01 / The mechanism and its boundary
What the technique establishes
Tamper evidence for verification hardware uses enclosures, seals and sensors to make physical interference visible, or to destroy the hardware's secrets when it happens. The devices, such as network taps, gateways and recomputation servers, would sit in facilities the checked party controls. The tamper-respondent IBM 4765 module was validated at FIPS 140-2 Level 4. Nuclear safeguards and arms control use tamper-indicating enclosures. Peer-reviewed prototypes detect probing through capacitive covers, radio waves inside server cases, or on-chip impedance sensing. As of September 2026 none has been built or evaluated for AI verifier hardware, and the MIRI overview lists retrofittable, mass-manufacturable enclosures for side-channel defence as an open problem. The main obstacles are scale, batteries and inspection burden. The largest known weakness is that seals are often defeated with simple methods: a 1996 Los Alamos study defeated all 94 seals it examined. Any enclosure is only as good as its inspection protocol.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- Retrofit device
- Prover cooperation
- Partial
- Confidentiality
- Preserving
- Category
- Off chip devices & sensors
Technical detail and cited results
- IBM 4765. FIPS 140-2 Level 4 overall and for physical security, validated in 2011. NIST later moved the certificate to its historical list after a random-number-generator transition S-3260. A tamper-respondent matrix monitors for intrusion and adverse conditions, with moderate and severe out-of-range temperature and voltage sensing. A hard tamper triggers active wiping of secrets: the high-speed-erase battery-backed RAM holding core secrets is erased within microseconds, and the module is zeroized and left inoperable S-0050.
- Batteryless PUF cover. A 140 mm × 140 mm flexPCB cover with 16 × 16 electrodes (256 sensor nodes, 128 used differentially) and 100 µm line and space, checked by an STM32F303 microcontroller. After open- and short-circuit checks pass, a key is derived from the differential capacitances, about 5.2 bits of entropy per node with 10x oversampling (about 665 bits in theory). The attacker model assumes penetrations of at least 300 µm; single 0.3 mm holes made key reconstruction infeasible; a full-cover measurement with 10x oversampling takes 384 ms; power is about 0.6 W; testing spanned −20 °C to +60 °C S-1315.
- Anti-Tamper Radio. Two wideband antennas inside a metal case, measured with a vector network analyzer (2–9 GHz) or ultra-wideband transceivers (2.496–7.488 GHz). In a Dell PowerEdge 2850 over 10 days, 40 mm insertions of 1 mm needles were reliably detected; in an empty aluminium box, 16 mm insertions of needles as thin as 0.1 mm were detected. UWB transceivers cost less than US$5 S-0052.
- ImpedanceVerif. An embedded network analyzer on an FPGA measures the frequency response of the power distribution network, and Wasserstein distance is used as the detection statistic S-0051.
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
This compute runs inference, not training
Protects the integrity of taps, gateways and recomputation hardware used for inference-only verification (S-0018, S-0067).
Communication between compute groups is bounded
Protects network devices that enforce or monitor bandwidth boundaries (S-0018).
Readiness for a stated use
Assessed use: detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence
medium confidence · current · assessed 2026-10-08 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
Peer-reviewed tamper-detection results exist under stated adversaries, one in a running server, but no enclosure has been built or evaluated for AI verifier devices. The running-server tests are representative in hardware, satisfying R2, while an integrated AI verifier enclosure remains unbuilt S-0052 S-0018.
- R1 met: enclosure designs with stated attacker models are published S-1315 S-0052, and the MIRI overview describes their role in protecting verification hardware in a host-controlled facility S-0018.
- R2 met: published end-to-end results exist under a stated adversary. Anti-Tamper Radio reliably detected needle insertions in a running 19-inch server over a 10-day experiment S-0052. Immler et al. report statistics over 115 batteryless covers, plus physical attacks against a stated 300 µm penetration model and environmental tests S-1315. On-chip impedance sensing detected board- and package-level tampering on commercial FPGA kits S-0051. All three are peer-reviewed; no public code or design files are cited for them.
- R3 not met for this use: production-grade tamper-respondent modules exist S-0050, PHYSEC markets a radio-based tamper sensor for infrastructure enclosures S-3262, and tamper-indicating enclosures are used in safeguards and arms control S-1316, but none has been built for AI verifier devices such as optical taps, FPGA gateways or recomputation servers. The MIRI overview says it is less established what defences "can be retrofitted at a massive scale to prevent bypassing of network taps" S-0018. The mechanism's only implementation, AI 2040 inference-only verification stack, is a proposed architecture at R1.
- R4 not met: the IBM 4765 was validated at FIPS 140-2 Level 4 S-0050, but no enclosure has been independently evaluated on AI verifier devices.
Confidence is medium, because how far the server-scale and HSM results transfer to AI verifier hardware is a judgment call.
Evidence needed for the next level
An enclosure or sensing design built for AI verifier devices (taps, gateways, recomputation servers) and deployable at data-centre scale.
An independent public evaluation (red team or certification) of such an enclosure in the AI verification setting.
Inspection protocols suited to host-controlled AI facilities.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / demonstrated attack
Seals are often defeated with simple methods
In 1996 a Los Alamos vulnerability assessment defeated all 94 security seals it examined, with 132 defeats in total, using rapid, inexpensive, low-tech methods. It found that seal cost did not predict security. In 2001 Johnston reported that high-tech seals are often easier to defeat than low-tech ones.
significant / open / theoretical argument
Security depends on inspection protocols
Johnston argues that a seal is no better than the protocols for using it, and that inspectors are usually given little useful information on how to detect tampering. The Sandia survey notes that larger enclosures are hard to inspect fully and that sensor data must be authenticated.
significant / open / open question
Attack classes outside published models
The authors of the batteryless cover say they cannot assess chemical-solvent attacks, which exceed their expertise, and deem cover removal impractical. Anti-Tamper Radio's reference can drift as the environment or measurement system ages; the authors suggest gradually renewing the reference. A 2025 follow-up by some of the same authors shows, by emulation on measured channel data, that an attacker who knows the reference channel and the needle's effect on it could inject a signal that cancels the change caused by a needle insertion. It proposes a reconfigurable intelligent surface that randomizes the channel as a countermeasure.
What still blocks use or stronger assurance
- S-0018
No tamper-evident enclosure has been designed for AI verifier hardware at retrofit scale.
- S-1315
Battery-backed designs add bulk, limit operating temperature (+10 °C to +35 °C for the IBM 4765) and complicate transport.
- S-1316
Active monitoring needs power, and visual inspection of large enclosures faces access limits.
- S-0018
No evaluation has been published in the AI verification setting.
Connections in the research map
Complementary techniques
Implementations
Sources and provenance
- S-0050 / Tier B
IBM 4765 Cryptographic Coprocessor Security Module: Security Policy ↗
IBM Corporation · 2012 · NIST Cryptographic Module Validation Program
Supports: FIPS 140-2 Level 4; tamper-respondent matrix; sensed conditions; zeroization
Locator: Table 1; §2 physical security; §8.1 Table 9
Version and catalogue details - S-3260 / Tier A
Cryptographic Module Validation Program Certificate #1505: IBM 4765 Cryptographic Coprocessor Security Module ↗
National Institute of Standards and Technology · 2011 · NIST Cryptographic Module Validation Program
Supports: IBM 4765 validation date and historical certificate status
Locator: certificate page
Version and catalogue details - S-0049 / Tier A
The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond ↗
J. Obermaier, V. Immler · 2018 · Journal of Hardware and Systems Security
Supports: existence of a review spanning battery-backed to PUF-based enclosures
Locator: title and abstract (full text not read)
Version and catalogue details - S-1315 / Tier A
Secure Physical Enclosures from Covers with Tamper-Resistance ↗
V. Immler, J. Obermaier, K. K. Ng, F. X. Ke, J. Lee, Y. P. Lim, W. K. Oh, K. H. Wee, G. Sigl · 2019 · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96
Supports: batteryless PUF cover design, attacker model, results, stated limitations, drawbacks of battery-backed enclosures
Locator: abstract; §2.1; §3.1; §8
Version and catalogue details - S-0052 / Tier A
Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems ↗
P. Staat, J. Tobisch, C. Zenger, C. Paar · 2022 · 2022 IEEE Symposium on Security and Privacy
Supports: Anti-Tamper Radio concept, threat model, server experiment, costs, limitations
Locator: abstract; §III–§VI
Version and catalogue details - S-3261 / Tier A
Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection ↗
M. S. Tabar, J. Kortz, P. Staat, H. Elders-Boll, C. Paar, C. Zenger · 2025 · 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025)
Supports: signal-injection (compensation) attack on Anti-Tamper Radio under a known-reference model; RIS countermeasure
Locator: abstract; §3.1; §4.2.1
Version and catalogue details - S-3262 / Tier B
PHYSEC SEAL: Change detection for maximum safety ↗
PHYSEC GmbH · 2026 · PHYSEC website
Supports: PHYSEC reports a commercial anti-tamper radio sensor for infrastructure enclosures
Locator: product page
Version and catalogue details - S-0051 / Tier A
ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection ↗
T. Mosavirik, P. Schaumont, S. Tajik · 2023 · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325
Supports: on-chip impedance sensing for tamper detection
Locator: abstract
Version and catalogue details - S-1316 / Tier B
Tamper-Indicating Enclosures, A Current Survey ↗
H. A. Smartt, Z. N. Gastelum · 2015 · Sandia National Laboratories, SAND2015-4251C
Supports: tamper-indicating enclosures in verification regimes; approaches; limitations
Locator: abstract; survey sections
Version and catalogue details - S-1317 / Tier B
Physical Security and Tamper-Indicating Devices ↗
R. G. Johnston, A. R. E. Garcia · 1996 · Los Alamos National Laboratory, LA-UR-96-3827
Supports: seal vulnerability assessment results; mean defeat time for one practised person
Locator: abstract; results; Table 2
Version and catalogue details - S-1318 / Tier A
Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials ↗
R. G. Johnston · 2001 · The Nonproliferation Review, Spring 2001, pp. 102–114
Supports: high-tech vs low-tech seals; role of protocols and inspector training
Locator: main text
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: enclosure needs in low-trust AI verification; open question on retrofittable enclosures for side-channel defence; inspections
Locator: §2b; §4.2; §5.3.1
Version and catalogue details - S-0067 / Tier C
Verification Plan ↗
R. Dean · 2026 · AI 2040
Supports: tamper-evident enclosures among physical security measures
Locator: physical security discussion
Version and catalogue details - S-0035 / Tier B
Flexible Hardware-Enabled Guarantees for AI Compute ↗
J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv
Supports: flexHEG secure enclosure for physical tamper protection
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review