{"resourceId":"kvgov-cache-isolation-study-260809225-v1","versions":[{"version":"external-22700eff3a9f0c1b297b592374273424f6979d9010ef0a20c8cdc405b60ef547","resource":{"id":"kvgov-cache-isolation-study-260809225-v1","title":"Cache-isolation preprint separates hardware timing evidence from simulated defenses","organization":"Tejasvi C. Addagada","sector":"AI inference platforms and shared-service assurance","geography":"Global technical applicability; no U.S. SLED field evaluation","publishedAt":"2026-08-10","publicationDate":"2026-08-10","eventDate":null,"sourceName":"arXiv","sourceLabel":"Independent author research preprint; affiliation not established","sourceUrl":"https://arxiv.org/html/2608.09225v1","evidenceClass":"independent-research","outcomeClass":"cautionary","topics":["developers-agents","infrastructure","data-security","governance-procurement","operating-model"],"finding":"The preprint measures a cache timing distinction and proposes principal-specific isolation; defense effectiveness is not established in production.","sledRelevance":"Interpretation: Relevant to government and education teams assessing shared copilots, coding assistants and document workflows. No measured SLED benefit or additional stream tag is asserted.","evidence":"Table 8 reports cold/cached latencies of 149.6/32.8 ms for a 2,119-token prefix on Qwen2.5-7B, vLLM 0.26.0 and A100, with 50 observations per arm across two blocks. Its stated 0.22 ratio is cached divided by cold, despite reversed wording. Defense experiments use 1,000 simulated trials; extreme success-rate columns are analytic controls.","architectureImplications":"Interpretation: validate the complete serving path and intended tenancy model before selecting placement or capacity.","governanceImplications":"Interpretation: assign separate approval owners for performance, answer quality and information boundaries.","securityPrivacyImplications":"Interpretation: protect prompts, retrieved records and telemetry; test authorization beyond the front-end login.","caveats":"No NIM or Nemotron test. Boundary-salting efficiency is extrapolated, semantic-cache isolation unmeasured, and field adversarial testing remains future work. Table 4 and prose disagree on noise results; the load adversary differs from the theorem's payoff. Those numerical claims are excluded.","streamIds":["nvidia"],"roles":{"sales":"Interpretation: Discuss shared assistant confidentiality with security, data stewards and the service owner. Ask which groups share infrastructure and which documents enter prompts. Offer a bounded architecture and assurance review using synthetic content. The value hypothesis is identifying an unexamined information boundary before wider adoption. This paper can motivate questions but cannot quantify a customer's likelihood of compromise, demonstrate an institutional incident or certify a defense. Request production evidence from suppliers and avoid presenting simulation outputs as observed breach reduction.","engineering":"Interpretation: Map authenticated users to every cache and retrieval store in the proposed service. Require synthetic fixtures, isolated test identities and explicit permission boundaries. Compare allowed reuse within a principal with prohibited reuse across principals, recording server and client telemetry under realistic load. Inspect semantic retrieval separately from exact-match caching. Validate the actual engine and release instead of importing a paper's configuration. A useful proof of value demonstrates traceable identity enforcement and measures the resulting capacity cost; it does not establish universal protection against all side channels.","delivery":"Interpretation: Security engineering should own the threat model with platform operators and application maintainers. Implement an inventory of shared state, change approval and incident escalation. Dependencies include trustworthy identity propagation, test capacity and staff able to interpret timing measurements. Train maintainers to revisit the boundary when routes or storage change. Proposed acceptance requires documented ownership for every shared store, reproducible tests of allowed and denied reuse, and a demonstrated containment procedure. Review before sensitive records enter the service. Risks include incomplete identity mapping and mistaking laboratory controls for operational assurance."},"retrievedAt":"2026-09-11T03:00:56Z","enrichedAt":"2026-09-11T03:03:34Z","enrichmentBasis":"retrieved source","accessibilityWorkforceImplications":"Interpretation: include assistive-technology users in workflow validation and budget operator training; the source measures no accessibility outcome.","procurementImplications":"Interpretation: require workload-specific evidence, support obligations and recurring-cost assumptions.","operatingModelImplications":"Interpretation: retain an accountable service owner, maintained test corpus and change-triggered revalidation.","updateExplanation":"New to the archive, not newly published today. Selected as scrutiny and implementation context for the September 10 cache-heavy serving benchmark; identifier and related-topic archive searches found no matching record.","sourceVerification":{"openedUrl":"https://arxiv.org/html/2608.09225v1","referenceExcerpt":"The 100% and 0% columns are analytic controls, not empirical findings","promptVersion":"sled-research-v3.1","model":null,"basis":"agent-reported inspection"}}}]}