Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors

📅 2026-06-09
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses a critical challenge in verifying compliance with future international AI agreements: preventing AI clusters from covertly leaking undisclosed computation results via I/O channels in the absence of mutually trusted processors. The paper proposes a novel security architecture that eliminates the need for shared trusted hardware between Prover and Verifier. By employing passive optical splitters to capture all I/O traffic in real time, the system generates tamper-evident data fingerprints through hash commitments and coin-tossing protocols. A secure gateway further neutralizes covert channels—including emulation, timing side channels, and protocol header steganography. This approach enables the first auditable yet privacy-preserving verification of AI cluster I/O, offering low cost, ease of deployment, and rapid prototyping by small teams within months, thereby effectively blocking covert exfiltration paths while supporting post-hoc compliance audits.
📝 Abstract
In preparation for potential international agreements on artificial intelligence, the development of verification infrastructure for AI data centres is vital. We propose a method for cryptographically committing all information entering and leaving a data centre: Hashes are computed by network taps placed on all the information-carrying wires between the cluster and the outside world, enabling an auditor to retroactively challenge the preimage data to be sent to a privacy-preserving verification facility performing compliance checks. Our goal is to make it infeasible to covertly exfiltrate the results of undisclosed workloads in the cluster through the tapped wires. To this end, we specify the architecture of a ``Secure Gateway Device'', which handles the erasure of covert channels that post-hoc verification on hashed data cannot address: analogue and timing side-channels, as well as steganography in network protocol headers. The architecture eliminates the need for any processors trusted by both the Prover and the Verifier, leveraging passive optical fibre splitters and coin-flip protocols for random number generation where needed. We expect development costs of a demonstration device to be roughly equivalent to the cost of a small team of engineers for a few months, with a comparatively small bill of materials.
Problem

Research questions and friction points this paper is trying to address.

AI verification
data center I/O fingerprinting
covert channel elimination
privacy-preserving auditing
secure gateway
Innovation

Methods, ideas, or system contributions that make the work stand out.

cryptographic commitment
covert channel elimination
trusted processor-free verification
network tap hashing
privacy-preserving audit
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
N
Naci Cankaya
MATS, Oxford Hardware AI Governance Lab
J
Jakub Kryś
SaferAI
J
Jonathan Ng
Independent
L
Luke Marks
Martian
F
Felix Krückel
RWTH Aachen University, Aachen, Germany