← Latest papers
💻 computer science

SL5 Standard for AI Security

This paper introduces the Security Level 5 (SL5) standard, a forward-looking framework for AI datacenter security designed to withstand state-level cyber threats by prioritizing long-lead-time infrastructure and organizational developments that must be initiated immediately to ensure feasibility by 2028/2029.

Original authors: Lisa Thiergart, Yoav Tzfati, Peter Wagstaff, Guy, Luis Cosio, Philip Reiner

Published 2026-05-12
📖 6 min read🧠 Deep dive

Original authors: Lisa Thiergart, Yoav Tzfati, Peter Wagstaff, Guy, Luis Cosio, Philip Reiner

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a group of top engineers and security experts from the world's biggest AI labs and governments getting together to build a "Fort Knox" for the most powerful artificial intelligence models ever created. They call this plan Security Level 5 (SL5).

Think of the AI models they are protecting not just as software, but as the "crown jewels" of the future—digital brains that could design new medicines, solve climate change, or even design better AI. Because these models are so valuable, the people trying to steal them (like rival nations with unlimited budgets and super-smart hackers) are as dangerous as a country's entire military cyber-unit.

This document is a draft blueprint (Version 0.1) for how to build a fortress around these digital brains so that even the most powerful enemies can't steal or break them. Here is the plan, broken down into simple concepts:

1. The Threat: The "Super-Hacker"

The paper assumes the enemy is incredibly smart. Imagine a team of 1,000 geniuses working for a government, with a budget of $1 billion, trying to steal your AI for years. They have resources far beyond what any normal company has. The goal of SL5 is to stop them.

2. The Strategy: The "Air-Gapped" Castle

The core idea is to build a digital castle that is completely cut off from the outside world.

  • The Air Gap: Imagine a room with no windows and no doors that connect to the internet. This is the SL5 Network. Nothing goes in or out electronically. If you want to move data in or out, you have to physically carry it on a hard drive, like a spy passing a microfilm in a movie.
  • The "Weight Enclave": Inside this castle, there is a smaller, even stronger room called the Weight Enclave. This is where the actual "brain" of the AI (its weights) lives. It's like a safe inside a vault. Only the absolute minimum amount of software is allowed in here, and it's strictly controlled.

3. The Five Pillars of Defense

🏰 Physical Security: The "Fortress"

The buildings housing these AI computers aren't just normal data centers; they are built like government secret facilities (called SCIFs).

  • The Walls: The rooms are shielded so no radio signals can leak out (like a Faraday cage) and no one can listen in through the walls.
  • The Doors: To get in, you have to go through a "mantrap"—a small room with two doors. The first door closes before the second opens, so no one can sneak in behind you.
  • The People: Only the most trusted people (with top-level security clearances) can enter alone. Everyone else needs a guard to hold their hand the whole time.

🤖 Machine Security: The "Unbreakable Box"

The computers (accelerators) running the AI need special hardware features.

  • The Independent Brain: The AI chip is like a robot that doesn't trust its own computer. Even if the main computer (the host) is hacked, the AI chip locks itself down and refuses to let the hacker see the data.
  • The Seal: The chip checks its own ID every time it starts up to make sure no one swapped its brain with a fake one.

🧍 Personnel Security: The "Inner Circle"

The paper introduces a new way to check people's backgrounds, called Sensitivity Levels (SenL).

  • The Levels: Think of it like a video game with 5 levels of clearance.
    • Level 1: You can walk in the lobby.
    • Level 5: You can walk into the secret room alone.
  • The Vetting: To get Level 5, you need a background check so deep it's almost like a government spy clearance. The paper admits that private companies might need the government's help to do this perfectly.

📦 Supply Chain Security: The "Ingredient Check"

Just as a chef checks every ingredient for poison, the AI builders must check every piece of hardware and every line of code.

  • The Staging Area: Before any new data (like a new dataset for training) enters the castle, it sits in a "quarantine zone." It's scanned by robots and humans to make sure it doesn't contain hidden traps (like "poisoned" data that tricks the AI).
  • The Parts: The chips and servers must come from trusted suppliers. If a chip looks suspicious, it gets inspected with X-rays to make sure no one planted a secret backdoor inside it.

🔒 Network Security: The "One-Way Street"

  • No Internet: The main network has no connection to the outside internet.
  • The "Rule of Two": If data must move between two different buildings, it goes through two different encryption machines made by two different companies. It's like having two different locks on a door; if one fails, the other still holds.
  • The Speed Limit: There is a physical speed limit on how much data can leave the "Weight Enclave." Even if a hacker tries to steal the whole AI brain, the "pipe" is too narrow to let it all out in time.

4. The Big Unknowns (Open Questions)

The authors are honest that they don't have all the answers yet. They are asking for help on three big puzzles:

  1. Can we trust our own people? Is a private company's background check good enough to stop a nation-state spy, or do we need the government to step in?
  2. Can we catch the "invisible" poison? Can we build a detector that finds every single trick an enemy might use to poison the AI's training data? (Right now, the answer is "we aren't sure.")
  3. Can we train AI across the world? If the "Weight Enclave" can't be connected to the internet, how do we train a massive AI using computers in different countries? The paper suggests we might have to move data by truck (physical media) instead of the internet, which is slow and hard.

Summary

This document is a "preliminary draft" for a super-secure way to build AI. It says: "To protect the most powerful AI from the world's best hackers, we need to build physical fortresses, use special unbreakable hardware, check our employees like spies, and cut off the internet completely."

It's a bold plan that admits it's hard to do, but argues that if we want to build the future of AI safely, we have to start building these fortresses now.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →