.
significant / open / open question
Some links cannot be passively tapped
Cankaya notes that copper-connected scale-up domains (for example NVL72 racks and TPU v7 cubes) are much harder to tap than fibre, and that optical budgets make passive taps impractical on 400GBASE-SR8 multimode links S-0031. Amodo found no taps advertised for 53 GBaud links as of May 2026 S-1310.
significant / open / open question
Encrypted fabrics hide plaintext from both parties
Cankaya notes that with TEE-protected sessions whose keys are ephemeral and managed inside the TEE, neither the operator nor the manufacturer can recover session keys after the session, so tapped traffic could not be opened for recomputation. For other encrypted fabrics, the operator can retain keys S-0031.
significant / open / theoretical argument
Residual side channels in simple passive setups
Amodo's analysis of its own tapped prototype lists unvalidated header fields, timing of permitted traffic and variation in response formatting as residual channels, and concludes that the passive tap must be replaced by an active one S-1312.
significant / open / open question
Completeness rests on physical monitoring left out of scope
The Secure Gateway Device paper assumes the facility is physically monitored, and states that the whole architecture depends on the device being the only communication channel. It names radio emanation, power-line signalling and thermal channels as covert channels beyond that scope S-1300.
minor / mitigated / theoretical argument
Verifier dictionary attacks on hashes
Hashes of very short outputs could be brute-forced by the verifier. The paper recommends hashing at least 5 tokens together, or at least 10 if the attacker filters for likely tokens S-1300.
What still blocks use or stronger assurance
- S-1311S-1310
No complete verification tap has been demonstrated at production frontend link rates, and on the tested CPU no hash algorithm reached line rate with minimum-size frames.
Nondeterministic inference leaves covert capacity in outputs that hashing cannot remove.
Dependency: Deterministic and bit-exact inference
S-1300Taps and gateway devices need tamper-evident housing and physical monitoring so that traffic cannot bypass them.
Dependency: Tamper evidence for verifier devices
S-1300S-0018Radio, power-line and thermal channels are not addressed by network-level designs.
Dependency: Side-channel suppression for isolated facilities
S-1300- S-1300
Red-teaming by specialists is called for but has not been reported.
Connections in the research map
Depends on
- Sampled inference recomputation
Challenged records are checked by recomputing them.
- Deterministic and bit-exact inference
Bit-exact replay is the main proposed way to remove covert capacity in model outputs.
- Tamper evidence for verifier devices
Taps and gateway devices must be physically protected and the facility monitored so all traffic passes through them.
- Side-channel suppression for isolated facilities
Radio, power-line and thermal channels bypass the tapped links.
Complementary techniques
Alternative approaches
Concepts used
Organizations and developers
Implementations
Sources and provenance
- S-1300 / Tier B
Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors ↗
N. Cankaya, J. Kryś, J. Ng, L. Marks, F. Krückel · 2026 · arXiv
Supports: Secure Gateway Device architecture, goal, assumptions, scope, covert-channel estimates, storage, dictionary attacks, need for validation
Locator: abstract; §1; §3; §4.1–4.2; §5.1–5.3; §6; appendices A–C
Version and catalogue details - S-0031 / Tier C
The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use ↗
N. Cankaya · 2026 · The Datacenter Lie Detector
Supports: tap definition; placement options and cost fractions; copper, multimode and encryption limits
Locator: sections on north-south, storage and compute-fabric taps; open problems
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: capture-everything principle; hashing over packet groups; failure conditions; perimeter size; commercial precedents; physical monitoring
Locator: §2b; §3.1–3.2; §5.1.1
Version and catalogue details - S-0067 / Tier C
Verification Plan ↗
R. Dean · 2026 · AI 2040
Supports: passive frontend taps feeding a recomputation server
Locator: inference-only retrofitting proposal
Version and catalogue details - S-1309 / Tier C
Network Taps — A First Test ↗
Amodo Design · 2026 · Amodo Design
Supports: first passive optical tap test at about 10 Gbps
Locator: whole note
Version and catalogue details - S-1310 / Tier C
Network Tapping for AI Verification: A Technical Assessment ↗
Amodo Design · 2026 · Amodo Design
Supports: COTS tap availability by baud rate; optical budget; possible need for a new ASIC
Locator: BLUF; passive and active tap sections
Version and catalogue details - S-1311 / Tier C
Network Traffic Hashing ↗
Amodo Design · 2026 · Amodo Design
Supports: line-rate hashing benchmarks on CPU and DPU
Locator: results and conclusions
Version and catalogue details - S-1312 / Tier C
Fitting a Network TAP to our Inference Verification Prototype ↗
Amodo Design · 2026 · Amodo Design
Supports: tapped 1 Gbps lab prototype, whitelist, flood stress-test result, no hashing of traffic contents, residual side channels, need for active tap
Locator: setup, results and side-channel sections
Version and catalogue details - S-1511 / Tier C
Get Involved in Verification ↗
AI Futures Project · 2026 · AI 2040
Supports: companion page's 400G component status and unresolved installation and monitoring
Locator: State of Play: Network taps on the frontend network; Physical security
Version and catalogue details - S-1007 / Tier B
Amodo-Design/Inference-Recomputation-Prototype (GitHub repository) ↗
Amodo Design · 2026 · GitHub
Supports: Amodo's public prototype code at tag v0.2.0: software-sidecar capture and the passive tap's frame processor
Locator: README at v0.2.0
Version and catalogue details - S-1319 / Tier B
inference-verification: Inference Verification Prototype ↗
Singapore AI Safety Hub (SASH) · 2026 · GitHub
Supports: public prototype code of a network-logger demo: inline proxy, no hashing, 270M model
Locator: README; components/
Version and catalogue details - S-1320 / Tier C
Internationalising AI Verification ↗
Singapore AI Safety Hub (SASH) · 2026 · SASH blog
Supports: confidential network logger prototype and planned FPGA certificates
Locator: whole post
Version and catalogue details - S-1507 / Tier B
Adversarial Entropy Inflation Against Gumbel-Based Inference Verification ↗
N. Kezins · 2026 · arXiv
Supports: prompt-controlled attack roughly doubling per-token leakage under Gumbel-based inference verification
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review