| A primer on secure enclaves | 2026 | B | Documentation | 5 |
| A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning Z. Peng et al. · Artificial Intelligence Review, vol. 59, no. 7, article 157 | 2026 | A | Peer-reviewed | 2 |
| A System Overview for Near-Term, Low-Trust AI Compute Verification | 2026 | B | Technical report | 38 |
| About Epoch AI | 2026 | B | Documentation | 1 |
| About MIRI | 2026 | B | Documentation | 1 |
| About NVIDIA | 2026 | B | Documentation | 1 |
| About RAND | 2026 | B | Documentation | 1 |
| About us: Centre for the Governance of AI (GovAI) | 2026 | B | Documentation | 1 |
| About: Oxford Martin AIGI | 2026 | B | Documentation | 1 |
| Adversarial Entropy Inflation Against Gumbel-Based Inference Verification N. Kezins · arXiv | 2026 | B | Preprint | 7 |
| AI 2040 Plan A — Verification SITREP | 2026 | C | Blog / article | 7 |
| AI Data Centers Documentation – Methodology | 2026 | B | Documentation | 2 |
| AI Futures Project homepage | 2026 | B | Documentation | 1 |
| AI Verification: Infrastructure for Prosperity, Governance, and Peace B. Harack · Lawfare | 2026 | C | Blog / article | — |
| Amodo Design: About Us | 2026 | B | Documentation | 1 |
| Amodo-Design/Inference-Recomputation-Prototype (GitHub repository) | 2026 | B | Code | 4 |
| Amodo-Design/PoSE-Memory-Wiping (GitHub repository) | 2026 | B | Code | 2 |
| An Inference Verification Prototype — Stage 1 | 2026 | C | Blog / article | 2 |
| Announcement: CAISI signs CRADA with OpenMined to Enable Secure AI Evaluations National Institute of Standards and Technology | 2026 | A | Government document | 1 |
| Attestable homepage | 2026 | B | Documentation | 1 |
Auditing a Frontier Model Without Seeing its WeightsD. McCann-Sayles & T. Verma · Tinfoil blog | 2026 | C | Blog / article | 1 |
| Auditor-in-a-Box: Tools for Third-Party Auditing R. Rinberg & B. Penchas · LessWrong | 2026 | C | Blog / article | 3 |
| Backend infrastructure | 2026 | B | Documentation | 4 |
| Batch Invariance (vLLM documentation) vLLM project · vLLM documentation (GitHub, docs/features/batch_invariance.md) | 2026 | B | Documentation | 2 |
| Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing J. De Meulemeester et al. · 47th IEEE Symposium on Security and Privacy (S&P 2026) | 2026 | A | Peer-reviewed | 6 |
| Beyond Prompt Injection: Hacking Apple's Private Cloud Compute D. Selmanaj · Sentry blog | 2026 | C | Blog / article | 2 |
| Bit-Exact AI Inference Verification Without Performance Tradeoffs N. Cankaya · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 9 |
| Blueprint, Bootstrap, and Bridge: A Security Look at NVIDIA GPU Confidential Computing Z. Gu et al. · Proceedings of the 9th MLSys Conference (MLSys 2026) | 2026 | A | Peer-reviewed | 1 |
| Building an Adversarial Testbed for AI Verification in Europe | 2026 | C | Blog / article | 1 |
Building Delphi: Pricing, Settlement, and Agentic TradingD. Jedamski · Gensyn blog · Gensyn | 2026 | C | Blog / article | 3 |
| Can governments quickly and cheaply slow AI training? joshc · AI Alignment Forum | 2026 | C | Blog / article | 4 |
| Center for a New American Security: Mission | 2026 | B | Documentation | 1 |
| Components of a Frontier AI Slowdown A. Chan · A Strange Attractor | 2026 | C | Blog / article | — |
| Confidential computing can enable better frontier AI auditing A. Tlaie Boria · Pour Demain | 2026 | C | Blog / article | 2 |
| Confidential Space overview Google Cloud · Google Cloud documentation | 2026 | B | Documentation | 1 |
| Confidential Space release notes Google Cloud · Google Cloud documentation | 2026 | B | Documentation | 1 |
| Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance S. Ding et al. · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 1 |
| Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance (reference implementation) covehub · GitHub | 2026 | B | Code | 1 |
| Covert AI Projects | 2026 | C | Blog / article | 4 |
| CVE-2026-20685 (Apple Private Cloud Compute Server Software) Apple (CVE Numbering Authority) · CVE Program | 2026 | B | Documentation | 1 |
| DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes J. De Meulemeester et al. · 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26) | 2026 | A | Peer-reviewed | 4 |
De-risking Interconnect Limits for AI VerificationA. Scher et al. · MIRI Technical Governance Team | 2026 | C | Blog / article | 3 |
| DeepSeek-V4: Towards Highly Efficient Million-Token Context Intelligence DeepSeek-AI · arXiv | 2026 | B | Technical report | 1 |
| Deployment of OPCW expert team to Syrian Arab Republic finds chemical weapons previously undeclared to the Organisation Organisation for the Prohibition of Chemical Weapons · OPCW | 2026 | A | Government document | — |
| Detecting Compute Structuring in AI Governance Is Likely Feasible E. Seferis & T. Fist · Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment) | 2026 | A | Peer-reviewed | 2 |
| Detecting Hidden ML Training With Zero-Overhead Telemetry R. Rahman & S. Tajdari · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 6 |
| Does Distributed Training Undermine Compute Governance? R. Rahman · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 2 |
Double Blind Evals: Resolving the Dual Confidentiality Dilemma in AI Safety AuditingA. Trask et al. · Google DeepMind · OpenMined | 2026 | B | Technical report | 3 |
| EigenAI: Deterministic Inference, Verifiable Results D. Ribeiro Alves et al. · arXiv | 2026 | B | Preprint | 2 |
| Enabling Verifiably-Scoped Monitoring through Large Language Models and Trusted Compute B. Penchas et al. · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 3 |
| Example Schemes for Verifying High-Stakes AI Agreements | 2026 | C | Blog / article | 9 |
| Expanding Private Cloud Compute Apple Security Engineering and Architecture (SEAR) · Apple Security Research blog | 2026 | C | Blog / article | 2 |
| Experiments: Lucid Labs | 2026 | B | Documentation | 2 |
| Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP B. Schlüter et al. · 35th USENIX Security Symposium (USENIX Security '26) | 2026 | A | Peer-reviewed | 1 |
| Field Notes on International AI Verification from Shanghai, Seoul, and Sydney | 2026 | C | Blog / article | 1 |
| Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors | 2026 | B | Preprint | 6 |
| Fitting a Network TAP to our Inference Verification Prototype | 2026 | C | Blog / article | 3 |
| From Verifiability to Model-Weight Security | 2026 | C | Blog / article | 3 |
| Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies M. Brundage et al. · arXiv | 2026 | B | Preprint | 2 |
| Future of Life Institute: Global Institutions Governing AI | 2026 | B | Documentation | 1 |
| gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository) | 2026 | B | Code | 4 |
| Gensyn: machines that predict the future | 2026 | B | Documentation | 1 |
| Get Involved in Verification | 2026 | C | Blog / article | 8 |
| GPU Fingerprinting for Location Verification W. Tee & J. Happel · arXiv | 2026 | B | Preprint | 2 |
| Haiku to Opus in Just 10 bits: LLMs Unlock Large Compression Gains R. Rinberg et al. · arXiv | 2026 | B | Preprint | 4 |
| Hardware AI Governance Lab | 2026 | B | Documentation | 2 |
| Hardware Mechanisms to Dynamically Throttle AI Performance H. Ma et al. · arXiv | 2026 | B | Preprint | 1 |
| Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification S. Ansari · arXiv | 2026 | B | Preprint | 5 |
Hawkeye: Reproducing GPU-Level Non-DeterminismE. Badash et al. · Proceedings of Machine Learning and Systems 8 (MLSys 2026) · Pearl Research Labs | 2026 | A | Peer-reviewed | 4 |
Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security EngineeringS. F. Comer et al. · RAND Corporation (Research Report RR-A4827-1) | 2026 | B | Technical report | 4 |
| Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference C. Gong et al. · arXiv | 2026 | B | Preprint | 2 |
| How Tinfoil Proves Exactly What Model Is Running | 2026 | C | Blog / article | 6 |
| How verification works in Tinfoil | 2026 | B | Documentation | 5 |
| IAEA Safeguards Overview: Comprehensive Safeguards Agreements and Additional Protocols International Atomic Energy Agency · IAEA fact sheet | 2026 | A | Government document | — |
| Improving Disk Wiping Speed for Memory Wipes | 2026 | C | Blog / article | 2 |
| inference-verification: Inference Verification Prototype | 2026 | B | Code | 4 |
| Insecure Despite Proven Updated: Extracting the Root VCEK Seed on EPYC Milan via a Software-Only Attack M. Shen & Y. Qin · arXiv | 2026 | B | Preprint | 1 |
| Institute for AI Policy and Strategy homepage | 2026 | B | Documentation | 1 |
| Intelligence Security Laboratories: Building secure infrastructure for transformative AI | 2026 | B | Documentation | 2 |
| Internationalising AI Verification | 2026 | C | Blog / article | 5 |
Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and OptimizationC. Shrauder & G. Frederick · NVIDIA Technical Blog | 2026 | B | Blog / article | 3 |
| Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field P. Horvath et al. · IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026) | 2026 | A | Peer-reviewed | 1 |
| Lagrange-Labs/deep-prove (GitHub repository) Lagrange Labs · GitHub | 2026 | B | Code | 1 |
| LLM-42: Enabling Determinism in LLM Inference with Verified Speculation R. Gond et al. · arXiv | 2026 | B | Preprint | 1 |
| Lucid Computing: Verifiable AI. Proven in hardware. | 2026 | B | Documentation | 3 |
| Lucid Developer Platform documentation | 2026 | B | Documentation | 2 |
| Lucid Labs: the verification flywheel | 2026 | B | Documentation | 2 |
| Memory Wipes - Performance Analysis | 2026 | C | Blog / article | 3 |
| MilanLaunchy Firmware Loader (AMD-SB-3045) AMD · AMD product security bulletin | 2026 | B | Documentation | 1 |
| modelwrap: Reproducible dm-verity read-only image of Huggingface models | 2026 | B | Code | 4 |
| NanoZK: Privacy-Preserving Verifiable Inference for Large Language Models via Layerwise Zero-Knowledge Proofs Z. Wang · International Conference on Information and Communications Security (ICICS 2026) | 2026 | A | Peer-reviewed | 1 |
| Near-Term Verification Methods for AI Chip Exports | 2026 | B | Preprint | 5 |
| Network Tapping for AI Verification: A Technical Assessment | 2026 | C | Blog / article | 2 |
| Network Taps — A First Test | 2026 | C | Blog / article | 2 |
| Network Traffic Hashing | 2026 | C | Blog / article | 2 |
| NIST Computer Security Resource Center (CSRC) Glossary National Institute of Standards and Technology · NIST Computer Security Resource Center | 2026 | A | Government document | 8 |
| NVIDIA Trusted Computing Solutions Release Notes (R595 TRD1) | 2026 | B | Documentation | 1 |
| On restraining AI development for the sake of safety J. Carlsmith · Joseph Carlsmith | 2026 | C | Blog / article | — |
On TEEs for Privacy-Preserving Monitoring in AI GovernanceGloria Z · MIRI Technical Governance Team | 2026 | C | Blog / article | 12 |
| Our Team: Intelligence Security Laboratories | 2026 | B | Documentation | 2 |
| Pacing AI Requires Proof | 2026 | C | Blog / article | 9 |
| PAL*M: Property Attestation for Large Generative Models P. Chantasantitam et al. · arXiv | 2026 | B | Preprint | 7 |
| Pearl Floating Point Scheme Specification | 2026 | B | Technical report | 4 |
| Pearl INT Whitepaper | 2026 | B | Technical report | 3 |
| Pearl Research Labs homepage | 2026 | B | Documentation | 1 |
| pearl: Monorepo for the Pearl network | 2026 | B | Code | 3 |
| PHYSEC SEAL: Change detection for maximum safety PHYSEC GmbH · PHYSEC website | 2026 | B | Documentation | 1 |
| Planet Reports Financial Results for Second Quarter of Fiscal Year 2027 | 2026 | C | Blog / article | 1 |
| Prime Intellect homepage | 2026 | B | Documentation | 1 |
| Privacy-Preserving AI Verification via Minimal Information Disclosure S. Abdelghafar & G. Kulp · arXiv | 2026 | B | Preprint | 1 |
| Private Cloud Compute (Apple Developer) Apple · Apple Developer | 2026 | B | Documentation | 1 |
| Private Processing for WhatsApp: Technical White Paper and Security Guide Meta | 2026 | B | Documentation | 1 |
| Proof of Useful Work from the Ground Up | 2026 | C | Blog / article | 1 |
| Proof-of-Guardrail in AI Agents and What (Not) to Trust from It X. Jin et al. · arXiv | 2026 | B | Preprint | 2 |
| Proving LLMs at Scale | 2026 | C | Blog / article | 3 |
| PySyft used for first double-blind evaluation of a proprietary, frontier-class AI model | 2026 | C | Blog / article | 2 |
Reproducible Execution Environment (REE) (Gensyn documentation)Gensyn · Gensyn documentation · Gensyn | 2026 | B | Documentation | 2 |
Safety Without Compromising on PrivacyD. McCann-Sayles et al. · Tinfoil blog | 2026 | C | Blog / article | 2 |
| Scaling Recomputation Inference Verification | 2026 | C | Blog / article | 4 |
| SEV-SNP Routing Misconfiguration (AMD-SB-3034) AMD · AMD product security bulletin | 2026 | B | Documentation | 1 |
| Singapore AI Safety Hub: About | 2026 | B | Documentation | 1 |
| Sovereignty Certificates Working Group sovcert.org | 2026 | B | Documentation | 1 |
| StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack Engine R. Zhang et al. · 35th USENIX Security Symposium (USENIX Security '26) | 2026 | A | Peer-reviewed | 1 |
| Summary: TGT's 2026 ICML Papers | 2026 | C | Blog / article | 1 |
Suppressing Side Channels in an Untrusted Data Center via Retrofitted DefensesN. Cankaya · MIRI Technical Governance Team | 2026 | C | Blog / article | 7 |
| TAO: Tolerance-Aware Optimistic Verification for Floating-Point Neural Networks J. Yao et al. · Proceedings of the 21st European Conference on Computer Systems (EuroSys 2026), pp. 1515-1532 | 2026 | A | Peer-reviewed | 1 |
| TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition J. Chuang et al. · 2026 IEEE Symposium on Security and Privacy (SP) | 2026 | A | Peer-reviewed | 7 |
| The Comprehensive Nuclear-Test-Ban Treaty (CTBT) CTBTO Preparatory Commission · CTBTO | 2026 | A | Government document | — |
| The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use N. Cankaya · The Datacenter Lie Detector | 2026 | C | Blog / article | 6 |
| The International Monitoring System CTBTO Preparatory Commission · CTBTO | 2026 | A | Government document | — |
| The Tray as a Bandwidth Boundary | 2026 | C | Blog / article | 3 |
| The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol A. Basu · arXiv | 2026 | B | Preprint | 3 |
| Thinking Machines Lab | 2026 | B | Documentation | 1 |
| Timing and Memory Telemetry on GPUs for AI Governance S. K. Monfared et al. · arXiv | 2026 | B | Preprint | 4 |
| Tinfoil homepage | 2026 | B | Documentation | 1 |
| Tracking Hyperscale AI Data Center Growth with Satellite Imagery C. Krawec · Federation of American Scientists | 2026 | B | Technical report | 4 |
| Traffic Shaping for Workload Classification | 2026 | C | Blog / article | 3 |
| Understanding Data Center Power Delivery | 2026 | C | Blog / article | 2 |
| Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence Y. Dittmar et al. · Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '26) | 2026 | A | Peer-reviewed | 1 |
| Verifiable constraints on frontier training via proofs of compartmentalization D. Reuter et al. · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 1 |
| Verifiable Semiconductor Manufacturing | 2026 | B | Technical report | 1 |
| Verifiable-ClawGuard: proof-of-guardrail reference code SaharaLabsAI · GitHub | 2026 | B | Code | 1 |
| Verification Plan | 2026 | C | Blog / article | 15 |
| Verifying AI Compute by Bounding Unexplained Information Exfiltration J. Petrie & Y. Mühlhäuser · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 1 |
| Verifying international AI deals: Plan A, the state-of-play, and what you can do to help | 2026 | C | Blog / article | 3 |
| What we learned about TEE security from auditing WhatsApp's Private Inference Trail of Bits · Trail of Bits blog | 2026 | C | Blog / article | 2 |
| Workload Identification with Physical Side Channels for AI Governance S. Gargiulo & G. Kulp · arXiv | 2026 | B | Preprint | 1 |
| Zero knowledge verification for frontier AI training is possible P. Peigné et al. · arXiv | 2026 | B | Preprint | 4 |
| zkonduit/ezkl (GitHub repository) | 2026 | B | Code | 2 |
| [Feature]: Batch Invariant Feature and Performance Optimization (vLLM issue #27433) vLLM project contributors · GitHub (vllm-project/vllm issues) | 2025 | C | Forum / discussion | 3 |
| Activating AI Safety Level 3 Protections Anthropic | 2025 | C | Blog / article | 1 |
| adamkarvonen/difr (GitHub repository) A. Karvonen · GitHub | 2025 | B | Code | 2 |
| AI Security RFDs AI Security Forum | 2025 | C | Forum / discussion | — |
| An International Agreement to Prevent the Premature Creation of Artificial Superintelligence | 2025 | B | Technical report | 7 |
| Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection M. S. Tabar et al. · 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025) | 2025 | A | Peer-reviewed | 1 |
| Are You Getting What You Pay For? Auditing Model Substitution in LLM APIs W. Cai et al. · arXiv | 2025 | B | Preprint | 1 |
| Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments | 2025 | B | Preprint | 9 |
| BarraCUDA: Edge GPUs do Leak DNN Weights P. Horvath et al. · 34th USENIX Security Symposium | 2025 | A | Peer-reviewed | 2 |
Boost GPU Memory Performance with No Code Changes Using NVIDIA CUDA MPSS. Nassernia · NVIDIA Technical Blog | 2025 | B | Blog / article | 1 |
| California Senate Bill 53 (2025): Transparency in Frontier Artificial Intelligence Act California State Legislature · Statutes of 2025, Chapter 138 (Business and Professions Code §22757.10 et seq.) | 2025 | A | Government document | 2 |
| Confidential Inference via Trusted Virtual Machines Anthropic & Pattern Labs · Anthropic research | 2025 | C | Blog / article | 1 |
| Countering AI Chip Smuggling Has Become a National Security Priority | 2025 | B | Technical report | 3 |
| DeepProve-1: The First zkML System to Prove a Full LLM Inference Lagrange Labs · Lagrange blog | 2025 | C | Blog / article | 1 |
| Defeating Nondeterminism in LLM Inference | 2025 | C | Blog / article | 5 |
| Detecting Anomalies in Machine Learning Infrastructure via Hardware Telemetry Z. Chen et al. · arXiv | 2025 | B | Preprint | 1 |
| DiFR: Inference Verification Despite Nondeterminism A. Karvonen et al. · ICML 2026 Workshop on Technical AI Governance Research | 2025 | B | Preprint | 9 |
| EigenCloud Brings Verifiable AI to Mass Market with EigenAI and EigenCompute Launches EigenCloud · Eigen Labs blog | 2025 | C | Blog / article | 1 |
| Embedded Off-Switches for AI Compute J. Petrie · arXiv | 2025 | B | Preprint | 1 |
| Empirical Evaluation of Memory-Erasure Protocols R. Gil-Pons et al. · Proceedings of the 22nd International Conference on Security and Cryptography (SECRYPT 2025), pp. 209–220 | 2025 | A | Peer-reviewed | 1 |
| Executive Order 14148: Initial Rescissions of Harmful Executive Orders and Actions Executive Office of the President · Federal Register, 90 FR 8237 (document 2025-01901, published 2025-01-28) | 2025 | A | Government document | 3 |
| EZKL documentation (overview) | 2025 | B | Documentation | 1 |
| Faster AI Diffusion Through Hardware-Based Verification N. Ammann & D. Dalrymple · Institute for Progress | 2025 | C | Blog / article | — |
| Flexible Hardware-Enabled Guarantees for AI Compute J. Petrie et al. · arXiv | 2025 | B | Preprint | 7 |
| Guaranteeable Memory: An HBM-Based Chiplet for Verifiable AI Workloads J. Petrie · ICML 2025 Workshop on Technical AI Governance | 2025 | B | Preprint | 1 |
| GuardAIn: Protecting Emerging Generative AI Workloads on Heterogeneous NPU A. Dhar et al. · 2025 IEEE Symposium on Security and Privacy | 2025 | A | Peer-reviewed | 1 |
| Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act) European Commission · European Commission, Communication C(2025) 5045 final | 2025 | A | Government document | 2 |
| Hardware-Enabled Mechanisms for Verifying Responsible AI Development A. O'Gara et al. · arXiv | 2025 | B | Preprint | 5 |
| Has My System Prompt Been Used? Large Language Model Prompt Membership Inference R. Levin et al. · arXiv | 2025 | B | Preprint | 1 |
| INTELLECT-2: A Reasoning Model Trained Through Globally Decentralized Reinforcement Learning | 2025 | B | Technical report | 3 |
| International AI Safety Report Y. Bengio et al. · International AI Safety Report | 2025 | B | Technical report | — |
| International Security Applications of Flexible Hardware-Enabled Guarantees O. Aarne & J. Petrie · arXiv | 2025 | B | Preprint | 1 |
| Introducing Judge | 2025 | C | Blog / article | 2 |
| Introducing the Frontier Data Centers Hub | 2025 | C | Blog / article | 3 |
| JamesPetrie/off-switch (GitHub repository) J. Petrie · GitHub | 2025 | B | Code | 1 |
| Location Verification for AI Chips (issue brief) | 2025 | B | Technical report | 3 |
| Mechanisms to Verify International Agreements About AI Development | 2025 | B | Preprint | 18 |
| Meta WhatsApp Private Processing (security review) Trail of Bits · Trail of Bits publications library | 2025 | B | Documentation | 2 |
| Model Equality Testing: Which Model Is This API Serving? I. Gao et al. · International Conference on Learning Representations (ICLR 2025) | 2025 | A | Peer-reviewed | 1 |
| MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs R. Ding et al. · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS 2025) | 2025 | A | Peer-reviewed | — |
| No Backdoors. No Kill Switches. No Spyware. | 2025 | B | Blog / article | 2 |
| NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper) | 2025 | B | Documentation | 4 |
| Open Problems in Technical AI Governance A. Reuel et al. · Transactions on Machine Learning Research | 2025 | A | Peer-reviewed | 2 |
| Opt-In NVIDIA Software Enables Data Center Fleet Management | 2025 | B | Blog / article | 3 |
| Ping-based Location Ulyssean · Ulyssean demonstration site | 2025 | B | Documentation | 1 |
| PrimeIntellect-ai/toploc (GitHub repository) | 2025 | B | Code | 3 |
| Private AI Compute: our next step in building private and helpful AI J. Yagnik · Google blog (The Keyword) | 2025 | C | Blog / article | 1 |
| Proofs of Useful Work from Arbitrary Matrix Multiplication I. Komargodski & O. Weinstein · arXiv | 2025 | B | Preprint | 4 |
| RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP B. Schlüter & S. Shinde · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) | 2025 | A | Peer-reviewed | 6 |
| SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020) AMD · AMD product security bulletin | 2025 | B | Documentation | 5 |
| Shortcut-connected Expert Parallelism for Accelerating Mixture of Experts W. Cai et al. · ICML 2025, Proceedings of Machine Learning Research 267 | 2025 | A | Peer-reviewed | 5 |
| Single-Node Power Demand During AI Training: Measurements on an 8-GPU NVIDIA H100 System I. Latif et al. · IEEE Access, vol. 13, pp. 61740–61747 | 2025 | A | Peer-reviewed | 1 |
| Sovereignty Certificates: draft specification, version 0.1.0 | 2025 | B | Documentation | 4 |
| SYNTHETIC-2 | 2025 | C | Blog / article | 2 |
| SYNTHETIC-2 Release: Four Million Collaboratively Generated Reasoning Traces | 2025 | C | Blog / article | 3 |
| Technical Options for Flexible Hardware-Enabled Guarantees J. Petrie & O. Aarne · arXiv | 2025 | B | Preprint | 3 |
| thinking-machines-lab/batch_invariant_ops (GitHub repository) | 2025 | B | Code | 3 |
TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable InferenceJ. M. Ong et al. · Proceedings of the 42nd International Conference on Machine Learning (PMLR 267), pp. 47196-47211 · Prime Intellect | 2025 | A | Peer-reviewed | 3 |
| TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference (blog post) | 2025 | C | Blog / article | 2 |
| Towards Deterministic Inference in SGLang and Reproducible RL Training The SGLang Team · LMSYS Org blog | 2025 | C | Blog / article | 3 |
| TSMC most definitely has a golden record of all AI chips it made N. Cankaya · The Datacenter Lie Detector (Substack) | 2025 | C | Blog / article | 1 |
| U.S. Authorities Shut Down Major China-Linked AI Tech Smuggling Network U.S. Department of Justice · U.S. Department of Justice, Office of Public Affairs | 2025 | A | Government document | 2 |
Verde Verification System In ProductionO. Ersoy · Gensyn research blog · Gensyn | 2025 | C | Blog / article | 4 |
Verde: Verification via Refereed Delegation for Machine Learning ProgramsA. Arun et al. · arXiv · Gensyn | 2025 | B | Preprint | 6 |
| Verification for International AI Governance | 2025 | B | Technical report | 8 |
Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and DeploymentM. Baker et al. · RAND Corporation | 2025 | B | Technical report | 20 |
| Verifying LLM Inference to Detect Model Weight Exfiltration R. Rinberg et al. · arXiv | 2025 | B | Preprint | 9 |
| VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs G. Liao et al. · arXiv | 2025 | B | Preprint | 2 |
| WireTap: Breaking Server SGX via DRAM Bus Interposition A. Seto et al. · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) | 2025 | A | Peer-reviewed | 1 |
| zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM Inference W. Qu et al. · 34th USENIX Security Symposium (USENIX Security 25), pp. 2045–2063 | 2025 | A | Peer-reviewed | 1 |
Zkonduit EZKL Security AssessmentF. Casal et al. · Trail of Bits (prepared for Zkonduit Inc.) | 2025 | B | Technical report | 3 |
| Accurate and Convenient Energy Measurements for GPUs: A Detailed Study of NVIDIA GPU's Built-In Power Sensor Z. Yang et al. · SC24: International Conference for High Performance Computing, Networking, Storage and Analysis | 2024 | A | Peer-reviewed | 2 |
| BWC at 50: Taking Bold Steps to Secure the Future G. Essix · NTI | 2024 | C | Blog / article | — |
| Computing Power and the Governance of Artificial Intelligence | 2024 | B | Preprint | 12 |
| DeepTheft: Stealing DNN Model Architectures through Power Side Channel Y. Gao et al. · 2024 IEEE Symposium on Security and Privacy | 2024 | A | Peer-reviewed | 2 |
| DiLoCo: Distributed Low-Communication Training of Language Models A. Douillard et al. · ICML 2024 Workshop on Advancing Neural Network Training (WANT) | 2024 | B | Preprint | 2 |
| Foundational Challenges in Assuring Alignment and Safety of Large Language Models U. Anwar et al. · Transactions on Machine Learning Research | 2024 | A | Peer-reviewed | — |
| Governing Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation | 2024 | B | Technical report | 1 |
Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090G. Kulp et al. · RAND Corporation | 2024 | B | Technical report | 12 |
| Input-Dependent Power Usage in GPUs T. Gregersen et al. · SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis (Sustainable Supercomputing workshop), pp. 1872–1877 | 2024 | B | Preprint | 1 |
| Limitations of Satellite Imagery Analysis for AI-Specific Data Centers L. Heim & K. Pilz · Lennart Heim's blog | 2024 | C | Blog / article | 1 |
| Location Verification for AI Chips | 2024 | B | Technical report | 5 |
| Now in General Availability: NVIDIA H100 GPUs in Microsoft Azure Confidential Virtual Machines | 2024 | C | Blog / article | 1 |
| Optimistic Verifiable Training by Controlling Hardware Nondeterminism M. Srivastava et al. · Advances in Neural Information Processing Systems 37 (NeurIPS 2024) | 2024 | A | Peer-reviewed | 1 |
| Preventing model exfiltration with upload limits R. Greenblatt · AI Alignment Forum | 2024 | C | Forum / discussion | 1 |
| Private Cloud Compute: A new frontier for AI privacy in the cloud Apple Security Engineering and Architecture (SEAR) · Apple Security Research blog | 2024 | C | Blog / article | 3 |
| Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) European Parliament & Council of the European Union · Official Journal of the European Union, OJ L, 2024/1689 | 2024 | A | Government document | 2 |
| Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing | 2024 | B | Technical report | 7 |
Securing AI Model Weights: Preventing Theft and Misuse of Frontier ModelsS. Nevo et al. · RAND Corporation | 2024 | B | Technical report | 3 |
| Security research on Private Cloud Compute Apple Security Engineering and Architecture (SEAR) · Apple Security Research blog | 2024 | C | Blog / article | 1 |
| Software-Based Memory Erasure with Relaxed Isolation Requirements S. Bursuc et al. · 2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024) | 2024 | A | Peer-reviewed | 3 |
| Trustless Audits without Revealing Data or Models S. Waiwitlikhit et al. · 41st International Conference on Machine Learning (ICML 2024) | 2024 | A | Peer-reviewed | 3 |
| Verifiable evaluations of machine learning models using zkSNARKs | 2024 | B | Preprint | 3 |
| Verifiable Training of AI Models | 2024 | C | Blog / article | 1 |
| Verification methods for international AI agreements A. R. Wasil et al. · arXiv | 2024 | B | Preprint | 8 |
| Zero-Knowledge Proofs of Training for Deep Neural Networks K. Abbaszadeh et al. · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330 | 2024 | A | Peer-reviewed | 2 |
| zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models | 2024 | B | Code | 3 |
zkLLM: Zero Knowledge Proofs for Large Language ModelsH. Sun et al. · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024) · University of Waterloo | 2024 | A | Peer-reviewed | 8 |
| ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs B.-J. Chen et al. · 19th European Conference on Computer Systems (EuroSys 2024) | 2024 | A | Peer-reviewed | 1 |
| A Practical Introduction to Side-Channel Extraction of Deep Neural Network Parameters R. Joud et al. · 21st International Conference on Smart Card Research and Advanced Applications (CARDIS 2022), LNCS 13820, pp. 45–65 | 2023 | A | Peer-reviewed | — |
Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AIE. Apsey et al. · NVIDIA Technical Blog | 2023 | C | Blog / article | 2 |
| Exploration of secure hardware solutions for safe AI deployment | 2023 | C | Blog / article | 2 |
| ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection T. Mosavirik et al. · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325 | 2023 | A | Peer-reviewed | 1 |
| International Governance of Civilian AI: A Jurisdictional Certification Approach | 2023 | B | Technical report | 1 |
| Nuclear Arms Control Verification and Lessons for AI Treaties M. Baker · arXiv | 2023 | B | Preprint | — |
| OPCW confirms: All declared chemical weapons stockpiles verified as irreversibly destroyed Organisation for the Prohibition of Chemical Weapons · OPCW | 2023 | A | Government document | — |
| Proof-of-Learning is Currently More Broken Than You Think C. Fang et al. · 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023) | 2023 | A | Peer-reviewed | 3 |
| Remote ATtestation procedureS (RATS) Architecture (RFC 9334) H. Birkholz et al. · Internet Engineering Task Force (RATS Working Group) | 2023 | B | Technical report | 4 |
| SAGE: Software-based Attestation for GPU Execution A. Ivanov et al. · 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 485–499 | 2023 | A | Peer-reviewed | 1 |
| Tools for Verifying Neural Models' Training Data D. Choi et al. · Advances in Neural Information Processing Systems 36 (NeurIPS 2023) | 2023 | A | Peer-reviewed | 2 |
| What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring Y. Shavit · arXiv | 2023 | B | Preprint | 20 |
| "Adversarial Examples" for Proof-of-Learning R. Zhang et al. · 2022 IEEE Symposium on Security and Privacy (SP), pp. 1408-1422 | 2022 | A | Peer-reviewed | 1 |
| Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems P. Staat et al. · 2022 IEEE Symposium on Security and Privacy | 2022 | A | Peer-reviewed | 1 |
| Common Terminology for Confidential Computing Confidential Computing Consortium | 2022 | B | Technical report | 2 |
| ZKProof Community Reference D. Benarroch et al. · ZKProof | 2022 | B | Technical report | 4 |
| Proof-of-Learning: code for Proof-of-Learning: Definitions and Practice CleverHans Lab · GitHub | 2021 | B | Code | 1 |
| Proof-of-Learning: Definitions and Practice H. Jia et al. · 2021 IEEE Symposium on Security and Privacy (SP), pp. 1039-1056 | 2021 | A | Peer-reviewed | 1 |
| Detecting Covert Cryptomining Using HPC A. Gangwal et al. · Cryptology and Network Security – CANS 2020, LNCS 12579, pp. 344–364 | 2020 | A | Peer-reviewed | 1 |
| Secure Physical Enclosures from Covers with Tamper-Resistance V. Immler et al. · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96 | 2019 | A | Peer-reviewed | 1 |
| Platform Firmware Resiliency Guidelines (NIST SP 800-193) A. Regenscheid · National Institute of Standards and Technology | 2018 | A | Government document | 1 |
| The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond J. Obermaier & V. Immler · Journal of Hardware and Systems Security | 2018 | A | Peer-reviewed | 1 |
| Proofs of Useful Work M. Ball et al. · IACR Cryptology ePrint Archive 2017/203 | 2017 | B | Preprint | 2 |
| TCG Glossary Trusted Computing Group | 2017 | B | Documentation | 2 |
| Proofs of Space S. Dziembowski et al. · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796) | 2015 | A | Peer-reviewed | 5 |
| Tamper-Indicating Enclosures, A Current Survey H. A. Smartt & Z. N. Gastelum · Sandia National Laboratories, SAND2015-4251C | 2015 | B | Technical report | 1 |
| A zero-knowledge protocol for nuclear warhead verification A. Glaser et al. · Nature 510, 497–502 | 2014 | A | Peer-reviewed | — |
| IBM 4765 Cryptographic Coprocessor Security Module: Security Policy IBM Corporation · NIST Cryptographic Module Validation Program | 2012 | B | Technical report | 1 |
| Cryptographic Module Validation Program Certificate #1505: IBM 4765 Cryptographic Coprocessor Security Module National Institute of Standards and Technology · NIST Cryptographic Module Validation Program | 2011 | A | Government document | 1 |
| Secure Code Update for Embedded Devices via Proofs of Secure Erasure D. Perito & G. Tsudik · Computer Security – ESORICS 2010, LNCS 6345, pp. 643–662 | 2010 | A | Peer-reviewed | 2 |
| On the Difficulty of Software-Based Attestation of Embedded Devices C. Castelluccia et al. · Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), pp. 400–409 | 2009 | A | Peer-reviewed | 1 |
| SWATT: SoftWare-based ATTestation for Embedded Devices A. Seshadri et al. · IEEE Symposium on Security and Privacy 2004, pp. 272–282 | 2004 | A | Peer-reviewed | 1 |
| Guidelines for Writing RFC Text on Security Considerations (RFC 3552, BCP 72) E. Rescorla et al. · Internet Engineering Task Force | 2003 | A | Standard | 1 |
| The Biological Weapons Convention Nuclear Threat Initiative · NTI | 2003 | B | Technical report | — |
| Security Requirements for Cryptographic Modules (FIPS PUB 140-2) National Institute of Standards and Technology | 2001 | A | Standard | 1 |
| Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials R. G. Johnston · The Nonproliferation Review, Spring 2001, pp. 102–114 | 2001 | A | Peer-reviewed | 1 |
| Physical Security and Tamper-Indicating Devices R. G. Johnston & A. R. E. Garcia · Los Alamos National Laboratory, LA-UR-96-3827 | 1996 | B | Technical report | 2 |
| Remarks on Signing the Intermediate-Range Nuclear Forces Treaty R. Reagan · Ronald Reagan Presidential Library and Museum | 1987 | A | Government document | — |
| Treaty between the United States of America and the Union of Soviet Socialist Republics on the Limitation of Anti-Ballistic Missile Systems United States of America & Union of Soviet Socialist Republics · United Nations Treaty Series, vol. 944, No. 13446 | 1972 | A | Government document | — |