arXiv Machine Learning By Robi Rahman, Sabiha Tajdari

Detecting Hidden ML Training With Zero-Overhead Telemetry

Read the original on arXiv Machine Learning →

arXiv:2606. 19262v1 Announce Type: new Abstract: Hardware-enabled monitoring of GPU workloads underpins many proposals for AI compute governance, but if developers can defeat monitoring mechanisms, such schemes are unworkable.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Machine Learning.

arXiv AI
Sep 2

Workload Identification with Physical Side Channels for AI Governance

The paper demonstrates that an external observer can identify the type of workload running on an NVIDIA H200 GPU by analyzing its power draw, distinguishing training, inference, and non‑AI tasks with high accuracy. Using 930 recorded traces, the authors achieve 97% accuracy and a macro‑averaged F1 score of 0.955 on unseen model families. They also test four evasion strategies to disguise training as inference, showing that a hardened detector can catch most attacks, though one strategy (LoRA) remains partially detectable.

By Simone Gargiulo, Gabriel Kulp
arXiv Machine Learning
Jun 2

Bit-Exact AI Inference Verification Without Performance Tradeoffs

arXiv:2606. 00279v1 Announce Type: cross Abstract: Verifying claims about AI workloads is a pre- requisite for credible AI governance of covert adversaries (who comply with monitoring only when detection likelihood is high), yet the ap- parent non-determinism of GPU floating-point arithmetic forces auditors to accept approximate output matches.

By Naci Cankaya
arXiv Machine Learning
Sep 16

OPEN-1B: A Fully Auditable Training Run

The paper introduces Open-1B, a language model trained under a new fully auditable regime that ensures every training operation is reproducible on heterogeneous commodity hardware with bitwise certainty. By enforcing a fixed order on sources of nondeterminism—GPU reductions, data batch ordering, and inter/intra-node communication—the authors enable auditors to replay and verify individual training steps on a single machine. The release includes the full pretraining dataset, all intermediate checkpoints, the training codebase, and an audit harness for step-by-step verification.

By John Donaghy, Brian Wilcox, O\u{g}uzhan Ersoy, Shikhar Rastogi, Adam St Arnaud, Alexey Titov, Jordan Greenberg, Ben Fielding, Harry Grieve
arXiv Machine Learning
Aug 31

Not to Break, but to Attest: Adversarial Probes for Privacy-Preserving LLM Verification

The paper introduces a privacy‑preserving zk‑SNARK audit framework that uses adversarial‑style probes to detect logit drift between an approved large language model and a modified deployment. It offers three probe families—token‑based (black‑box), embedding‑based (gray‑box), and stress probes (partial white‑box)—allowing users to balance sensitivity, access, and cost. Experiments across LLM architectures and GPU platforms show token‑based probes achieve the highest mean sensitivity while remaining practical in a black‑box setting, with Groth16 proving times scaling modestly from 1.02 to 1.78 seconds and constant proof size.

By Cameron Wilding, Mina Shaker, Fatemeh Ganji
arXiv AI
Sep 21

TERMon: Detecting Persistent Behavioral Threats in Edge AI via Hardware-Native Ternary Runtime Monitor

TERMon is a lightweight hardware runtime monitor designed for edge AI accelerators in safety‑critical environments. It detects persistent behavioral threats—such as model corruption, distribution shift, and adversarial inputs—by observing inference behavior through hardware‑efficient ternary patterns matched against a thermometer‑encoded fingerprint. Implemented on a PYNQ‑Z2 FPGA, TERMon operates with a two‑cycle decision latency and requires no on‑chip block RAM or DSPs.

By Arish Sateesan, Edlira Dushku
arXiv Machine Learning
Aug 24

RouteScan: A Non-Intrusive Approach to Auditing MoE LLMs Safety via Expert Routing Telemetry

RouteScan is a non‑intrusive auditing framework that detects harmful behavior in Mixture‑of‑Experts (MoE) large language models by analyzing expert‑routing telemetry captured from GPU execution. It uses the number of active GPU threads during the prefilling phase as a micro‑architectural fingerprint to isolate cross‑domain risk indicators and precisely identify malicious prompts. Evaluations on four open‑source MoE LLMs show strong generalization with AUROC > 0.91 on unseen harmful domains, while privacy tests indicate that full prompts cannot be reliably recovered from aggregated telemetry.

By Bo Lv, Zhiheng Xu, KeDong Xiu, Ruyi Ding, Tianhang Zheng, Zhibo Wang, Kui Ren