Project Details
Updated 07/10/26 · Provided via application · VerifiedMy previous research project developed a workload classifier that distinguishes training, inference, and non-ML computations, based on short snapshots of NVML telemetry logs (which record utilization of different GPU components). However, this system has security vulnerabilities, both in NVIDIA software libraries, and inherently in any operating system that is running alongside the ML workload, which could allow an evader to spoof the telemetry and insert readings that cause a training workload to be misclassified as inference or something else.
Project is planned by me, and physical construction is done by my research fellow Felix. When all the hardware is running, I'll do the ML experiments in my existing project repo, plus new ones. For context, see my paper https://arxiv.org/abs/2606.19262 and repository https://github.com/robirahman/GPU-monitoring/
Theory of Impact
Updated 07/10/26 · By grantmaking.aiThis makes AI governance more reliable and prevents developers from cheating by disguising training workloads as inference or non-ML computations.
People
Updated 07/12/26 · Edited by orgTeam Member
Funding Details
- Feb 1, 2026
- -
- 3 months
- -
- -
- -
- -
- -
- partially funded
- -
Track Record
Advanced the state of the art on workload classification, including adversarial robustness testing, which has never been done before for AI workloads. (Small precedent exists for covert crypto mining, but our trials are much more extensive.) I've published a paper illustrating a previous phase of this research.
Discussion
Private comment. Only shown to approved funders and grant reviewers.
Hi Robi,
We'd like to fund this for $30k. Logistics:
Did you receive funding from anywhere since submitting this application, or has the funding ask changed for any other reason?
Please confirm your commitment to post quarterly updates on how the project is going
Obvious question is how adversarially robust this is, and obvious answer is not very. That's not a fatal objection, as you can see from the grant, but I would like to hear your ambitious thoughts about a fully successful successor to this project.
Good luck!
Minor CoI: I know Robi a little, we've met twice.
Hi Gavin,
We haven't received any more funding that I'm aware of since I submitted this, but Felix was applying for some small (~$5k) personal/transitional funds, so I'll check with him if he got any of those.
The main thing to mention is that we haven't been able to receive our previously awarded FAR AI verification grant yet due to legal bureaucracy. They can only grant to US 501(c)(3) orgs, so they want to give the money to MIRI who would then have to re-grant the money to AI Safety Aachen (a registered nonprofit in Germany) who would re-grant it to Felix. We can't give the money to Felix directly because then a large chunk would be lost to taxes. So we would like to know if you can make this grant unrestricted, so that we're able to re-grant it, or if you can give the grant to AI Safety Aachen.
Yes, I am happy to provide updates at least quarterly, or even much more often. Easiest for us would be if you join our Slack channel where we have active discussion, but I assume you prefer that I give you quarterly summaries. We also might have another paper drafted in ~3 weeks.
3
[replied privately about upcoming results on adversarial robustness]
I still lean toward thinking this method can be made adversarially robust in the multi-node case, because training models larger than one node's memory requires so much interconnect bandwidth (but I still have to think about the implications of low-communication distributed methods here).
@Anton Makiievskyi 🔸
@Gavin Leech @Robi Rahman happy to make the grant unrestricted , as long as Manifund is be able to distribute it
Private comment. Only shown to approved funders and grant reviewers.