发表机构
The University of Melbourne; University of Oxford(墨尔本大学; 牛津大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究推导功耗测量对隐蔽计算的约束上限,发现仅凭功耗无法有效限制计算,但结合重新执行验证可显著降低隐藏计算量。
AI 中文摘要
前沿AI条约或关于限制计算的协议需要外部验证;外部审计员必须能够确认实际运行了多少计算,以及各方是否遵守协议。模拟的、芯片外的测量(如功耗)为验证提供了信息通道。目前尚不清楚这些模拟通道在对抗主动试图破坏审计的对手时,能在多大程度上约束计算。我们推导出$\eta$的闭式解,$\eta$是功耗轨迹无法排除的最大隐藏计算量,以声明机器容量的分数表示。在NVIDIA A100 GPU上的测量在 worst case 下约束$\eta = 1.16$,而对抗性的匹配能量策略被证明至少能隐藏$\eta = 0.41$的计算量。因此,仅凭模拟功耗测量对计算的约束很弱。威胁模型提供的额外限制,例如验证者在观察到的操作点重新执行声明工作的能力,使得验证者在最大限制情况下能将$\eta$降至$0.059$。这为模拟测量对计算验证的贡献提供了定量估计。
英文摘要
Frontier AI treaties or agreements on limiting computation require external verification; an external auditor must be able to confirm how much computation actually ran and that parties are adhering to the agreement. Analogue, off-chip measurements such as power draw provide an information channel for verification. It is unknown how well these analogue channels can constrain computation against an adversary who actively tries to subvert the audit. We derive a closed form for $β$, the largest hidden computation a power trace cannot exclude, as a fraction of the declared machine capacity. Measurements on NVIDIA A100 GPUs constrain $β= 1.16$ in the worst case, while adversarial matched-energy strategies are shown to hide at least $β= 0.41$ of compute. Analogue power measurements alone therefore constrain compute weakly. Additional restrictions granted by the threat model, such as the ability of the verifier to re-execute the declared work at an observed operating point, let the verifier push $β$ down to $0.059$ in the maximally restricted case. This gives a quantitative estimate of what analogue measurements can contribute to compute verification.
Comments14 pages, 8 figures