arXiv:cs.AI· Tom Kimpson, Mauricio Baker, Emlyn Graham·· 10 小时前AI 评分42
功耗能否约束隐蔽算力?AI 治理中模拟验证的极限
Can Power Draw Constrain Covert Compute? Limits of Analogue Verification for AI Governance
AI 导读
研究推导出功耗轨迹无法排除的最大隐蔽算力 β(占申报机器容量的比例),在 NVIDIA A100 GPU 上实测最坏情况 β = 1.16,对抗性能量匹配策略可隐藏至少 β = 0.41 的算力。若验证方能在观测工作点重执行申报任务,最大受限情形下 β 可压至 0.059,表明仅靠模拟功耗测量对算力的约束较弱。
正文
Abstract:Frontier AI treaties or agreements on limiting computation require external verification; an external auditor must be able to confirm how much computation actually ran and that parties are adhering to the agreement. Analogue, off-chip measurements such as power draw provide an information channel for verification. It is unknown how well these analogue channels can constrain computation against an adversary who actively tries to subvert the audit. We derive a closed form for $\beta$, the largest hidden computation a power trace cannot exclude, as a fraction of the declared machine capacity. Measurements on NVIDIA A100 GPUs constrain $\beta = 1.16$ in the worst case, while adversarial matched-energy strategies are shown to hide at least $\beta = 0.41$ of compute. Analogue power measurements alone therefore constrain compute weakly. Additional restrictions granted by the threat model, such as the ability of the verifier to re-execute the declared work at an observed operating point, let the verifier push $\beta$ down to $0.059$ in the maximally restricted case. This gives a quantitative estimate of what analogue measurements can contribute to compute verification.
| Comments: | 14 pages, 8 figures |
| Subjects: | Computers and Society (cs.CY); Artificial Intelligence (cs.AI); Cryptography and Security (cs.CR) |
| Cite as: | arXiv:2610.07476 [cs.CY] |
| (or arXiv:2610.07476v1 [cs.CY] for this version) | |
| https://doi.org/10.48550/arXiv.2610.07476 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Tom Kimpson [view email]
[v1]
Mon, 5 Oct 2026 22:40:45 UTC (179 KB)
来源:arXiv:cs.AI · arxiv.org