01 / The mechanism and its boundary
What the technique establishes
Side-channel suppression would retrofit an AI facility with metal enclosures, filters, jamming, vibration isolation and inspections to limit communication outside monitored network links. Verification designs that watch every official link out of an AI cluster depend on it, because data could otherwise travel by radio emissions, sound, vibration or signals on power lines. One design aims to push hidden-channel capacity down to a few kilobits per second; whether that rate is tolerable depends on the prohibited workload and the other controls. The design estimates the cost at about 0.1–0.5% of hardware cost. Its author calls it a first-pass study. As of September 2026 no build has been prototyped, measured or red-teamed; that validation gap is the main obstacle. The biggest known weaknesses are hardware implanted in the supply chain, which inspection may miss, and the difficulty of keeping shielding intact around airflow, cabling and optical links.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- Retrofit device
- Prover cooperation
- Partial
- Confidentiality
- Preserving
- Category
- Off chip devices & sensors
Technical detail and cited results
- Capacity target. Cankaya frames suppression with the Shannon-Hartley limit C = B log2(1 + SNR). Defences either lower the signal power or raise the noise floor. Holding capacity to 1 kbit/s over 1 GHz of bandwidth needs an SNR of about −62 dB or less S-0038.
- Shielding. Enclosures built to NSA specification 94-106 are cited at −100 dB of attenuation from 100 MHz to 10 GHz S-0038. Cable conduits should have at least two right-angle turns, and each turn gives an estimated 15–25 dB of diffraction loss at ultrasonic wavelengths. Air vents should not face each other S-0038.
- Jamming and monitoring. Radio monitoring can run behind jamming using continuous or interrupted look-through, and a commodity-radio demonstration of continuous look-through is cited at 39 dB of suppression S-0038.
- Cost. Each 8-rack scalable unit has 64 power cables ("whips") to filter. Cankaya's bill of materials for one scalable unit totals $35,000–$150,000, about 0.1–0.5% of the hardware cost at an assumed $4 million per rack S-0038.
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
Communication between compute groups is bounded
Bounds the capacity of physical covert channels out of an enclosure, so that monitored links carry all significant traffic.
Model weights have not left the facility
Supports arguments that weights cannot leave by unmonitored physical routes.
This compute runs inference, not training
Inference-only designs count on suppressing unmonitored physical channels so that all significant traffic passes the taps (S-0018).
Readiness for a stated use
Assessed use: bounding physical covert channels out of a verified enclosure
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
One public design study gives costs and assumptions. Nothing has been built or measured.
- R1 met: Cankaya publicly describes a design with its goal (bounding covert capacity around a verified enclosure to a tolerable rate), the channel classes it addresses, defences, cost estimates and assumptions S-0038.
- R2 not met: Cankaya describes the work as a two-week research sprint that is far from conclusive, and calls for prototyping and red-teaming S-0038. Components such as shielded enclosures and commercial power-line filters exist as products S-0038, but as of September 2026 no integrated build for an AI facility, or measurement of one, has been published. The mechanism's implementations, RAND secure inference data center (SIDC) design, AI 2040 inference-only verification stack and Low-trust AI compute verification system overview, are proposed architectures at R1.
Confidence is medium: a single tier C source carries the design, but its author states plainly that nothing has been prototyped.
Evidence needed for the next level
A prototype enclosure for at least one AI rack or scalable unit, with measured attenuation for each channel class.
A red-team exercise against the prototype by a stated adversary.
Validated costs for filters, jamming and optical conversion at production scale.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / theoretical argument
Supply-chain implants may evade inspection
Cankaya identifies malicious hardware embedded deep in purchased components as a residual risk that visual inspection and disassembly may not catch. He notes that radiographic examination under high-security standards could mitigate it S-0038.
significant / open / theoretical argument
Openings for airflow, power and optics weaken shielding
Cankaya notes that keeping attenuation high while passing high-power airflow, cabling and optical links adds complexity beyond existing shielded-enclosure specifications S-0038.
significant / open / open question
Inspection assumptions may not hold
The design's statistical argument assumes that visual or disassembly inspection catches every flaw that is present in a sampled unit. Cankaya is unsure whether destructive teardowns are defence-dominant or offence-dominant S-0038.
What still blocks use or stronger assurance
Connections in the research map
Complementary techniques
Organizations and developers
Implementations
Sources and provenance
- S-0038 / Tier C
Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses ↗
N. Cankaya · 2026 · MIRI Technical Governance Team
Supports: setting, threat framing, channel classes, Shannon-Hartley framing, defences, attenuation figures, costs, assumptions, residual risks
Locator: whole post; bill-of-materials table; residual-risk discussion
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: side-channel suppression as part of a low-trust inference verification design; covert side-channel bandwidth target
Locator: §5.3.1
Version and catalogue details - S-0043 / Tier A
BarraCUDA: Edge GPUs do Leak DNN Weights ↗
P. Horvath, L. Chmielewski, L. Weissbart, L. Batina, Y. Yarom · 2025 · 34th USENIX Security Symposium
Supports: EM side channel leaks DNN parameters on edge GPUs
Locator: Abstract
Version and catalogue details - S-0044 / Tier A
Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field ↗
P. Horvath, I. Shumailov, L. Chmielewski, L. Batina, Y. Yarom · 2026 · IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026)
Supports: EM leakage from GPU Tensor Cores, including at 100 cm through glass
Locator: Abstract
Version and catalogue details - S-0046 / Tier A
DeepTheft: Stealing DNN Model Architectures through Power Side Channel ↗
Y. Gao, H. Qiu, Z. Zhang, B. Wang, H. Ma, A. Abuadbba, M. Xue, A. Fu, S. Nepal · 2024 · 2024 IEEE Symposium on Security and Privacy
Supports: RAPL power side channel recovers DNN architectures; 99.75% Levenshtein-distance accuracy
Locator: Abstract
Version and catalogue details - S-0007 / Tier B
Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification ↗
S. Ansari · 2026 · arXiv
Supports: side-channel attacks on on-chip security implementations within reach of commercial tooling
Locator: §4.3
Version and catalogue details - S-3566 / Tier C
Can governments quickly and cheaply slow AI training? ↗
joshc · 2026 · AI Alignment Forum
Supports: independent public analysis of residual low-bandwidth paths and covert RL-training strategies
Locator: §2.3; §3.4; §4
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review