Bit2Watt (arXiv:2607.05993) now anchors three claim-notes directly, with a fourth blocked by the single-source concentration cap — what would corroborate it, and does its stated CHES/TCHES acceptance already clear the bar?
As of 2026-09-09, three notes in 30-notes/ rest directly on Ji, Pan & Xu's "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures" (arXiv:2607.05993) as their source_url:
- claim-bit2watt-gpu-scheduling-destabilizes-power-grid
- claim-bit2watt-citations-omit-kocher-1999-zhao-suh-2018
- claim-power-side-channel-attacks-scaled-chip-to-grid-1999-2026 (type
observation, but itssource_urlis the same arXiv abstract page — it counts)
Per sources.md's single-source concentration cap (Cali, 2026-07-29): "No more than three claim-notes may rest on a single unrefereed primary... until at least one independent source corroborates it," where independence means "a different author group and a different venue." That count is exactly three. The cap is reached.
What this blocked
The promotion of 10-inbox/raw/2026-09-08-how-does-bit2watts-own-reverse-watt2bit-path-allegedly.md (2026-09-09) produced three well-sourced, Tier-1 findings from a full direct read of Bit2Watt's own text — all of which would have become claim-notes but for the cap. Recording them here rather than dropping them, per the cap's own instruction that "the next finding from that source does not become a claim-note. It goes to 50-questions/ as a corroboration question."
Held finding 1 — the exfiltration mechanism. Watt2Bit's §4.4 states the mechanism generally ("an adversary could encode bits by modulating either the attack frequency or the attack amplitude... A receiver observing these side-channel emissions could then demodulate the corresponding spectral or amplitude features to recover the transmitted symbols"); §5.3.5 gives the concrete implementation — binary bits FSK-encoded on the GPU load profile at 2 kHz ("1") / 200 Hz ("0"), 10 ms bit duration, decoded via a relative-energy ratio between two fixed EMI frequency bands (600–800 kHz vs. 1080–1180 kHz).
Held finding 2 — the demonstration. §5.3.5 reports an actual lab experiment, not just an analytical projection: EMI captured via a near-field antenna-coupled USRP B210 software-defined radio, decoded with "an accuracy exceeding 99%," and Figure 15(c) shows "the successful recovery of a 50-bit test sequence, where every transmitted bit is correctly identified with zero bit errors." Scope is narrow — near-field only, one 50-bit run, no distance/range or multi-trial statistics.
Held finding 3 — the paper hedges its own result. The abstract calls the whole risk "a plausible Watt2Bit feedback path"; §5.3.5's own conclusion sentence, written immediately after the 99%-accuracy result, says only that power modulation "could potentially serve as a feasible covert channel" — and the paper's final Conclusion (§6), which restates the paper's contributions, mentions only the denial-of-service consequence and drops the exfiltration finding entirely, despite a dedicated experiment three pages earlier. The paper's own Contributions section (§1.1) uses stronger language ("further demonstrate that the same mechanism may also enable covert information exfiltration") than either the abstract or the conclusion — so the paper's own certainty language is inconsistent across its own sections.
Held lead — a possible second citation-omission pattern. A full-text search of Bit2Watt's 28 pages and bibliography found no mention of "Guri," "TEMPEST," or "air-gap" — the established academic EM/acoustic/thermal air-gap covert-channel-exfiltration subfield (Mordechai Guri's AirHopper/GSMem/MAGNETO/ODINI line) appears uncited, despite being the closest prior art to Watt2Bit's own EMI-exfiltration claim. This would parallel claim-bit2watt-citations-omit-kocher-1999-zhao-suh-2018 (a second, independent instance of the same citation-omission pattern) but the capture that found it explicitly flagged it as "worth a dedicated verification capture rather than asserting it here as a settled claim" — it wasn't checked with the same rigor (exact quote, page-by-page bibliography pass) as the Kocher/Zhao-Suh finding was. Also blocked by the cap regardless: confirming it would be a fourth Bit2Watt-sourced claim-note.
What would discharge the cap
Two live paths, not yet checked (no network access in the sessions that found these):
- Independent corroboration — a different author group, different venue, replicating or citing either the grid-destabilization finding or the EMI-exfiltration demonstration. No citation, replication, or commentary on Bit2Watt has been checked for in this vault yet (unlike the parallel cricket-Laws corroboration sweep at question-corroborate-cricket-laws-preprint-single-source, which did run this search for its own capped preprint).
- Refereed-status ruling — every Bit2Watt-derived note's frontmatter carries
source_venue: "arXiv preprint (accepted, IACR Transactions on Cryptographic Hardware and Embedded Systems / CHES 2026)", but this "accepted" status has never itself been verified against a primary record (CHES/TCHES's own accepted-papers list or proceedings page, or the arXiv listing's own "comments" field stating the acceptance). The 2026-08-17 ruling at question-corroborate-steck-2024-cosine-arbitrariness-single-source-cap (now claim-steck-2024-www-short-paper-cleared-committee-peer-review) found that a paper cleared through a genuine committee peer-review process is categorically outside the cap's "unrefereed primary" list, even while circulating as a preprint/companion paper. IACR TCHES runs a rigorous multi-round journal-style peer review — if Bit2Watt's CHES/TCHES acceptance is real and verifiable at the primary, the same logic would likely apply here, and the cap may not bind on this source at all. This promotion session declined to make that ruling unilaterally, since (unlike the Steck case) no primary acceptance record has actually been read — the "accepted" language in this vault's frontmatter is an inherited assertion, not a verified fact. A future session with network access should check the CHES 2026 program/proceedings page or arXiv's own comment field before ruling either way.
Until one of these lands, the branch stays exactly as it is — three notes, seedling, honest — and no new Bit2Watt-sourced claim-note should be written.
Progress log
- [object Object]