{"id":"https://openalex.org/W7128635815","doi":"https://doi.org/10.48550/arxiv.2602.09369","title":"Timing and Memory Telemetry on GPUs for AI Governance","display_name":"Timing and Memory Telemetry on GPUs for AI Governance","publication_year":2026,"publication_date":"2026-02-10","ids":{"openalex":"https://openalex.org/W7128635815","doi":"https://doi.org/10.48550/arxiv.2602.09369"},"language":null,"primary_location":{"id":"pmh:doi:10.48550/arxiv.2602.09369","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5021442954","display_name":"Saleh Khalaj Monfared","orcid":"https://orcid.org/0000-0001-5369-5270"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Monfared, Saleh K.","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017195195","display_name":"Fatemeh Ganji","orcid":"https://orcid.org/0000-0003-0151-1307"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ganji, Fatemeh","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075494874","display_name":"Dan Holcomb","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Holcomb, Dan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5119934729","display_name":"Shahin Tajik","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tajik, Shahin","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5021442954"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.6044999957084656,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.6044999957084656,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10054","display_name":"Parallel Computing and Optimization Techniques","score":0.14249999821186066,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10101","display_name":"Cloud Computing and Resource Management","score":0.07509999722242355,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/verifiable-secret-sharing","display_name":"Verifiable secret sharing","score":0.6000000238418579},{"id":"https://openalex.org/keywords/locality","display_name":"Locality","score":0.536899983882904},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5300999879837036},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.4927999973297119},{"id":"https://openalex.org/keywords/observable","display_name":"Observable","score":0.40860000252723694},{"id":"https://openalex.org/keywords/matrix-multiplication","display_name":"Matrix multiplication","score":0.38499999046325684},{"id":"https://openalex.org/keywords/granularity","display_name":"Granularity","score":0.37130001187324524},{"id":"https://openalex.org/keywords/architecture-framework","display_name":"Architecture framework","score":0.3693999946117401},{"id":"https://openalex.org/keywords/power","display_name":"Power (physics)","score":0.36169999837875366}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8083999752998352},{"id":"https://openalex.org/C85847156","wikidata":"https://www.wikidata.org/wiki/Q59015987","display_name":"Verifiable secret sharing","level":3,"score":0.6000000238418579},{"id":"https://openalex.org/C2779808786","wikidata":"https://www.wikidata.org/wiki/Q6664603","display_name":"Locality","level":2,"score":0.536899983882904},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5300999879837036},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.4927999973297119},{"id":"https://openalex.org/C32848918","wikidata":"https://www.wikidata.org/wiki/Q845789","display_name":"Observable","level":2,"score":0.40860000252723694},{"id":"https://openalex.org/C17349429","wikidata":"https://www.wikidata.org/wiki/Q1049914","display_name":"Matrix multiplication","level":3,"score":0.38499999046325684},{"id":"https://openalex.org/C177774035","wikidata":"https://www.wikidata.org/wiki/Q1246948","display_name":"Granularity","level":2,"score":0.37130001187324524},{"id":"https://openalex.org/C53619493","wikidata":"https://www.wikidata.org/wiki/Q4787093","display_name":"Architecture framework","level":3,"score":0.3693999946117401},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.36169999837875366},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.3573000133037567},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3569999933242798},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.34860000014305115},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.34549999237060547},{"id":"https://openalex.org/C118524514","wikidata":"https://www.wikidata.org/wiki/Q173212","display_name":"Computer architecture","level":1,"score":0.3416000008583069},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.3352999985218048},{"id":"https://openalex.org/C2776007630","wikidata":"https://www.wikidata.org/wiki/Q2798912","display_name":"Accountability","level":2,"score":0.33489999175071716},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.3249000012874603},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.3138999938964844},{"id":"https://openalex.org/C2780598303","wikidata":"https://www.wikidata.org/wiki/Q65921492","display_name":"Flexibility (engineering)","level":2,"score":0.3000999987125397},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.2994999885559082},{"id":"https://openalex.org/C39389867","wikidata":"https://www.wikidata.org/wiki/Q380767","display_name":"Corporate governance","level":2,"score":0.29760000109672546},{"id":"https://openalex.org/C133875982","wikidata":"https://www.wikidata.org/wiki/Q764810","display_name":"Shared memory","level":2,"score":0.29429998993873596},{"id":"https://openalex.org/C18131444","wikidata":"https://www.wikidata.org/wiki/Q163585","display_name":"Memory protection","level":5,"score":0.2874000072479248},{"id":"https://openalex.org/C112313634","wikidata":"https://www.wikidata.org/wiki/Q7886648","display_name":"Complement (music)","level":5,"score":0.2849000096321106},{"id":"https://openalex.org/C2778456923","wikidata":"https://www.wikidata.org/wiki/Q5337692","display_name":"Edge computing","level":3,"score":0.2728999853134155},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.27250000834465027},{"id":"https://openalex.org/C176649486","wikidata":"https://www.wikidata.org/wiki/Q2308807","display_name":"Memory management","level":3,"score":0.2718000113964081},{"id":"https://openalex.org/C2780595030","wikidata":"https://www.wikidata.org/wiki/Q3860309","display_name":"Multiplication (music)","level":2,"score":0.26910001039505005},{"id":"https://openalex.org/C49154492","wikidata":"https://www.wikidata.org/wiki/Q5300","display_name":"Central processing unit","level":2,"score":0.2597000002861023}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:doi:10.48550/arxiv.2602.09369","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2602.09369","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.09369","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:doi:10.48550/arxiv.2602.09369","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"sustainable_development_goals":[{"score":0.6428820490837097,"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"rapid":[1],"expansion":[2],"of":[3,75,92,176],"GPU-accelerated":[4],"computing":[5],"has":[6],"enabled":[7],"major":[8],"advances":[9],"in":[10],"large-scale":[11,33],"artificial":[12],"intelligence":[13],"(AI),":[14],"while":[15],"heightening":[16],"concerns":[17],"about":[18],"how":[19],"accelerators":[20],"are":[21,81],"observed":[22],"or":[23,46,62,187],"governed":[24],"once":[25],"deployed.":[26],"Governance":[27],"is":[28,36],"essential":[29],"to":[30,95,122,136,194,230],"ensure":[31],"that":[32,88,101,148,158,179,204],"compute":[34,104],"infrastructure":[35],"not":[37],"silently":[38],"repurposed":[39],"for":[40],"training":[41],"models,":[42],"circumventing":[43],"usage":[44],"policies,":[45],"operating":[47],"outside":[48],"legal":[49],"oversight.":[50],"Because":[51],"current":[52],"GPUs":[53,94],"expose":[54,123],"limited":[55],"trusted":[56,184],"telemetry":[57,219],"and":[58,79,98,153,173,200,207],"can":[59,71,220],"be":[60],"modified":[61],"virtualized":[63],"by":[64,119,225],"adversaries,":[65],"we":[66],"explore":[67],"whether":[68],"compute-based":[69,218],"measurements":[70,147],"provide":[72,171],"actionable":[73],"signals":[74,228],"utilization":[76,212],"when":[77],"host":[78],"device":[80],"untrusted.":[82],"We":[83,190],"introduce":[84],"a":[85,114,155],"measurement":[86],"framework":[87],"leverages":[89],"architectural":[90,196,227],"characteristics":[91],"modern":[93],"generate":[96],"timing-":[97],"memory-based":[99],"observables":[100],"correlate":[102],"with":[103],"activity.":[105],"Our":[106,214],"design":[107],"draws":[108],"on":[109],"four":[110],"complementary":[111],"primitives:":[112],"(1)":[113],"probabilistic,":[115],"workload-driven":[116],"mechanism":[117],"inspired":[118],"Proof-of-Work":[120],"(PoW)":[121],"parallel":[124],"effort,":[125],"(2)":[126],"sequential,":[127],"latency-sensitive":[128],"workloads":[129],"derived":[130],"via":[131],"Verifiable":[132],"Delay":[133],"Functions":[134],"(VDFs)":[135],"characterize":[137],"scalar":[138],"execution":[139],"pressure,":[140,199],"(3)":[141],"General":[142],"Matrix":[143],"Multiplication":[144],"(GEMM)-based":[145],"tensor-core":[146],"reflect":[149],"dense":[150],"linear-algebra":[151],"throughput,":[152],"(4)":[154],"VRAM-residency":[156],"test":[157],"distinguishes":[159],"on-device":[160],"memory":[161,198],"locality":[162],"from":[163],"off-chip":[164],"access":[165],"through":[166],"bandwidth-dependent":[167],"hashing.":[168],"These":[169],"primitives":[170],"statistical":[172],"behavioral":[174],"indicators":[175],"GPU":[177,232],"engagement":[178],"remain":[180],"observable":[181],"even":[182],"without":[183],"firmware,":[185],"enclaves,":[186],"vendor-controlled":[188],"counters.":[189],"evaluate":[191],"their":[192],"responses":[193],"contention,":[195],"alignment,":[197],"power":[201],"overhead,":[202],"showing":[203],"timing":[205],"shifts":[206],"residency":[208],"latencies":[209],"reveal":[210],"meaningful":[211],"patterns.":[213],"results":[215],"illustrate":[216],"why":[217],"complement":[221],"future":[222],"accountability":[223],"mechanisms":[224],"exposing":[226],"relevant":[229],"post-deployment":[231],"governance.":[233]},"counts_by_year":[],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2026-02-12T00:00:00"}
