01 / The mechanism and its boundary
What the technique establishes
The Singapore AI Safety Hub (SASH) describes confidential network loggers (CNLs) as systems that split and copy traffic leaving a data centre's cable. In SASH's planned next prototype, an FPGA certifies the traffic it sees, and a random sample of inputs and outputs goes to a separate recomputation cluster, which re-runs them on its own model copy and flags mismatches; the verifier would see only encrypted hashes. The aim is to show a facility serves inference, not training. The first prototype's code is public; it re-runs every request rather than a sample and computes no hashes. A hardware demonstration used DGX Spark GPUs and Raspberry Pis. As of September 2026 it has not been tested at realistic scale or against a stated adversary. SASH says the recomputation cluster's security cannot yet be monitored, that a Raspberry Pi logger ties the design to particular supply chains, and that side channels remain.
- Threat model
- Semi-trusted prover
- Adversarial evaluation
- None
- Hardware needed
- Retrofit device
- Prover cooperation
- Required
- Confidentiality
- Partial
- Category
- Off chip devices & sensors
Technical detail and cited results
- Services. The repository starts five services together: a Svelte dashboard (port 5173) and FastAPI services for the gateway (8010), network logger (8020), main cluster (8030) and recomputation cluster (8040) S-1319.
- Gateway. It wraps each inference request in an envelope encrypted with AES-GCM-SIV, using a 256-bit key derived by SHA-256 from a configured host key and a nonce derived from the request ID and direction, and posts it to the network logger S-1319.
- Network logger. It forwards the encrypted request to the main cluster, then posts the encrypted request and response to the recomputation cluster's /verify endpoint. It returns the response only if the result is "verified"; otherwise it returns an HTTP 400 "Recomputation failed" S-1319.
- Recomputation cluster. It decrypts both, re-runs inference and compares response text for exact equality. Inference calls an OpenAI-compatible endpoint with seed 0 S-1319.
- Model and demo modes. The Docker configuration serves google/gemma-3-270m-it on a CPU vLLM image, and a mock mode returns placeholder text. A demo switch replaces output characters with random hex characters to "simulate covert training" S-1319.
- Difference from the blog post. In this version the logger is an inline software proxy that forwards every request for verification and computes no hashes of the traffic, whereas the blog post describes random sampling and hashes for the next, FPGA-based prototype S-1319 S-1320.
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
This compute runs inference, not training
SASH describes the aim as distinguishing inference from training in data centres (S-1320).
The declared model is the one being served
Recomputation uses another copy of the declared model (S-1320, S-1319).
Readiness for a stated use
Assessed use: telling inference from training on a mutually inspected cluster
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
Public code exists, but it runs a toy model through a software proxy with no stated adversary.
- R1 met: SASH publicly describes the design (a traffic-splitting logger plus sampled recomputation on a mutually inspected cluster), the claim (inference rather than training) and its stated limitations S-1320. Public code exists S-1319.
- R2 not met: the implementation does not run under conditions representative of the verification use in any key respect. The model is Gemma 3 270M on a CPU inference image, and the logger is a software proxy S-1319. The hardware demonstration used DGX Spark GPUs and Raspberry Pis S-1320. The only adversary is a demo switch that replaces outputs with random characters S-1319. As of September 2026 no evaluation by others has been published.
Confidence is medium: the code can be read directly, but the hardware demonstration is known only from SASH's blog post.
Evidence needed for the next level
A hardware logger (the planned FPGA version) on a real data-centre link, with realistic model size or traffic volume.
A stated adversary and threat model, with testing against it.
Random sampling and hashed or certified traffic records, as described in the blog post, implemented in the public code.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / open question
Recomputation cluster security is not monitored
SASH states that the current prototype has no means to monitor the security of the recomputation cluster, which holds a copy of the model and decides whether an alarm is raised.
significant / open / open question
Side channels not yet addressed
SASH lists eliminating a wider range of side-channel vulnerabilities as future work.
minor / open / open question
Logger hardware supply chain
The prototype uses a Raspberry Pi 5 as the logger, which SASH says locks the design into Broadcom and Arm supply chains.
What still blocks use or stronger assurance
- S-1320
The planned FPGA logger has not yet been built.
- S-1320
The design has not been scaled to production traffic volumes.
Exact-match recomputation requires reproducible inference.
Dependency: Deterministic and bit-exact inference
S-1319
Connections in the research map
Depends on
- Deterministic and bit-exact inference
The recomputation check compares output text exactly.
- Tamper evidence for verifier devices
The logger and recomputation cluster must be protected against tampering.
Mechanisms implemented
Organizations and developers
Sources and provenance
- S-1320 / Tier C
Internationalising AI Verification ↗
Singapore AI Safety Hub (SASH) · 2026 · SASH blog
Supports: project aims, CNL description, workflow, hardware demo, partners, limitations and future work
Locator: whole post
Version and catalogue details - S-1319 / Tier B
inference-verification: Inference Verification Prototype ↗
Singapore AI Safety Hub (SASH) · 2026 · GitHub
Supports: components, data flow, encryption, recomputation comparison, model, demo switch, licence
Locator: README.md; run-dev.sh; components/gateway, network_logger, recomputation_cluster, lib/
Version and catalogue details - S-3200 / Tier C
Field Notes on International AI Verification from Shanghai, Seoul, and Sydney ↗
Singapore AI Safety Hub (SASH) · 2026 · SASH blog
Supports: planned v2 of the logger based on a zero-knowledge proof system
Locator: paragraph beginning 'SASH is contributing to this effort'
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review