Fall 2026 mentee applications are open! Apply to research projects by August 18. Apply now

All Fall 2026 projects

De-risk a technical crux of retrofittable AI datacenter workload verification systems

Compute governance US-China governance AI security

There is a range of problems to resolve in order to make verification of international AI agreements work. Among current technical bets (network monitoring, analog sensors, verifiable resource exhaustion, memory pinging, ...) some have technical cruxes that need more investigation.

About the project

To mitigate dangerous racing dynamics between AI-developing global powers (read: USA and China), a trustless and privacy-preserving monitoring and verification regime may be needed soon. The combination of high security, privacy preservation, and robustness against evasion poses a technical challenge that calls for novel solutions.

We pick a niche problem together.

To get up to speed on the context, I recommend skimming these two publications:

https://www.rand.org/pubs/working\_papers/WRA4077-1.html https://www.lesswrong.com/posts/fgvmKqRGvBteKeDoc/a-system-overview-for-near-term-low-trust-ai-compute

The second one lists multiple open research questions, and mentees can choose among them. Alternatively, I am open to related project proposals beyond the ones listed in the post.

Here are some examples of technical cruxes:

How viable is physical security as a deterrent against large-scale evasion attempts? Suppose a "datacenter lie detector" kind of system was installed, and its proper operation relies on the monitoring devices being untampered. Is physical security against nation-state level actors possible at this scale, and what concessions would this take? Note that only large-scale, consequential evasion counts as a failure (e.g. a week of automated AI research using a datacenter's worth of compute).

What makes a computing substrate unilaterally secure against any software-attacks (i.e. a chip that the USG trusts but China not, and vice versa). Formal verification of all logic? Note that "secure" means that it can not be made to produce any specific output, not "can not be broken".

Theory of change

De-risking AI compute verification approaches informs research agendas and helps prepare technology for an international agreement.

Without such agreements, "arms race" continues to be a convenient and politically potent excuse for frontier labs to be reckless with AI.

Your role

Two possible paths:

  1. Investigative research + interviews. Gather publicly available information on the question at hand, e.g. about FPGAs in military applications (for unilaterally secure chips).
  2. Experimental work on cloud compute. Example: How useful is precise re-computation (see https://arxiv.org/abs/2606.00279) for disproving that a machine ran no undeclared workloads in parallel?

The mentees will have most of the agency and handle execution work. They will be the lead (if not sole) authors of any publication.

Mentorship will be for project selection, unblocking when questions arise, feedback on writing and warm intros to relevant researchers.

Prerequisites

  • Strong STEM generalist.
  • Ability to learn quickly and reason from first principles.
  • High agency and initiative.
  • Over-communicates, but keeps signal-to-noise ratio high.

Bonus:

  • Security experience. Cyber or physical.
  • Conducted research in a STEM field, e.g. computer science, physics, etc.
  • Coding proficiency.
  • Strong writing skills, demonstrable through prior work

Application question(s)

https://www.lesswrong.com/posts/fgvmKqRGvBteKeDoc/a-system-overview-for-near-term-low-trust-ai-compute

Identify key cruxes with the proposed system. Are they resolvable? How would you approach this? Did anything strike you as factually off/a dealbreaker even?

About the mentor

Naci Cankaya

Naci Cankaya

Machine Intelligence Research Institute

Naci’s work at MIRI's Technical Governance Team is focused on transparency and verification mechanisms for AI development and use. These mechanisms aim to enable international agreements on restraint and caution with AI, as well as democratic oversight over AI technologies and stakeholders. Naci has a master’s degree in physics from RWTH Aachen University and conducted research on AI hardware technology and supply chains under mentorship from Aaron Scher at SPAR and Mauricio Baker at MATS.

Similar projects