Mechanisms · category

Cryptographic & computational

Protocols that check computation itself: recomputation, zero-knowledge proofs, proofs of learning, proofs of work, challenge-response.

NameTypeReadinessVerifiesThreat model
Apple Private Cloud Compute
Apple's cloud AI inference service, in which user devices send requests only to servers that attest to running software published in a public transparency log.
ImplementationR3In productionSemi-trusted prover
Deterministic and bit-exact inference
Making model inference reproducible bit for bit, so that a verifier's re-run must match the provider's output exactly rather than approximately.
MechanismR3In productionAdversarial prover
Model identity attestation
Establishes that responses come from a specific, committed set of model weights, using enclave measurements or recomputation of sampled outputs.
MechanismR3In productionSemi-trusted prover
Pearl proof-of-useful-work blockchain
A blockchain whose mining is designed to be a by-product of GPU matrix multiplications in AI workloads, with public node and miner code.
ImplementationR3In productionAdversarial prover
Sampled inference recomputation
A verifier re-runs a random sample of an AI provider's logged queries on a trusted copy of the declared model and checks the outputs match.
MechanismR3In productionAdversarial prover
TEE remote attestation for AI workloads
Trusted execution environments (TEEs) in CPUs and GPUs sign reports of loaded software, so a remote party can check which code ran an AI workload.
MechanismR3In productionSemi-trusted prover
Tinfoil model identity (Modelwrap)
Tinfoil's method for proving which model weights its enclave-hosted inference service runs, by binding a dm-verity hash of the weights into remote attestation.
ImplementationR3In productionSemi-trusted prover
TOPLOC
TOPLOC is a hashing scheme from Prime Intellect that lets a verifier check whether an inference provider ran the model, prompt and precision it claims.
ImplementationR3In productionAdversarial prover
Verde and RepOps (Gensyn)
Gensyn's system for checking delegated machine-learning jobs, which settles disagreements between providers by re-running a single operation with bitwise-reproducible operators.
ImplementationR3In productionAdversarial prover
Attestable Audits
A research prototype that runs AI safety benchmarks inside a trusted execution environment and publishes attestations binding the model, the audit and the results.
ImplementationR2DemonstratedSemi-trusted prover
Batch-invariant inference kernels (Thinking Machines)
Open-source kernels from Thinking Machines Lab that make LLM outputs independent of batch size, adopted in vLLM and SGLang to give reproducible inference.
ImplementationR2DemonstratedCooperative prover
Bounding unexplained information in outputs
Limits the hidden information a facility's outputs can carry by measuring how much of those outputs the declared computation fails to predict.
MechanismR2DemonstratedAdversarial prover
Confidential multi-party verification
Lets mutually distrusting parties run an agreed check over private models or records inside attested enclaves or zero-knowledge proofs, revealing only the result.
MechanismR2DemonstratedSemi-trusted prover
DiFR (Divergence From Reference)
DiFR checks that an inference provider ran its declared model by comparing output tokens or activations with a trusted re-run using the same random seed.
ImplementationR2DemonstratedAdversarial prover
EZKL
EZKL is a library from Zkonduit that turns neural networks into zero-knowledge circuits, so a prover can show an output came from a committed model.
ImplementationR2DemonstratedAdversarial prover
PySyft double-blind evaluations
PySyft coordinates an attested enclave where a model owner and evaluator run tests without sharing weights or private prompts.
ImplementationR2DemonstratedSemi-trusted prover
Safeguard attestation
Hardware-signed evidence that an AI service ran its declared safeguards, such as a guardrail classifier or monitor, when producing a given response.
MechanismR2DemonstratedSemi-trusted prover
Timed challenge-response and memory-occupation challenges
A verifier sends unpredictable questions that a device can answer in time only if it holds specified data, or dedicates specified resources, locally.
MechanismR2DemonstratedAdversarial prover
Training-transcript verification (proof-of-learning)
A trainer logs checkpoints, data order and settings, so a verifier can re-run sampled training segments and check that the claimed training happened.
MechanismR2DemonstratedAdversarial prover
Zero-knowledge proofs of inference
A prover produces a cryptographic proof that an output came from running a committed model on a given input, without revealing the weights.
MechanismR2DemonstratedAdversarial prover
Zero-knowledge proofs of training constraints
Cryptographic proofs that a training run followed a committed dataset, procedure and rules, checkable without revealing the model or the data.
MechanismR2DemonstratedAdversarial prover
zkLLM
zkLLM is a GPU-accelerated zero-knowledge proof system that proves a large language model's output came from committed weights without revealing those weights.
ImplementationR2DemonstratedAdversarial prover
AI 2040 inference-only verification stack
A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs.
ImplementationR1ProposedAdversarial prover
Attestable zero-knowledge inference prover
Attestable's zero-knowledge prover, which the company reports proves large language model outputs came from committed weights at tens of tokens per second.
ImplementationR1ProposedAdversarial prover
Chip registries and manufacturing records
Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.
MechanismR1ProposedSemi-trusted prover
Low-trust AI compute verification system overview
A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records.
ImplementationR1ProposedAdversarial prover
Memory wiping and proofs of secure erasure
Overwriting a device's memory in a way a verifier can check, so that data from earlier, undeclared work cannot persist in memory the wipe reaches.
MechanismR1ProposedAdversarial prover
Network taps and certifiers
Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work.
MechanismR1ProposedAdversarial prover
Proofs of useful work for capacity accounting
Cryptographic evidence that a given amount of matrix-multiplication work was completed, proposed as one input to accounting for spare capacity on declared hardware.
MechanismR1ProposedAdversarial prover
SASH confidential network logger
An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference.
ImplementationR1ProposedSemi-trusted prover
Whole-workload recomputation (reproducible packets)
Organizing all AI workloads in a facility into discrete, reproducible units, so that a verifier can recompute a random sample and check each one.
MechanismR1ProposedAdversarial prover

Includes records that list this as a secondary category. Claims in grey italics are supported rather than aimed at.

Search

Full search page