Security researcher debunks claims that AI could breach air-gapped networks via side channels
On September 18, security researcher Blanche Minerva posted a series of threads systematically rebutting the popular risk narrative that AI could someday use side-channel attacks, making even air-gapped networks insufficient as a defense. Her core conclusion: the claim is technically unsound. Covert channels in air-gapped networks have extremely low bandwidth, and "possible non-zero information exchange" by no means implies "a model can bypass an air gap the way it bypasses a weak sandbox."
Confirmed
- She noted that the heat-exchange example Noam cited comes from the BitWhisper research, whose maximum throughput is just 0.002 bits per second—heat is a terrible medium for data transmission.
- The fastest air-gap side-channel scheme she knows of is BitJabber, at only about 300kbps; real-world throughput would be several orders of magnitude lower.
- Even if all physical challenges were solved with major breakthroughs, an observer with internet access would at best get a one-way channel carrying less than 10 GB per week.
- Two-way communication is conceptually impossible to achieve naturally: it would require OpenAI to first install antennas inside the isolated network, or rely on coordination between internal and external agents—and the latter presumes the model is already deployed, which is circular reasoning.
Unconfirmed
- She criticized proponents of the "AI penetrates air gaps" narrative for never specifying what side-channel attacks could actually be used for, calling it an exaggerated narrative dressed up as "taking the AI threat seriously."
Why it matters
- The debate bears directly on the frontier safety question of whether air-gapping suffices to contain misaligned AI. If low-bandwidth side channels truly cannot support model escape or large-scale exfiltration, air gaps remain a viable defense—and overhyping the risk could distort resource allocation and public perception.
2026-09-18 ~ 2026-09-18 · 6 related posts
- Episode 1: OpenAI's Noam Brown: Air-Gapping Won't Stop a Rogue AI(2026-09-18, 11 posts)
- Episode 2: Debate Rages Over Whether AI Can Exfiltrate Data via Fan Noise from Air-Gapped Systems(2026-09-18, 2 posts)
- Episode 3: tszzl: Containing an uncooperative superintelligence is ten times harder than you think(2026-09-18, 5 posts)
- Episode 4: Debate over superhuman AI side-channel escape scenarios(2026-09-18, 3 posts)
- Episode 5: Debate Erupts Over Noam Brown's Air-Gapped Computer Threat Claims(2026-09-18, 2 posts)
- Episode 6: a16z's Casado pushes back on 'air gaps are useless' AI risk claims(2026-09-18, 2 posts)
- Episode 7: Security researcher debunks claims that AI could breach air-gapped networks via side channels(2026-09-18, 6 posts)
Primary sources
- AI safety researcher pushes back on claims that side-channel attacks make air-gapped networks insufficient — BlancheMinerva · 2026-09-18
- [source] Safety researcher debunks claim that AI could escape air-gapped networks — BlancheMinerva · 2026-09-18
- [source] Air-gap exfiltration is slow: BitWhisper hits 0.002 bps, best known BitJabber just 300 kbps — BlancheMinerva · 2026-09-18
- Air-gapped covert channels: BitWhisper tops out at 0.002 bits/s, BitJabber at 300 kbps — BlancheMinerva · 2026-09-18
- [source] Even with physics breakthroughs, air-gapped leaks would stay under 10 GB/week — BlancheMinerva · 2026-09-18
- Covert AI Exfiltration Channels Are Impractical: Under 10 GB/Week, Need Dedicated Hardware — BlancheMinerva · 2026-09-18