Escape via shared accelerators
Statement (NASA form)
Given that training and inference tenants share GPUs, caches, and sometimes memory fabrics, there is a possibility of a tenant reading or influencing another tenant’s weights or prompts resulting in cross-customer leakage of secrets, and a path out of a logical sandbox.
Side channels did not go away because the workload is a transformer.
Composite 10 = 2×4 + 2
Applicable mitigations
Controls · Automatic session kill on unexpected egress · Hardware-enforced sandbox with attested images · Default-deny egress for eval and untrusted agents · Mandatory chain-of-thought monitoring on tool-using evals and RL · Capability thresholds that cannot be open-released · Know-your-customer on high-end fine-tune clusters · Pair open release with synthesis and exploit screening upgrades