Understanding Intel's Ivy Bridge Random Number Generator (2012)
electronicdesign.com
electronicdesign.com
That is the basics of how people in astronomy clean their signal.
http://beauty-of-imagination.blogspot.fr/2012/09/fun-with-si...
The average filter is basically correlating the input signal with a (window sized) square wave
It's one of the most basic denoising techniques available (for AWGN)
It definitely depends on your domain, but moving average/median can be extremely effective. (Or terrible, if mis-applied).
http://www.analog.com/media/en/technical-documentation/dsp-b...
And I don't believe there is a general way to distinguish such a device from an actual random source without looking inside. For example, they could use AES256 output in counter mode on a low entopy chip ID + high entropy backdoor key. Trivial to bruteforce given a few words of output, but you would essentially need to break AES to detect it.
Now, before I continue, I should mention that Intel explained that in their design the back-end of RDRAND is completely separate from other (micro)architectural state (like registers). [However, this restriction does not help if you were to assume that e.g. RDRAND microcode is evil].
Theorem of poisonous entropy: Given an attacker able to observe the state of your CSPRNG, they can embed information in the CSPRNG output with negligible computational cost iff they are able to supply entropy.
Therefore, if you don't trust RDRAND to not spy on you, but still use it as an entropy source, you cannot build a secure CSRPNG.
edit: wait, all of them are :(