I-0008 / Off-chip devices & sensors

SASH confidential network logger

An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference.

R1 ProposedSource reviewed 2026-09-25Provider-reported evidence

01 / The mechanism and its boundary

What the technique establishes

The Singapore AI Safety Hub (SASH) describes confidential network loggers (CNLs) as systems that split and copy traffic leaving a data centre's cable. In SASH's planned next prototype, an FPGA certifies the traffic it sees, and a random sample of inputs and outputs goes to a separate recomputation cluster, which re-runs them on its own model copy and flags mismatches; the verifier would see only encrypted hashes. The aim is to show a facility serves inference, not training. The first prototype's code is public; it re-runs every request rather than a sample and computes no hashes. A hardware demonstration used DGX Spark GPUs and Raspberry Pis. As of September 2026 it has not been tested at realistic scale or against a stated adversary. SASH says the recomputation cluster's security cannot yet be monitored, that a Raspberry Pi logger ties the design to particular supply chains, and that side channels remain.

Threat model
Semi-trusted prover
Adversarial evaluation
None
Hardware needed
Retrofit device
Prover cooperation
Required
Confidentiality
Partial
Category
Off chip devices & sensors
Technical detail and cited results
  • Services. The repository starts five services together: a Svelte dashboard (port 5173) and FastAPI services for the gateway (8010), network logger (8020), main cluster (8030) and recomputation cluster (8040) S-1319.
  • Gateway. It wraps each inference request in an envelope encrypted with AES-GCM-SIV, using a 256-bit key derived by SHA-256 from a configured host key and a nonce derived from the request ID and direction, and posts it to the network logger S-1319.
  • Network logger. It forwards the encrypted request to the main cluster, then posts the encrypted request and response to the recomputation cluster's /verify endpoint. It returns the response only if the result is "verified"; otherwise it returns an HTTP 400 "Recomputation failed" S-1319.
  • Recomputation cluster. It decrypts both, re-runs inference and compares response text for exact equality. Inference calls an OpenAI-compatible endpoint with seed 0 S-1319.
  • Model and demo modes. The Docker configuration serves google/gemma-3-270m-it on a CPU vLLM image, and a mock mode returns placeholder text. A demo switch replaces output characters with random hex characters to "simulate covert training" S-1319.
  • Difference from the blog post. In this version the logger is an inline software proxy that forwards every request for verification and computes no hashes of the traffic, whereas the blog post describes random sampling and hashes for the next, FPGA-based prototype S-1319 S-1320.

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R1 Proposed

Assessed use: telling inference from training on a mutually inspected cluster

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Public code exists, but it runs a toy model through a software proxy with no stated adversary.

  • R1 met: SASH publicly describes the design (a traffic-splitting logger plus sampled recomputation on a mutually inspected cluster), the claim (inference rather than training) and its stated limitations S-1320. Public code exists S-1319.
  • R2 not met: the implementation does not run under conditions representative of the verification use in any key respect. The model is Gemma 3 270M on a CPU inference image, and the logger is a software proxy S-1319. The hardware demonstration used DGX Spark GPUs and Raspberry Pis S-1320. The only adversary is a demo switch that replaces outputs with random characters S-1319. As of September 2026 no evaluation by others has been published.

Confidence is medium: the code can be read directly, but the hardware demonstration is known only from SASH's blog post.

Evidence needed for the next level

  • A hardware logger (the planned FPGA version) on a real data-centre link, with realistic model size or traffic volume.

  • A stated adversary and threat model, with testing against it.

  • Random sampling and hashed or certified traffic records, as described in the blog post, implemented in the public code.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / open question

Recomputation cluster security is not monitored

SASH states that the current prototype has no means to monitor the security of the recomputation cluster, which holds a copy of the model and decides whether an alarm is raised.

S-1320

significant / open / open question

Side channels not yet addressed

SASH lists eliminating a wider range of side-channel vulnerabilities as future work.

S-1320

minor / open / open question

Logger hardware supply chain

The prototype uses a Raspberry Pi 5 as the logger, which SASH says locks the design into Broadcom and Arm supply chains.

S-1320

What still blocks use or stronger assurance

  1. The planned FPGA logger has not yet been built.

    S-1320
  2. The design has not been scaled to production traffic volumes.

    S-1320
  3. Exact-match recomputation requires reproducible inference.

    Dependency: Deterministic and bit-exact inference

    S-1319

Connections in the research map

Depends on

Mechanisms implemented

Concepts used

Organizations and developers

Sources and provenance

  1. S-1320 / Tier C

    Internationalising AI Verification ↗

    Singapore AI Safety Hub (SASH) · 2026 · SASH blog

    Supports: project aims, CNL description, workflow, hardware demo, partners, limitations and future work

    Locator: whole post

    Version and catalogue details
  2. S-1319 / Tier B

    inference-verification: Inference Verification Prototype ↗

    Singapore AI Safety Hub (SASH) · 2026 · GitHub

    Supports: components, data flow, encryption, recomputation comparison, model, demo switch, licence

    Locator: README.md; run-dev.sh; components/gateway, network_logger, recomputation_cluster, lib/

    Version and catalogue details
  3. S-3200 / Tier C

    Field Notes on International AI Verification from Shanghai, Seoul, and Sydney ↗

    Singapore AI Safety Hub (SASH) · 2026 · SASH blog

    Supports: planned v2 of the logger based on a zero-knowledge proof system

    Locator: paragraph beginning 'SASH is contributing to this effort'

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review