01 / The mechanism and its boundary
What the technique establishes
A timed challenge is an unpredictable question that a device can answer in time only if it holds certain data locally or dedicates certain resources to the answer. Designs differ in what the answer depends on: the device's own code, data it claims to hold, its whole memory capacity, or its spare compute. Each design has its own implementation page. The approach builds on software-based attestation of embedded devices and on proofs of space. AI-specific public work is thin: one design overview, one study on T4 and H100 GPUs showing that response times reveal co-running models and whether data sits in GPU memory, and one peer-reviewed attestation scheme for GPUs. As of September 2026, no network-level test across data-centre servers has been reported. The main obstacle is excluding outside help, such as fast remote memory. Published attacks on embedded attestation are partly disputed by two of its designers.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- None
- Prover cooperation
- Required
- Confidentiality
- Preserving
- Category
- Cryptography & computation
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
Declared hardware is idle or shut down
Compute and memory probes can reveal whether a GPU is engaged in other work (S-0033).
This compute runs inference, not training
Listed as an alternative inference-verification direction that may not need a hardware retrofit (S-0067); bounds spare memory (S-0018).
Chips are where they are declared to be
Speed-of-light bounds on signed challenge round trips underlie delay-based location checks; see M-0018.
Readiness for a stated use
Assessed use: detecting whether a GPU is doing other work
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
R2 for detecting whether a GPU is doing other work: published experiments on T4 and H100 GPUs show that challenge response times reveal co-running models and data residency, but only on single GPUs, and no challenge that bounds free memory across servers has been shown.
- R1 met: the MIRI overview describes memory challenges for verifying the presence of information and the absence of free memory, with timing figures and assumptions S-0018. The AI 2040 plan names memory-challenge verification as a possible direction S-0067. The underlying primitives (timed attestation, proofs of space and proofs of secure erasure) are peer-reviewed S-1307 S-1607 S-1304 S-0032.
- R2 met through reproducible published results. Monfared et al. describe four verifier-issued challenge probes with their parameters and sample counts, under a threat model in which host and GPU firmware "may be modified, virtualized, or colluding" S-0033. On T4 and H100 GPUs, solve times rise when language models run alongside, and a VRAM-residency challenge separates data in GPU memory from data in host memory by more than 350 ms S-0033. No code is linked, which the rubric does not require. SAGE shows timed software attestation on A100 GPUs for trusted execution, not for detecting other work S-1306. The level rests on GPU contention probes (upstream draft) and VRAM-residency challenge (upstream draft), the implementations that report these results. Data-centre memory challenging (upstream draft) and Low-trust AI compute verification system overview are proposed designs without results.
- R3 not met: no production-grade challenge tool is publicly documented, and no source reports a party other than the authors relying on such challenges for a verification decision. For bounding spare memory (This compute runs inference, not training), the MIRI overview states that, to its author's knowledge, a network-level timing probe of memory contents between servers "has not yet been demonstrated" S-0018.
Confidence is medium: the results come from one group's single-GPU experiments without quantified error rates.
Evidence needed for the next level
Production-grade challenge tooling, or use by a party other than the developers for a verification decision.
A network-level challenge that bounds free memory across accelerator servers, with public code or measurements described in enough detail to repeat.
Quantified false-positive and false-negative rates under adversarial conditions.
Evaluation against known attack classes on timed attestation, such as compression and relocation.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / disputed / demonstrated attack
Timing-based software attestation has been broken in practice
Castelluccia et al. implemented two generic attacks, one based on a return-oriented rootkit and one on code compression, together with specific attacks on SWATT and ICE-based schemes, on commodity sensor nodes. They conclude that secure time-based attestation is "very difficult, if not impossible, to design correctly". The attacks target embedded schemes, not AI accelerators.
Perrig and van Doorn, two of the designers of SWATT and ICE, replied in August 2010. They argue that the rootkit attack defeats a naive implementation, not a property the schemes claim, and that the SWATT attack was run on a re-implementation on a chip with eight times the program memory, where SWATT's own chip is almost always full of code. They accept that the attack on ICE works S-0074.
significant / open / theoretical argument
Remote memory narrows the timing margin
Data-centre remote memory access returns in about 1–2 µs, against about 70–200 ns for local DRAM. The MIRI overview says verification of memory saturation depends on ruling out remote access by latency or physical disconnection. It adds that pre-staging data is ruled out only by unpredictable, capacity-filling challenges.
minor / open / open question
Error rates not quantified
Monfared et al. show separable timing distributions but do not define thresholds or statistical tests, so false-positive and false-negative rates are not quantified.
What still blocks use or stronger assurance
- S-0018
No network-level memory challenge across data-centre servers has been demonstrated.
- S-0018S-0033
Challenges that fill memory displace workloads; filling a pod's volatile memory takes tens of minutes and SSDs take hours.
Outside help, such as remote memory, must be excluded during challenges.
Dependency: Bandwidth limits and compartmentalization
S-0018
Connections in the research map
Complementary techniques
Alternative approaches
Concepts used
Organizations and developers
Implementations
Sources and provenance
- S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: memory challenging for presence and absence; response-time domains; latencies; fill times; RDMA caveat; pre-staging; not yet demonstrated at network level
Locator: §5.1.2
Version and catalogue details - S-0067 / Tier C
Verification Plan ↗
R. Dean · 2026 · AI 2040
Supports: memory-challenge verification and low-latency challenges as alternative directions
Locator: verification overview; other promising directions
Version and catalogue details - S-0033 / Tier B
Timing and Memory Telemetry on GPUs for AI Governance ↗
S. K. Monfared, F. Ganji, D. E. Holcomb, S. Tajik · 2026 · arXiv
Supports: PoW, VDF, GEMM and VRAM-residency probes; contention results on T4 and H100; H100 residency result; threat model; overhead; FP/FN caveat
Locator: abstract; §4–§6; limitations
Version and catalogue details - S-1306 / Tier A
SAGE: Software-based Attestation for GPU Execution ↗
A. Ivanov, B. Rothenberger, A. Dethise, M. Canini, T. Hoefler, A. Perrig · 2023 · 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 485–499
Supports: software-based attestation on A100 GPUs
Locator: abstract
Version and catalogue details - S-1307 / Tier A
SWATT: SoftWare-based ATTestation for Embedded Devices ↗
A. Seshadri, A. Perrig, L. van Doorn, P. Khosla · 2004 · IEEE Symposium on Security and Privacy 2004, pp. 272–282
Supports: timed checksum attestation; verifier knowledge requirements
Locator: abstract; design sections
Version and catalogue details - S-1308 / Tier A
On the Difficulty of Software-Based Attestation of Embedded Devices ↗
C. Castelluccia, A. Francillon, D. Perito, C. Soriente · 2009 · Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), pp. 400–409
Supports: demonstrated attacks on timed attestation; conclusions
Locator: abstract; §3–§5
Version and catalogue details - S-0074 / Tier B
Refutation of "On the Difficulty of Software-Based Attestation of Embedded Devices" ↗
A. Perrig, L. van Doorn · 2010 · Technical note (CyLab, Carnegie Mellon University)
Supports: designers' reply: rootkit attack on a naive implementation; SWATT attack on a larger-memory re-implementation; ICE attack accepted
Locator: §2.1–§2.3
Version and catalogue details - S-1607 / Tier A
Proofs of Space ↗
S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak · 2015 · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796)
Supports: proofs of space: dedicating disk space instead of computation; construction
Locator: abstract
Version and catalogue details - S-0032 / Tier A
Software-Based Memory Erasure with Relaxed Isolation Requirements ↗
S. Bursuc, R. Gil-Pons, S. Mauw, R. Trujillo-Rasua · 2024 · 2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024)
Supports: timed rounds with a round-trip bound in PoSE; peer-reviewed timed PoSE
Locator: §3
Version and catalogue details - S-1302 / Tier C
Memory Wipes - Performance Analysis ↗
Amodo Design · 2026 · Amodo Design
Supports: challenge phase of a PoSE implementation; 1 ms RTT assumption
Locator: protocol section
Version and catalogue details - S-1304 / Tier A
Secure Code Update for Embedded Devices via Proofs of Secure Erasure ↗
D. Perito, G. Tsudik · 2010 · Computer Security – ESORICS 2010, LNCS 6345, pp. 643–662
Supports: peer-reviewed proofs of secure erasure; weaknesses of timed software attestation as motivation
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review