cs.CYOct 5, 2026

Can Power Draw Constrain Covert Compute? Limits of Analogue Verification for AI Governance

Authors: Tom Kimpson, Mauricio Baker, Emlyn Graham

Abstract

Frontier AI treaties or agreements on limiting computation require external verification; an external auditor must be able to confirm how much computation actually ran and that parties are adhering to the agreement. Analogue, off-chip measurements such as power draw provide an information channel for verification. It is unknown how well these analogue channels can constrain computation against an adversary who actively tries to subvert the audit. We derive a closed form for ββ, the largest hidden computation a power trace cannot exclude, as a fraction of the declared machine capacity. Measurements on NVIDIA A100 GPUs constrain β=1.16β= 1.16 in the worst case, while adversarial matched-energy strategies are shown to hide at least β=0.41β= 0.41 of compute. Analogue power measurements alone therefore constrain compute weakly. Additional restrictions granted by the threat model, such as the ability of the verifier to re-execute the declared work at an observed operating point, let the verifier push ββ down to 0.0590.059 in the maximally restricted case. This gives a quantitative estimate of what analogue measurements can contribute to compute verification.

Explore similar work

CardsList
  1. Workload Identification with Physical Side Channels for AI Governance

    Aug 31, 2026Simone Gargiulo, Gabriel KulpAdversarial AttacksAI Governance

  2. Does Distributed Training Undermine Compute Governance?

    May 28, 2026Robi RahmanDistributed TrainingAI Governance