01 / The mechanism and its boundary
What is being described
A side channel is an unintended path through which information leaks from a system via observable effects of its operation, such as timing, power consumption, and electromagnetic or acoustic emissions S-1600. NIST defines a side-channel attack as one enabled by such leakage from a physical cryptosystem S-1600.
A covert channel is related but deliberate. Two cooperating parties use an unintended or unauthorized channel to transfer information in a way that violates a system's security policy S-1600.
Side channels can leak secrets that verification designs aim to protect. BarraCUDA used electromagnetic analysis to recover the parameters of neural networks running on an edge GPU S-0043. A 2026 MIRI Technical Governance Team post describes microarchitectural side channels as a limitation of trusted execution environments S-0014.
Covert channels threaten the checks themselves. Another post from the same team describes electromagnetic, acoustic, power-line and fibre-optic channels that could carry data around a data centre's monitored network links. It proposes shielded enclosures, jamming combined with sensing, inspection and filtering, the approach of side-channel suppression S-0038. The same author's low-trust system design judges that keeping covert bandwidth below kilobits per second is much more achievable than eliminating it S-0018.
Physical signals can also serve the verifier. Training and inference often differ in accelerator utilization and power draw, which workload classification uses S-0005.
Connections in the research map
Related research
Sources and provenance
- S-1600 / Tier A
NIST Computer Security Resource Center (CSRC) Glossary ↗
National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center
Supports: NIST definitions of side-channel attack and covert channel
Locator: terms: side_channel_attack (NIST SP 1800-21B; SP 800-63-4); covert_channel (CNSSI 4009-2015; NIST SP 800-53 Rev. 5)
Version and catalogue details - S-0043 / Tier A
BarraCUDA: Edge GPUs do Leak DNN Weights ↗
P. Horvath, L. Chmielewski, L. Weissbart, L. Batina, Y. Yarom · 2025 · 34th USENIX Security Symposium
Supports: correlation electromagnetic analysis recovers neural-network parameters on an edge GPU device
Locator: abstract
Version and catalogue details - S-0014 / Tier C
On TEEs for Privacy-Preserving Monitoring in AI Governance ↗
Gloria Z · 2026 · MIRI Technical Governance Team
Supports: microarchitectural side channels as a TEE limitation
Locator: Limitations
Version and catalogue details - S-0038 / Tier C
Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses ↗
N. Cankaya · 2026 · MIRI Technical Governance Team
Supports: physical channels could bypass network monitoring; electromagnetic, acoustic, conducted power-line and fibre-optic channels in a data centre; shielded enclosures, jamming with sensing, inspection and filtering as defences
Locator: sections on channels and defences
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: suppressing covert bandwidth below kilobits per second judged much more achievable than zero
Locator: §5.3.1
Version and catalogue details - S-0005 / Tier B
Mechanisms to Verify International Agreements About AI Development ↗
A. Scher, L. Thiergart · 2025 · arXiv
Supports: utilization and power draw often differ between training and inference
Locator: Workload classification with high-level chip measures
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review