M-0016 / Cryptography & computation

Timed challenge-response and memory-occupation challenges

A verifier sends unpredictable questions that a device can answer in time only if it holds specified data, or dedicates specified resources, locally.

R2 DemonstratedSource reviewed 2026-09-25

01 / The mechanism and its boundary

What the technique establishes

A timed challenge is an unpredictable question that a device can answer in time only if it holds certain data locally or dedicates certain resources to the answer. Designs differ in what the answer depends on: the device's own code, data it claims to hold, its whole memory capacity, or its spare compute. Each design has its own implementation page. The approach builds on software-based attestation of embedded devices and on proofs of space. AI-specific public work is thin: one design overview, one study on T4 and H100 GPUs showing that response times reveal co-running models and whether data sits in GPU memory, and one peer-reviewed attestation scheme for GPUs. As of September 2026, no network-level test across data-centre servers has been reported. The main obstacle is excluding outside help, such as fast remote memory. Published attacks on embedded attestation are partly disputed by two of its designers.

Threat model
Adversarial prover
Adversarial evaluation
Published analysis
Hardware needed
None
Prover cooperation
Required
Confidentiality
Preserving
Category
Cryptography & computation

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R2 Demonstrated

Assessed use: detecting whether a GPU is doing other work

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

R2 for detecting whether a GPU is doing other work: published experiments on T4 and H100 GPUs show that challenge response times reveal co-running models and data residency, but only on single GPUs, and no challenge that bounds free memory across servers has been shown.

  • R1 met: the MIRI overview describes memory challenges for verifying the presence of information and the absence of free memory, with timing figures and assumptions S-0018. The AI 2040 plan names memory-challenge verification as a possible direction S-0067. The underlying primitives (timed attestation, proofs of space and proofs of secure erasure) are peer-reviewed S-1307 S-1607 S-1304 S-0032.
  • R2 met through reproducible published results. Monfared et al. describe four verifier-issued challenge probes with their parameters and sample counts, under a threat model in which host and GPU firmware "may be modified, virtualized, or colluding" S-0033. On T4 and H100 GPUs, solve times rise when language models run alongside, and a VRAM-residency challenge separates data in GPU memory from data in host memory by more than 350 ms S-0033. No code is linked, which the rubric does not require. SAGE shows timed software attestation on A100 GPUs for trusted execution, not for detecting other work S-1306. The level rests on GPU contention probes (upstream draft) and VRAM-residency challenge (upstream draft), the implementations that report these results. Data-centre memory challenging (upstream draft) and Low-trust AI compute verification system overview are proposed designs without results.
  • R3 not met: no production-grade challenge tool is publicly documented, and no source reports a party other than the authors relying on such challenges for a verification decision. For bounding spare memory (This compute runs inference, not training), the MIRI overview states that, to its author's knowledge, a network-level timing probe of memory contents between servers "has not yet been demonstrated" S-0018.

Confidence is medium: the results come from one group's single-GPU experiments without quantified error rates.

Evidence needed for the next level

  • Production-grade challenge tooling, or use by a party other than the developers for a verification decision.

  • A network-level challenge that bounds free memory across accelerator servers, with public code or measurements described in enough detail to repeat.

  • Quantified false-positive and false-negative rates under adversarial conditions.

  • Evaluation against known attack classes on timed attestation, such as compression and relocation.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / disputed / demonstrated attack

Timing-based software attestation has been broken in practice

Castelluccia et al. implemented two generic attacks, one based on a return-oriented rootkit and one on code compression, together with specific attacks on SWATT and ICE-based schemes, on commodity sensor nodes. They conclude that secure time-based attestation is "very difficult, if not impossible, to design correctly". The attacks target embedded schemes, not AI accelerators.

S-1308S-0074
Response recorded by the source map

Perrig and van Doorn, two of the designers of SWATT and ICE, replied in August 2010. They argue that the rootkit attack defeats a naive implementation, not a property the schemes claim, and that the SWATT attack was run on a re-implementation on a chip with eight times the program memory, where SWATT's own chip is almost always full of code. They accept that the attack on ICE works S-0074.

significant / open / theoretical argument

Remote memory narrows the timing margin

Data-centre remote memory access returns in about 1–2 µs, against about 70–200 ns for local DRAM. The MIRI overview says verification of memory saturation depends on ruling out remote access by latency or physical disconnection. It adds that pre-staging data is ruled out only by unpredictable, capacity-filling challenges.

S-0018

minor / open / open question

Error rates not quantified

Monfared et al. show separable timing distributions but do not define thresholds or statistical tests, so false-positive and false-negative rates are not quantified.

S-0033

What still blocks use or stronger assurance

  1. No network-level memory challenge across data-centre servers has been demonstrated.

    S-0018
  2. Challenges that fill memory displace workloads; filling a pod's volatile memory takes tens of minutes and SSDs take hours.

    S-0018S-0033
  3. Outside help, such as remote memory, must be excluded during challenges.

    Dependency: Bandwidth limits and compartmentalization

    S-0018

Connections in the research map

Complementary techniques

Alternative approaches

Concepts used

Organizations and developers

Implementations

Sources and provenance

  1. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: memory challenging for presence and absence; response-time domains; latencies; fill times; RDMA caveat; pre-staging; not yet demonstrated at network level

    Locator: §5.1.2

    Version and catalogue details
  2. S-0067 / Tier C

    Verification Plan ↗

    R. Dean · 2026 · AI 2040

    Supports: memory-challenge verification and low-latency challenges as alternative directions

    Locator: verification overview; other promising directions

    Version and catalogue details
  3. S-0033 / Tier B

    Timing and Memory Telemetry on GPUs for AI Governance ↗

    S. K. Monfared, F. Ganji, D. E. Holcomb, S. Tajik · 2026 · arXiv

    Supports: PoW, VDF, GEMM and VRAM-residency probes; contention results on T4 and H100; H100 residency result; threat model; overhead; FP/FN caveat

    Locator: abstract; §4–§6; limitations

    Version and catalogue details
  4. S-1306 / Tier A

    SAGE: Software-based Attestation for GPU Execution ↗

    A. Ivanov, B. Rothenberger, A. Dethise, M. Canini, T. Hoefler, A. Perrig · 2023 · 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 485–499

    Supports: software-based attestation on A100 GPUs

    Locator: abstract

    Version and catalogue details
  5. S-1307 / Tier A

    SWATT: SoftWare-based ATTestation for Embedded Devices ↗

    A. Seshadri, A. Perrig, L. van Doorn, P. Khosla · 2004 · IEEE Symposium on Security and Privacy 2004, pp. 272–282

    Supports: timed checksum attestation; verifier knowledge requirements

    Locator: abstract; design sections

    Version and catalogue details
  6. S-1308 / Tier A

    On the Difficulty of Software-Based Attestation of Embedded Devices ↗

    C. Castelluccia, A. Francillon, D. Perito, C. Soriente · 2009 · Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), pp. 400–409

    Supports: demonstrated attacks on timed attestation; conclusions

    Locator: abstract; §3–§5

    Version and catalogue details
  7. S-0074 / Tier B

    Refutation of "On the Difficulty of Software-Based Attestation of Embedded Devices" ↗

    A. Perrig, L. van Doorn · 2010 · Technical note (CyLab, Carnegie Mellon University)

    Supports: designers' reply: rootkit attack on a naive implementation; SWATT attack on a larger-memory re-implementation; ICE attack accepted

    Locator: §2.1–§2.3

    Version and catalogue details
  8. S-1607 / Tier A

    Proofs of Space ↗

    S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak · 2015 · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796)

    Supports: proofs of space: dedicating disk space instead of computation; construction

    Locator: abstract

    Version and catalogue details
  9. S-0032 / Tier A

    Software-Based Memory Erasure with Relaxed Isolation Requirements ↗

    S. Bursuc, R. Gil-Pons, S. Mauw, R. Trujillo-Rasua · 2024 · 2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024)

    Supports: timed rounds with a round-trip bound in PoSE; peer-reviewed timed PoSE

    Locator: §3

    Version and catalogue details
  10. S-1302 / Tier C

    Memory Wipes - Performance Analysis ↗

    Amodo Design · 2026 · Amodo Design

    Supports: challenge phase of a PoSE implementation; 1 ms RTT assumption

    Locator: protocol section

    Version and catalogue details
  11. S-1304 / Tier A

    Secure Code Update for Embedded Devices via Proofs of Secure Erasure ↗

    D. Perito, G. Tsudik · 2010 · Computer Security – ESORICS 2010, LNCS 6345, pp. 643–662

    Supports: peer-reviewed proofs of secure erasure; weaknesses of timed software attestation as motivation

    Locator: abstract

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review