Red team vs. blue team: tamper with the hardware, then switch sides and trace the evidence.
Red tries to run a prohibited training run while making the hardware-verification stack keep reporting “compliant.” Blue spends a limited budget on detection layers. The lesson lives in the gap: every tamper defeats one layer but leaves a residual tell that an independent layer can catch. No single mechanism holds — verification is Swiss cheese.
SCENARIO
Step 1 of 3 · pass the screen to the Red player
Red — the evader
Budget: 0 / 8Pick the tampering techniques you’ll deploy. You cannot afford everything — that’s the point. Each card shows what layer it defeats and the tell it leaves behind. Or bluff: Stay honest and dare Blue to false-alarm.
Facilitator notes & debrief prompts
- The core teaching move (Swiss cheese). A single detection layer is beatable. Independent layers with different blind spots converge — which is why cross-layer reconciliation (comparing chip attestation vs. facility power vs. procurement) is the most powerful and most expensive card. Ask: did the winning catch come from the direct counter, or from a tell picked up elsewhere?
- Cost–cost, not a wall (Ray). Blue can’t buy everything — they satisfice. The debrief question is never “was the stack perfect,” it’s “given the budget, was this the residual-risk portfolio you can most live with?” Every layer has a price: money, intrusiveness, sovereignty friction, and false positives.
- The false-alarm trap. A maximal Blue stack raises the chance of flagging an honest party (run the “Stay honest” bluff and watch it fire). Tie this to base-rate reasoning: a regime that treats every anomaly as an existential red alert drowns in false positives and loses credibility to escalate when it matters.
- Assumptions are load-bearing. Flip a scenario toggle mid-debrief and re-resolve. “Vendor won’t patch physical attacks” makes the tamper-evident enclosure the only recourse for an interposer (a real 2025 fact — AMD declined to mitigate physical SEV-SNP attacks). “Legacy fleet” guts the on-chip layers and forces Blue onto off-chip + human evidence. The ranking of good moves changes with the assumption — that’s the lesson, not the specific outcome.
- Falsifiability. Ask each player: what single piece of evidence would flip your confidence judgment one band? If they can’t name it, they have a narrative, not a judgment.
- Tamper-evidence, not tamper-proofing. The real-world standard (IAEA-style, carried into FlexHEG) is not that tampering is impossible, but that tampering a large fleet can’t go undetected. Surface this when Red “succeeds” on one chip: would it scale to 50,000 without leaving a trace?
Grounded in: FlexHEG (guarantee processor + secure enclosure); “Six Layers of Verification” (RAND); BadRAM / DDR5-interposer attacks on SEV-SNP; MOLE firmware attack; zero-overhead GPU telemetry. All techniques are anticipated threats — no such treaty exists yet.