M-0022 / Off-chip devices & sensors

Side-channel suppression for isolated facilities

Shielding, filtering, jamming and inspecting an AI facility to limit hidden physical communication around monitored network links.

R1 ProposedSource reviewed 2026-09-25

01 / The mechanism and its boundary

What the technique establishes

Side-channel suppression would retrofit an AI facility with metal enclosures, filters, jamming, vibration isolation and inspections to limit communication outside monitored network links. Verification designs that watch every official link out of an AI cluster depend on it, because data could otherwise travel by radio emissions, sound, vibration or signals on power lines. One design aims to push hidden-channel capacity down to a few kilobits per second; whether that rate is tolerable depends on the prohibited workload and the other controls. The design estimates the cost at about 0.1–0.5% of hardware cost. Its author calls it a first-pass study. As of September 2026 no build has been prototyped, measured or red-teamed; that validation gap is the main obstacle. The biggest known weaknesses are hardware implanted in the supply chain, which inspection may miss, and the difficulty of keeping shielding intact around airflow, cabling and optical links.

Threat model
Adversarial prover
Adversarial evaluation
Published analysis
Hardware needed
Retrofit device
Prover cooperation
Partial
Confidentiality
Preserving
Category
Off chip devices & sensors
Technical detail and cited results
  • Capacity target. Cankaya frames suppression with the Shannon-Hartley limit C = B log2(1 + SNR). Defences either lower the signal power or raise the noise floor. Holding capacity to 1 kbit/s over 1 GHz of bandwidth needs an SNR of about −62 dB or less S-0038.
  • Shielding. Enclosures built to NSA specification 94-106 are cited at −100 dB of attenuation from 100 MHz to 10 GHz S-0038. Cable conduits should have at least two right-angle turns, and each turn gives an estimated 15–25 dB of diffraction loss at ultrasonic wavelengths. Air vents should not face each other S-0038.
  • Jamming and monitoring. Radio monitoring can run behind jamming using continuous or interrupted look-through, and a commodity-radio demonstration of continuous look-through is cited at 39 dB of suppression S-0038.
  • Cost. Each 8-rack scalable unit has 64 power cables ("whips") to filter. Cankaya's bill of materials for one scalable unit totals $35,000–$150,000, about 0.1–0.5% of the hardware cost at an assumed $4 million per rack S-0038.

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R1 Proposed

Assessed use: bounding physical covert channels out of a verified enclosure

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

One public design study gives costs and assumptions. Nothing has been built or measured.

  • R1 met: Cankaya publicly describes a design with its goal (bounding covert capacity around a verified enclosure to a tolerable rate), the channel classes it addresses, defences, cost estimates and assumptions S-0038.
  • R2 not met: Cankaya describes the work as a two-week research sprint that is far from conclusive, and calls for prototyping and red-teaming S-0038. Components such as shielded enclosures and commercial power-line filters exist as products S-0038, but as of September 2026 no integrated build for an AI facility, or measurement of one, has been published. The mechanism's implementations, RAND secure inference data center (SIDC) design, AI 2040 inference-only verification stack and Low-trust AI compute verification system overview, are proposed architectures at R1.

Confidence is medium: a single tier C source carries the design, but its author states plainly that nothing has been prototyped.

Evidence needed for the next level

  • A prototype enclosure for at least one AI rack or scalable unit, with measured attenuation for each channel class.

  • A red-team exercise against the prototype by a stated adversary.

  • Validated costs for filters, jamming and optical conversion at production scale.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / theoretical argument

Supply-chain implants may evade inspection

Cankaya identifies malicious hardware embedded deep in purchased components as a residual risk that visual inspection and disassembly may not catch. He notes that radiographic examination under high-security standards could mitigate it S-0038.

S-0038

significant / open / theoretical argument

Openings for airflow, power and optics weaken shielding

Cankaya notes that keeping attenuation high while passing high-power airflow, cabling and optical links adds complexity beyond existing shielded-enclosure specifications S-0038.

S-0038

significant / open / open question

Inspection assumptions may not hold

The design's statistical argument assumes that visual or disassembly inspection catches every flaw that is present in a sampled unit. Cankaya is unsure whether destructive teardowns are defence-dominant or offence-dominant S-0038.

S-0038

What still blocks use or stronger assurance

  1. No prototype or red-team exists; the design is a first-pass viability study.

    S-0038
  2. Volume costs of TEMPEST-grade power-line filters are uncertain, because existing products are mostly made to order.

    S-0038

Connections in the research map

Complementary techniques

Concepts used

Organizations and developers

Implementations

Sources and provenance

  1. S-0038 / Tier C

    Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses ↗

    N. Cankaya · 2026 · MIRI Technical Governance Team

    Supports: setting, threat framing, channel classes, Shannon-Hartley framing, defences, attenuation figures, costs, assumptions, residual risks

    Locator: whole post; bill-of-materials table; residual-risk discussion

    Version and catalogue details
  2. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: side-channel suppression as part of a low-trust inference verification design; covert side-channel bandwidth target

    Locator: §5.3.1

    Version and catalogue details
  3. S-0043 / Tier A

    BarraCUDA: Edge GPUs do Leak DNN Weights ↗

    P. Horvath, L. Chmielewski, L. Weissbart, L. Batina, Y. Yarom · 2025 · 34th USENIX Security Symposium

    Supports: EM side channel leaks DNN parameters on edge GPUs

    Locator: Abstract

    Version and catalogue details
  4. S-0044 / Tier A

    Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field ↗

    P. Horvath, I. Shumailov, L. Chmielewski, L. Batina, Y. Yarom · 2026 · IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026)

    Supports: EM leakage from GPU Tensor Cores, including at 100 cm through glass

    Locator: Abstract

    Version and catalogue details
  5. S-0046 / Tier A

    DeepTheft: Stealing DNN Model Architectures through Power Side Channel ↗

    Y. Gao, H. Qiu, Z. Zhang, B. Wang, H. Ma, A. Abuadbba, M. Xue, A. Fu, S. Nepal · 2024 · 2024 IEEE Symposium on Security and Privacy

    Supports: RAPL power side channel recovers DNN architectures; 99.75% Levenshtein-distance accuracy

    Locator: Abstract

    Version and catalogue details
  6. S-0007 / Tier B

    Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification ↗

    S. Ansari · 2026 · arXiv

    Supports: side-channel attacks on on-chip security implementations within reach of commercial tooling

    Locator: §4.3

    Version and catalogue details
  7. S-3566 / Tier C

    Can governments quickly and cheaply slow AI training? ↗

    joshc · 2026 · AI Alignment Forum

    Supports: independent public analysis of residual low-bandwidth paths and covert RL-training strategies

    Locator: §2.3; §3.4; §4

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review