Mechanisms · category
Cryptographic & computational
Protocols that check computation itself: recomputation, zero-knowledge proofs, proofs of learning, proofs of work, challenge-response.
| Name | Type | Readiness | Verifies | Threat model |
|---|---|---|---|---|
| Apple Private Cloud Compute Apple's cloud AI inference service, in which user devices send requests only to servers that attest to running software published in a public transparency log. | Implementation | R3In production | Semi-trusted prover | |
| Deterministic and bit-exact inference Making model inference reproducible bit for bit, so that a verifier's re-run must match the provider's output exactly rather than approximately. | Mechanism | R3In production | Adversarial prover | |
| Model identity attestation Establishes that responses come from a specific, committed set of model weights, using enclave measurements or recomputation of sampled outputs. | Mechanism | R3In production | Semi-trusted prover | |
| Pearl proof-of-useful-work blockchain A blockchain whose mining is designed to be a by-product of GPU matrix multiplications in AI workloads, with public node and miner code. | Implementation | R3In production | Adversarial prover | |
| Sampled inference recomputation A verifier re-runs a random sample of an AI provider's logged queries on a trusted copy of the declared model and checks the outputs match. | Mechanism | R3In production | Adversarial prover | |
| TEE remote attestation for AI workloads Trusted execution environments (TEEs) in CPUs and GPUs sign reports of loaded software, so a remote party can check which code ran an AI workload. | Mechanism | R3In production | Semi-trusted prover | |
| Tinfoil model identity (Modelwrap) Tinfoil's method for proving which model weights its enclave-hosted inference service runs, by binding a dm-verity hash of the weights into remote attestation. | Implementation | R3In production | Semi-trusted prover | |
| TOPLOC TOPLOC is a hashing scheme from Prime Intellect that lets a verifier check whether an inference provider ran the model, prompt and precision it claims. | Implementation | R3In production | Adversarial prover | |
| Verde and RepOps (Gensyn) Gensyn's system for checking delegated machine-learning jobs, which settles disagreements between providers by re-running a single operation with bitwise-reproducible operators. | Implementation | R3In production | Adversarial prover | |
| Attestable Audits A research prototype that runs AI safety benchmarks inside a trusted execution environment and publishes attestations binding the model, the audit and the results. | Implementation | R2Demonstrated | Semi-trusted prover | |
| Batch-invariant inference kernels (Thinking Machines) Open-source kernels from Thinking Machines Lab that make LLM outputs independent of batch size, adopted in vLLM and SGLang to give reproducible inference. | Implementation | R2Demonstrated | Cooperative prover | |
| Bounding unexplained information in outputs Limits the hidden information a facility's outputs can carry by measuring how much of those outputs the declared computation fails to predict. | Mechanism | R2Demonstrated | Adversarial prover | |
| Confidential multi-party verification Lets mutually distrusting parties run an agreed check over private models or records inside attested enclaves or zero-knowledge proofs, revealing only the result. | Mechanism | R2Demonstrated | Semi-trusted prover | |
| DiFR (Divergence From Reference) DiFR checks that an inference provider ran its declared model by comparing output tokens or activations with a trusted re-run using the same random seed. | Implementation | R2Demonstrated | Adversarial prover | |
| EZKL EZKL is a library from Zkonduit that turns neural networks into zero-knowledge circuits, so a prover can show an output came from a committed model. | Implementation | R2Demonstrated | Adversarial prover | |
| PySyft double-blind evaluations PySyft coordinates an attested enclave where a model owner and evaluator run tests without sharing weights or private prompts. | Implementation | R2Demonstrated | Semi-trusted prover | |
| Safeguard attestation Hardware-signed evidence that an AI service ran its declared safeguards, such as a guardrail classifier or monitor, when producing a given response. | Mechanism | R2Demonstrated | Semi-trusted prover | |
| Timed challenge-response and memory-occupation challenges A verifier sends unpredictable questions that a device can answer in time only if it holds specified data, or dedicates specified resources, locally. | Mechanism | R2Demonstrated | Adversarial prover | |
| Training-transcript verification (proof-of-learning) A trainer logs checkpoints, data order and settings, so a verifier can re-run sampled training segments and check that the claimed training happened. | Mechanism | R2Demonstrated | Adversarial prover | |
| Zero-knowledge proofs of inference A prover produces a cryptographic proof that an output came from running a committed model on a given input, without revealing the weights. | Mechanism | R2Demonstrated | Adversarial prover | |
| Zero-knowledge proofs of training constraints Cryptographic proofs that a training run followed a committed dataset, procedure and rules, checkable without revealing the model or the data. | Mechanism | R2Demonstrated | Adversarial prover | |
| zkLLM zkLLM is a GPU-accelerated zero-knowledge proof system that proves a large language model's output came from committed weights without revealing those weights. | Implementation | R2Demonstrated | Adversarial prover | |
| AI 2040 inference-only verification stack A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs. | Implementation | R1Proposed | Adversarial prover | |
| Attestable zero-knowledge inference prover Attestable's zero-knowledge prover, which the company reports proves large language model outputs came from committed weights at tens of tokens per second. | Implementation | R1Proposed | Adversarial prover | |
| Chip registries and manufacturing records Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later. | Mechanism | R1Proposed | Semi-trusted prover | |
| Low-trust AI compute verification system overview A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records. | Implementation | R1Proposed | Adversarial prover | |
| Memory wiping and proofs of secure erasure Overwriting a device's memory in a way a verifier can check, so that data from earlier, undeclared work cannot persist in memory the wipe reaches. | Mechanism | R1Proposed | Adversarial prover | |
| Network taps and certifiers Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work. | Mechanism | R1Proposed | Adversarial prover | |
| Proofs of useful work for capacity accounting Cryptographic evidence that a given amount of matrix-multiplication work was completed, proposed as one input to accounting for spare capacity on declared hardware. | Mechanism | R1Proposed | Adversarial prover | |
| SASH confidential network logger An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference. | Implementation | R1Proposed | Semi-trusted prover | |
| Whole-workload recomputation (reproducible packets) Organizing all AI workloads in a facility into discrete, reproducible units, so that a verifier can recompute a random sample and check each one. | Mechanism | R1Proposed | Adversarial prover |
Includes records that list this as a secondary category. Claims in grey italics are supported rather than aimed at.