M-0017 / Off-chip devices & sensors

Tamper evidence for verifier devices

Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating.

R2 DemonstratedSource reviewed 2026-09-25

01 / The mechanism and its boundary

What the technique establishes

Tamper evidence for verification hardware uses enclosures, seals and sensors to make physical interference visible, or to destroy the hardware's secrets when it happens. The devices, such as network taps, gateways and recomputation servers, would sit in facilities the checked party controls. The tamper-respondent IBM 4765 module was validated at FIPS 140-2 Level 4. Nuclear safeguards and arms control use tamper-indicating enclosures. Peer-reviewed prototypes detect probing through capacitive covers, radio waves inside server cases, or on-chip impedance sensing. As of September 2026 none has been built or evaluated for AI verifier hardware, and the MIRI overview lists retrofittable, mass-manufacturable enclosures for side-channel defence as an open problem. The main obstacles are scale, batteries and inspection burden. The largest known weakness is that seals are often defeated with simple methods: a 1996 Los Alamos study defeated all 94 seals it examined. Any enclosure is only as good as its inspection protocol.

Threat model
Adversarial prover
Adversarial evaluation
Published analysis
Hardware needed
Retrofit device
Prover cooperation
Partial
Confidentiality
Preserving
Category
Off chip devices & sensors
Technical detail and cited results
  • IBM 4765. FIPS 140-2 Level 4 overall and for physical security, validated in 2011. NIST later moved the certificate to its historical list after a random-number-generator transition S-3260. A tamper-respondent matrix monitors for intrusion and adverse conditions, with moderate and severe out-of-range temperature and voltage sensing. A hard tamper triggers active wiping of secrets: the high-speed-erase battery-backed RAM holding core secrets is erased within microseconds, and the module is zeroized and left inoperable S-0050.
  • Batteryless PUF cover. A 140 mm × 140 mm flexPCB cover with 16 × 16 electrodes (256 sensor nodes, 128 used differentially) and 100 µm line and space, checked by an STM32F303 microcontroller. After open- and short-circuit checks pass, a key is derived from the differential capacitances, about 5.2 bits of entropy per node with 10x oversampling (about 665 bits in theory). The attacker model assumes penetrations of at least 300 µm; single 0.3 mm holes made key reconstruction infeasible; a full-cover measurement with 10x oversampling takes 384 ms; power is about 0.6 W; testing spanned −20 °C to +60 °C S-1315.
  • Anti-Tamper Radio. Two wideband antennas inside a metal case, measured with a vector network analyzer (2–9 GHz) or ultra-wideband transceivers (2.496–7.488 GHz). In a Dell PowerEdge 2850 over 10 days, 40 mm insertions of 1 mm needles were reliably detected; in an empty aluminium box, 16 mm insertions of needles as thin as 0.1 mm were detected. UWB transceivers cost less than US$5 S-0052.
  • ImpedanceVerif. An embedded network analyzer on an FPGA measures the frequency response of the power distribution network, and Wasserstein distance is used as the detection statistic S-0051.

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R2 Demonstrated

Assessed use: detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence

medium confidence · current · assessed 2026-10-08 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Peer-reviewed tamper-detection results exist under stated adversaries, one in a running server, but no enclosure has been built or evaluated for AI verifier devices. The running-server tests are representative in hardware, satisfying R2, while an integrated AI verifier enclosure remains unbuilt S-0052 S-0018.

  • R1 met: enclosure designs with stated attacker models are published S-1315 S-0052, and the MIRI overview describes their role in protecting verification hardware in a host-controlled facility S-0018.
  • R2 met: published end-to-end results exist under a stated adversary. Anti-Tamper Radio reliably detected needle insertions in a running 19-inch server over a 10-day experiment S-0052. Immler et al. report statistics over 115 batteryless covers, plus physical attacks against a stated 300 µm penetration model and environmental tests S-1315. On-chip impedance sensing detected board- and package-level tampering on commercial FPGA kits S-0051. All three are peer-reviewed; no public code or design files are cited for them.
  • R3 not met for this use: production-grade tamper-respondent modules exist S-0050, PHYSEC markets a radio-based tamper sensor for infrastructure enclosures S-3262, and tamper-indicating enclosures are used in safeguards and arms control S-1316, but none has been built for AI verifier devices such as optical taps, FPGA gateways or recomputation servers. The MIRI overview says it is less established what defences "can be retrofitted at a massive scale to prevent bypassing of network taps" S-0018. The mechanism's only implementation, AI 2040 inference-only verification stack, is a proposed architecture at R1.
  • R4 not met: the IBM 4765 was validated at FIPS 140-2 Level 4 S-0050, but no enclosure has been independently evaluated on AI verifier devices.

Confidence is medium, because how far the server-scale and HSM results transfer to AI verifier hardware is a judgment call.

Evidence needed for the next level

  • An enclosure or sensing design built for AI verifier devices (taps, gateways, recomputation servers) and deployable at data-centre scale.

  • An independent public evaluation (red team or certification) of such an enclosure in the AI verification setting.

  • Inspection protocols suited to host-controlled AI facilities.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / demonstrated attack

Seals are often defeated with simple methods

In 1996 a Los Alamos vulnerability assessment defeated all 94 security seals it examined, with 132 defeats in total, using rapid, inexpensive, low-tech methods. It found that seal cost did not predict security. In 2001 Johnston reported that high-tech seals are often easier to defeat than low-tech ones.

S-1317S-1318

significant / open / theoretical argument

Security depends on inspection protocols

Johnston argues that a seal is no better than the protocols for using it, and that inspectors are usually given little useful information on how to detect tampering. The Sandia survey notes that larger enclosures are hard to inspect fully and that sensor data must be authenticated.

S-1318S-1316

significant / open / open question

Attack classes outside published models

The authors of the batteryless cover say they cannot assess chemical-solvent attacks, which exceed their expertise, and deem cover removal impractical. Anti-Tamper Radio's reference can drift as the environment or measurement system ages; the authors suggest gradually renewing the reference. A 2025 follow-up by some of the same authors shows, by emulation on measured channel data, that an attacker who knows the reference channel and the needle's effect on it could inject a signal that cancels the change caused by a needle insertion. It proposes a reconfigurable intelligent surface that randomizes the channel as a countermeasure.

S-1315S-0052S-3261

What still blocks use or stronger assurance

  1. No tamper-evident enclosure has been designed for AI verifier hardware at retrofit scale.

    S-0018
  2. Battery-backed designs add bulk, limit operating temperature (+10 °C to +35 °C for the IBM 4765) and complicate transport.

    S-1315
  3. Active monitoring needs power, and visual inspection of large enclosures faces access limits.

    S-1316
  4. No evaluation has been published in the AI verification setting.

    S-0018

Connections in the research map

Complementary techniques

Concepts used

Implementations

Sources and provenance

  1. S-0050 / Tier B

    IBM 4765 Cryptographic Coprocessor Security Module: Security Policy ↗

    IBM Corporation · 2012 · NIST Cryptographic Module Validation Program

    Supports: FIPS 140-2 Level 4; tamper-respondent matrix; sensed conditions; zeroization

    Locator: Table 1; §2 physical security; §8.1 Table 9

    Version and catalogue details
  2. S-3260 / Tier A

    Cryptographic Module Validation Program Certificate #1505: IBM 4765 Cryptographic Coprocessor Security Module ↗

    National Institute of Standards and Technology · 2011 · NIST Cryptographic Module Validation Program

    Supports: IBM 4765 validation date and historical certificate status

    Locator: certificate page

    Version and catalogue details
  3. S-0049 / Tier A

    The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond ↗

    J. Obermaier, V. Immler · 2018 · Journal of Hardware and Systems Security

    Supports: existence of a review spanning battery-backed to PUF-based enclosures

    Locator: title and abstract (full text not read)

    Version and catalogue details
  4. S-1315 / Tier A

    Secure Physical Enclosures from Covers with Tamper-Resistance ↗

    V. Immler, J. Obermaier, K. K. Ng, F. X. Ke, J. Lee, Y. P. Lim, W. K. Oh, K. H. Wee, G. Sigl · 2019 · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96

    Supports: batteryless PUF cover design, attacker model, results, stated limitations, drawbacks of battery-backed enclosures

    Locator: abstract; §2.1; §3.1; §8

    Version and catalogue details
  5. S-0052 / Tier A

    Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems ↗

    P. Staat, J. Tobisch, C. Zenger, C. Paar · 2022 · 2022 IEEE Symposium on Security and Privacy

    Supports: Anti-Tamper Radio concept, threat model, server experiment, costs, limitations

    Locator: abstract; §III–§VI

    Version and catalogue details
  6. S-3261 / Tier A

    Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection ↗

    M. S. Tabar, J. Kortz, P. Staat, H. Elders-Boll, C. Paar, C. Zenger · 2025 · 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025)

    Supports: signal-injection (compensation) attack on Anti-Tamper Radio under a known-reference model; RIS countermeasure

    Locator: abstract; §3.1; §4.2.1

    Version and catalogue details
  7. S-3262 / Tier B

    PHYSEC SEAL: Change detection for maximum safety ↗

    PHYSEC GmbH · 2026 · PHYSEC website

    Supports: PHYSEC reports a commercial anti-tamper radio sensor for infrastructure enclosures

    Locator: product page

    Version and catalogue details
  8. S-0051 / Tier A

    ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection ↗

    T. Mosavirik, P. Schaumont, S. Tajik · 2023 · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325

    Supports: on-chip impedance sensing for tamper detection

    Locator: abstract

    Version and catalogue details
  9. S-1316 / Tier B

    Tamper-Indicating Enclosures, A Current Survey ↗

    H. A. Smartt, Z. N. Gastelum · 2015 · Sandia National Laboratories, SAND2015-4251C

    Supports: tamper-indicating enclosures in verification regimes; approaches; limitations

    Locator: abstract; survey sections

    Version and catalogue details
  10. S-1317 / Tier B

    Physical Security and Tamper-Indicating Devices ↗

    R. G. Johnston, A. R. E. Garcia · 1996 · Los Alamos National Laboratory, LA-UR-96-3827

    Supports: seal vulnerability assessment results; mean defeat time for one practised person

    Locator: abstract; results; Table 2

    Version and catalogue details
  11. S-1318 / Tier A

    Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials ↗

    R. G. Johnston · 2001 · The Nonproliferation Review, Spring 2001, pp. 102–114

    Supports: high-tech vs low-tech seals; role of protocols and inspector training

    Locator: main text

    Version and catalogue details
  12. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: enclosure needs in low-trust AI verification; open question on retrofittable enclosures for side-channel defence; inspections

    Locator: §2b; §4.2; §5.3.1

    Version and catalogue details
  13. S-0067 / Tier C

    Verification Plan ↗

    R. Dean · 2026 · AI 2040

    Supports: tamper-evident enclosures among physical security measures

    Locator: physical security discussion

    Version and catalogue details
  14. S-0035 / Tier B

    Flexible Hardware-Enabled Guarantees for AI Compute ↗

    J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv

    Supports: flexHEG secure enclosure for physical tamper protection

    Locator: abstract

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review