---
格式版本: 2
标题: "Workload Identification with Physical Side Channels for AI Governance"
原文链接: "https://arxiv.org/abs/2609.00309"
发布日期: "2026-08-31"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Mon, 31 Aug 2026 19:59:35 UTC (231 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-09-04T01:37:19+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-09-04T01:32:14+08:00"
入库时间: "2026-09-03T17:37:19.612Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=GPU&searchtype=all"
匹配关键词:
  - "GPU"
  - "AI"
相关厂家:
  - "NVIDIA"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 18
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为基于GPU功耗侧信道识别AI工作负载，用于AI治理，未涉及超节点/AI Rack/机柜级系统、Scale-up、供电、液冷、量产等核心关注点，与项目主题无关。"
AI质检模型: "zj-deepseek-v4-flash"
AI质检时间: "2026-09-04T01:38:40+08:00"
AI主题相关性: 2
AI来源权威性: 8
AI新颖性: 5
AI技术细节: 2
AI商业部署信号: 0
AI完整性: 1
AI摘要: "研究者利用NVIDIA H200 GPU的功耗物理侧信道，在无需操作方配合的情况下识别AI工作负载类别；基于930条5秒迹线，能以97%准确率和0.955的宏平均F1区分训练、推理与非AI计算。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-04T00:17:53.001Z"
采集批次: "2026年9月3日22点43分34秒"
采集批次ID: "20260903-224334-406"
去重键: "https://arxiv.org/abs/2609.00309"
---

## Computer Science > Cryptography and Security

## Title:Workload Identification with Physical Side Channels for AI Governance

Authors:[Simone Gargiulo](https://arxiv.org/search/cs?searchtype=author&query=Gargiulo,+S), [Gabriel Kulp](https://arxiv.org/search/cs?searchtype=author&query=Kulp,+G)

[View PDF](https://arxiv.org/pdf/2609.00309) [HTML (experimental)](https://arxiv.org/html/2609.00309v1)

> Abstract:AI compute verification is one of the first tangible and tractable points for international policy aimed at AI governance. Determining whether frontier labs, or any operator, comply with agreements requires the regulating authority to discern how their compute is used. The elementary building block of AI compute is the GPU, and any activity it executes leaves a physical trace. Here, we show that an external observer can identify the class of the workload running on an NVIDIA H200 from its power draw. Unlike on-chip NVML telemetry, which can be spoofed or replayed, such a physical channel can in principle be observed independently of operator cooperation. We recorded $930$ five-second traces at $\sim 10$ MHz, covering seventeen open LLM families and twenty-five non-AI workloads. Over this corpus we separate training from inference and from non-AI computation with an accuracy of $97\\%$ and a macro-averaged F1 score of $0.955$, evaluated on model families unseen during training. AI workload spectral content predominantly lies below $\sim 20$ kHz and training is particularly recognizable through the memory-bound optimizer update. The GPU operator is then treated as adversarial and able to reshape the physical computation itself. Four evasion strategies are tested to disguise training as inference, producing an additional 680 adversarial traces. A detector hardened against evasion strategies, with the tested strategy held out, catches training $\geq 99\%$ of the time for three of the four strategies. The fourth, diluted low-rank adaptation (LoRA), is detected $48$--$88\\%$ of the time with a hardened classifier, rising to $\geq 98\%$ with an additional rescue rule. While these attacks are not a comprehensive evaluation against adversarial behaviour, they offer initial insights beyond genuine activities and a dataset for developing and testing stronger evasion mechanisms.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Computers and Society (cs.CY); Machine Learning (cs.LG) |
| Cite as: | [arXiv:2609.00309](https://arxiv.org/abs/2609.00309) \[cs.CR\] |
|  | (or [arXiv:2609.00309v1](https://arxiv.org/abs/2609.00309v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2609.00309](https://doi.org/10.48550/arXiv.2609.00309) |

## Submission history

From: Simone Gargiulo \[[view email](https://arxiv.org/show-email/9402d15a/2609.00309)\]  
**\[v1\]** Mon, 31 Aug 2026 19:59:35 UTC (231 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2609.00309) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
