Security Veterans Push Back on AI Air-Gap Heat-Channel Threat Claims
In response to claims that "AI could covertly communicate between air-gapped computers via CPU heat," several security and tech figures pushed back on September 18, with one core message: don't assume superintelligent AI is exempt from the laws of physics. Renowned security researcher Halvar Flake (Thomas Dullien) published a rebuttal, urging people to first estimate how many bits per minute such a channel could actually extract. He stressed that AI is still bound by the second law of thermodynamics, the cost of acquiring information, noisy channels, and measurement error—fundamental physical and information-theoretic constraints. He did not claim AI can never find side channels; rather, he argued that "useful side channels that deliver meaningful capability gains" are an entirely different matter, and that side-channel attacks face real information-theoretic and physical limits.
Confirmed
- Halvar Flake's rebuttal targets recent AI-doomsday-style concerns (linked to claims by Noam Brown and others) that "two AIs might communicate covertly by heating their CPUs."
- Quantum computing expert whurley publicly disputed the claim that air-gapped computers can be remotely attacked via thermal signals, arguing the threat is overstated and largely academic, and cited the IEEE BitWhisper paper as the literature source behind the claim.
- Gary Marcus shared a post from deedydas: two air-gapped computers can indeed communicate through temperature changes, but the rate is far too slow (only a few bits per hour) to be practical; the real threat lies in the far faster techniques in the literature, such as those exploiting DRAM.
Why it matters
- The debate touches on the core methodology of AI safety assessments: AI risks should be evaluated against the physical and information-theoretic upper bounds of channel capacity, rather than assuming superintelligence can bypass all physical constraints.
- The rebuttals don't deny that side-channel threats exist—they argue for distinguishing "theoretically feasible" from "practically useful," so threat narratives aren't exaggerated while faster side-channel techniques in the literature aren't overlooked.
- The discussion also exposes a public rift between AI doomsayers (e.g., claims associated with Noam Brown) and veteran security practitioners—worth watching whether AI safety evaluation standards shift as a result.
2026-09-18 ~ 2026-09-18 · 5 related posts
- Episode 1: OpenAI's Noam Brown: Air-Gapping Won't Stop Rogue AI, CPUs Could Talk via Heat(2026-09-18, 12 posts)
- Episode 2: Debate Rages Over Whether AI Can Exfiltrate Data via Fan Noise from Air-Gapped Systems(2026-09-18, 2 posts)
- Episode 3: tszzl: Containing an uncooperative superintelligence is ten times harder than you think(2026-09-18, 5 posts)
- Episode 4: Debate over superhuman AI side-channel escape scenarios(2026-09-18, 3 posts)
- Episode 5: Security Veterans Push Back on AI Air-Gap Heat-Channel Threat Claims(2026-09-18, 5 posts)
- Episode 6: a16z's Casado pushes back on 'air gaps are useless' AI risk claims(2026-09-18, 2 posts)
- Episode 7: Security researcher debunks claims that AI could breach air-gapped networks via side channels(2026-09-18, 6 posts)
Primary sources
- [source] whurley cites BitWhisper paper to debunk Noam Brown's air-gap attack fearmongering — whurley · 2026-09-18
- [source] Gary Marcus jumps into Noam Brown airgap debate: DRAM EM leaks hit 300kbps — GaryMarcus · 2026-09-18
- Halvar Flake: Don't Assume Hyperintelligent AI Isn't Subject to Physics, CPU-Heat Covert Channels Have Tiny Bandwidth — AccBalanced · 2026-09-18
- [source] Halvar Flake: Useful AI Side Channels Face Real Information-Theoretic and Physical Limits — basedjensen · 2026-09-18
- Halvar Flake: stop assuming AI is exempt from the second law of thermodynamics — tobowers · 2026-09-18