Bibliography

Sources

The bibliography: 287 public sources, 267 of them cited by at least one record. Tier A is peer-reviewed work, standards and government publications; tier B is preprints, reports, documentation and code; tier C is expert blogs and talks. See the citation policy.

Seeded from Will Hodgkins' AI Workload Verification Papers bibliography (CC BY 4.0), which builds on earlier reading lists by Mauricio Baker and James Petrie.

TitleYearTierTypeCited by
A primer on secure enclaves
Tinfoil · Tinfoil documentation
2026BDocumentation5
A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning
Z. Peng et al. · Artificial Intelligence Review, vol. 59, no. 7, article 157
2026APeer-reviewed2
A System Overview for Near-Term, Low-Trust AI Compute Verification2026BTechnical report38
About Epoch AI2026BDocumentation1
About MIRI2026BDocumentation1
About NVIDIA2026BDocumentation1
About RAND2026BDocumentation1
About us: Centre for the Governance of AI (GovAI)2026BDocumentation1
About: Oxford Martin AIGI2026BDocumentation1
Adversarial Entropy Inflation Against Gumbel-Based Inference Verification
N. Kezins · arXiv
2026BPreprint7
AI 2040 Plan A — Verification SITREP2026CBlog / article7
AI Data Centers Documentation – Methodology2026BDocumentation2
AI Futures Project homepage2026BDocumentation1
AI Verification: Infrastructure for Prosperity, Governance, and Peace
B. Harack · Lawfare
2026CBlog / article—
Amodo Design: About Us2026BDocumentation1
Amodo-Design/Inference-Recomputation-Prototype (GitHub repository)
Amodo Design · GitHub
2026BCode4
Amodo-Design/PoSE-Memory-Wiping (GitHub repository)
Amodo Design · GitHub
2026BCode2
An Inference Verification Prototype — Stage 12026CBlog / article2
Announcement: CAISI signs CRADA with OpenMined to Enable Secure AI Evaluations
National Institute of Standards and Technology
2026AGovernment document1
Attestable homepage2026BDocumentation1
Auditing a Frontier Model Without Seeing its Weights
D. McCann-Sayles & T. Verma · Tinfoil blog
2026CBlog / article1
Auditor-in-a-Box: Tools for Third-Party Auditing
R. Rinberg & B. Penchas · LessWrong
2026CBlog / article3
Backend infrastructure
Tinfoil · Tinfoil documentation
2026BDocumentation4
Batch Invariance (vLLM documentation)
vLLM project · vLLM documentation (GitHub, docs/features/batch_invariance.md)
2026BDocumentation2
Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing
J. De Meulemeester et al. · 47th IEEE Symposium on Security and Privacy (S&P 2026)
2026APeer-reviewed6
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
D. Selmanaj · Sentry blog
2026CBlog / article2
Bit-Exact AI Inference Verification Without Performance Tradeoffs
N. Cankaya · ICML 2026 Workshop on Technical AI Governance Research
2026BPreprint9
Blueprint, Bootstrap, and Bridge: A Security Look at NVIDIA GPU Confidential Computing
Z. Gu et al. · Proceedings of the 9th MLSys Conference (MLSys 2026)
2026APeer-reviewed1
Building an Adversarial Testbed for AI Verification in Europe
Lucid Computing · Lucid Computing (Substack)
2026CBlog / article1
Building Delphi: Pricing, Settlement, and Agentic Trading
D. Jedamski · Gensyn blog · Gensyn
2026CBlog / article3
Can governments quickly and cheaply slow AI training?
joshc · AI Alignment Forum
2026CBlog / article4
Center for a New American Security: Mission2026BDocumentation1
Components of a Frontier AI Slowdown
A. Chan · A Strange Attractor
2026CBlog / article—
Confidential computing can enable better frontier AI auditing
A. Tlaie Boria · Pour Demain
2026CBlog / article2
Confidential Space overview
Google Cloud · Google Cloud documentation
2026BDocumentation1
Confidential Space release notes
Google Cloud · Google Cloud documentation
2026BDocumentation1
Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance
S. Ding et al. · ICML 2026 Workshop on Technical AI Governance Research
2026BPreprint1
Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance (reference implementation)
covehub · GitHub
2026BCode1
Covert AI Projects
B. Halstead & T. Larsen · AI 2040 · AI Futures Project
2026CBlog / article4
CVE-2026-20685 (Apple Private Cloud Compute Server Software)
Apple (CVE Numbering Authority) · CVE Program
2026BDocumentation1
DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes
J. De Meulemeester et al. · 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26)
2026APeer-reviewed4
De-risking Interconnect Limits for AI Verification
A. Scher et al. · MIRI Technical Governance Team
2026CBlog / article3
DeepSeek-V4: Towards Highly Efficient Million-Token Context Intelligence
DeepSeek-AI · arXiv
2026BTechnical report1
Deployment of OPCW expert team to Syrian Arab Republic finds chemical weapons previously undeclared to the Organisation
Organisation for the Prohibition of Chemical Weapons · OPCW
2026AGovernment document—
Detecting Compute Structuring in AI Governance Is Likely Feasible
E. Seferis & T. Fist · Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment)
2026APeer-reviewed2
Detecting Hidden ML Training With Zero-Overhead Telemetry
R. Rahman & S. Tajdari · ICML 2026 Workshop on Technical AI Governance Research
2026BPreprint6
Does Distributed Training Undermine Compute Governance?
R. Rahman · ICML 2026 Workshop on Technical AI Governance Research
2026BPreprint2
Double Blind Evals: Resolving the Dual Confidentiality Dilemma in AI Safety Auditing
A. Trask et al. · Google DeepMind · OpenMined
2026BTechnical report3
EigenAI: Deterministic Inference, Verifiable Results
D. Ribeiro Alves et al. · arXiv
2026BPreprint2
Enabling Verifiably-Scoped Monitoring through Large Language Models and Trusted Compute
B. Penchas et al. · ICML 2026 Workshop on Technical AI Governance Research
2026BPreprint3
Example Schemes for Verifying High-Stakes AI Agreements2026CBlog / article9
Expanding Private Cloud Compute
Apple Security Engineering and Architecture (SEAR) · Apple Security Research blog
2026CBlog / article2
Experiments: Lucid Labs2026BDocumentation2
Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
B. Schlüter et al. · 35th USENIX Security Symposium (USENIX Security '26)
2026APeer-reviewed1
Field Notes on International AI Verification from Shanghai, Seoul, and Sydney2026CBlog / article1
Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors
N. Cankaya et al. · arXiv · Hardware AI Governance Lab
2026BPreprint6
Fitting a Network TAP to our Inference Verification Prototype2026CBlog / article3
From Verifiability to Model-Weight Security
Attestable · Attestable blog
2026CBlog / article3
Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies
M. Brundage et al. · arXiv
2026BPreprint2
Future of Life Institute: Global Institutions Governing AI2026BDocumentation1
gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository)
Gensyn · GitHub · Gensyn
2026BCode4
Gensyn: machines that predict the future
Gensyn · Gensyn
2026BDocumentation1
Get Involved in Verification2026CBlog / article8
GPU Fingerprinting for Location Verification
W. Tee & J. Happel · arXiv
2026BPreprint2
Haiku to Opus in Just 10 bits: LLMs Unlock Large Compression Gains
R. Rinberg et al. · arXiv
2026BPreprint4
Hardware AI Governance Lab2026BDocumentation2
Hardware Mechanisms to Dynamically Throttle AI Performance
H. Ma et al. · arXiv
2026BPreprint1
Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification
S. Ansari · arXiv
2026BPreprint5
Hawkeye: Reproducing GPU-Level Non-Determinism
E. Badash et al. · Proceedings of Machine Learning and Systems 8 (MLSys 2026) · Pearl Research Labs
2026APeer-reviewed4
Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering
S. F. Comer et al. · RAND Corporation (Research Report RR-A4827-1)
2026BTechnical report4
Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference
C. Gong et al. · arXiv
2026BPreprint2
How Tinfoil Proves Exactly What Model Is Running
Tinfoil Team · Tinfoil
2026CBlog / article6
How verification works in Tinfoil
Tinfoil · Tinfoil documentation
2026BDocumentation5
IAEA Safeguards Overview: Comprehensive Safeguards Agreements and Additional Protocols
International Atomic Energy Agency · IAEA fact sheet
2026AGovernment document—
Improving Disk Wiping Speed for Memory Wipes2026CBlog / article2
inference-verification: Inference Verification Prototype2026BCode4
Insecure Despite Proven Updated: Extracting the Root VCEK Seed on EPYC Milan via a Software-Only Attack
M. Shen & Y. Qin · arXiv
2026BPreprint1
Institute for AI Policy and Strategy homepage2026BDocumentation1
Intelligence Security Laboratories: Building secure infrastructure for transformative AI2026BDocumentation2
Internationalising AI Verification2026CBlog / article5
Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization
C. Shrauder & G. Frederick · NVIDIA Technical Blog
2026BBlog / article3
Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field
P. Horvath et al. · IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026)
2026APeer-reviewed1
Lagrange-Labs/deep-prove (GitHub repository)
Lagrange Labs · GitHub
2026BCode1
LLM-42: Enabling Determinism in LLM Inference with Verified Speculation
R. Gond et al. · arXiv
2026BPreprint1
Lucid Computing: Verifiable AI. Proven in hardware.2026BDocumentation3
Lucid Developer Platform documentation2026BDocumentation2
Lucid Labs: the verification flywheel2026BDocumentation2
Memory Wipes - Performance Analysis2026CBlog / article3
MilanLaunchy Firmware Loader (AMD-SB-3045)
AMD · AMD product security bulletin
2026BDocumentation1
modelwrap: Reproducible dm-verity read-only image of Huggingface models
Tinfoil · GitHub
2026BCode4
NanoZK: Privacy-Preserving Verifiable Inference for Large Language Models via Layerwise Zero-Knowledge Proofs
Z. Wang · International Conference on Information and Communications Security (ICICS 2026)
2026APeer-reviewed1
Near-Term Verification Methods for AI Chip Exports
B. Avellar & E. Grunewald · arXiv · Institute for AI Policy and Strategy
2026BPreprint5
Network Tapping for AI Verification: A Technical Assessment2026CBlog / article2
Network Taps — A First Test2026CBlog / article2
Network Traffic Hashing2026CBlog / article2
NIST Computer Security Resource Center (CSRC) Glossary
National Institute of Standards and Technology · NIST Computer Security Resource Center
2026AGovernment document8
NVIDIA Trusted Computing Solutions Release Notes (R595 TRD1)
NVIDIA · NVIDIA documentation
2026BDocumentation1
On restraining AI development for the sake of safety
J. Carlsmith · Joseph Carlsmith
2026CBlog / article—
On TEEs for Privacy-Preserving Monitoring in AI Governance
Gloria Z · MIRI Technical Governance Team
2026CBlog / article12
Our Team: Intelligence Security Laboratories2026BDocumentation2
Pacing AI Requires Proof
Attestable · Attestable blog
2026CBlog / article9
PAL*M: Property Attestation for Large Generative Models
P. Chantasantitam et al. · arXiv
2026BPreprint7
Pearl Floating Point Scheme Specification
Pearl Research Team · Pearl Research Labs
2026BTechnical report4
Pearl INT Whitepaper2026BTechnical report3
Pearl Research Labs homepage2026BDocumentation1
pearl: Monorepo for the Pearl network2026BCode3
PHYSEC SEAL: Change detection for maximum safety
PHYSEC GmbH · PHYSEC website
2026BDocumentation1
Planet Reports Financial Results for Second Quarter of Fiscal Year 2027
Planet Labs PBC · Business Wire (press release)
2026CBlog / article1
Prime Intellect homepage2026BDocumentation1
Privacy-Preserving AI Verification via Minimal Information Disclosure
S. Abdelghafar & G. Kulp · arXiv
2026BPreprint1
Private Cloud Compute (Apple Developer)
Apple · Apple Developer
2026BDocumentation1
Private Processing for WhatsApp: Technical White Paper and Security Guide
Meta
2026BDocumentation1
Proof of Useful Work from the Ground Up2026CBlog / article1
Proof-of-Guardrail in AI Agents and What (Not) to Trust from It
X. Jin et al. · arXiv
2026BPreprint2
Proving LLMs at Scale
Attestable · Attestable blog
2026CBlog / article3
PySyft used for first double-blind evaluation of a proprietary, frontier-class AI model
OpenMined Team · OpenMined
2026CBlog / article2
Reproducible Execution Environment (REE) (Gensyn documentation)
Gensyn · Gensyn documentation · Gensyn
2026BDocumentation2
Safety Without Compromising on Privacy
D. McCann-Sayles et al. · Tinfoil blog
2026CBlog / article2
Scaling Recomputation Inference Verification2026CBlog / article4
SEV-SNP Routing Misconfiguration (AMD-SB-3034)
AMD · AMD product security bulletin
2026BDocumentation1
Singapore AI Safety Hub: About2026BDocumentation1
Sovereignty Certificates Working Group
sovcert.org
2026BDocumentation1
StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack Engine
R. Zhang et al. · 35th USENIX Security Symposium (USENIX Security '26)
2026APeer-reviewed1
Summary: TGT's 2026 ICML Papers2026CBlog / article1
Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses
N. Cankaya · MIRI Technical Governance Team
2026CBlog / article7
TAO: Tolerance-Aware Optimistic Verification for Floating-Point Neural Networks
J. Yao et al. · Proceedings of the 21st European Conference on Computer Systems (EuroSys 2026), pp. 1515-1532
2026APeer-reviewed1
TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
J. Chuang et al. · 2026 IEEE Symposium on Security and Privacy (SP)
2026APeer-reviewed7
The Comprehensive Nuclear-Test-Ban Treaty (CTBT)
CTBTO Preparatory Commission · CTBTO
2026AGovernment document—
The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use
N. Cankaya · The Datacenter Lie Detector
2026CBlog / article6
The International Monitoring System
CTBTO Preparatory Commission · CTBTO
2026AGovernment document—
The Tray as a Bandwidth Boundary2026CBlog / article3
The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol
A. Basu · arXiv
2026BPreprint3
Thinking Machines Lab2026BDocumentation1
Timing and Memory Telemetry on GPUs for AI Governance
S. K. Monfared et al. · arXiv
2026BPreprint4
Tinfoil homepage2026BDocumentation1
Tracking Hyperscale AI Data Center Growth with Satellite Imagery
C. Krawec · Federation of American Scientists
2026BTechnical report4
Traffic Shaping for Workload Classification
Lucid Computing · Lucid Computing (Substack)
2026CBlog / article3
Understanding Data Center Power Delivery2026CBlog / article2
Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence
Y. Dittmar et al. · Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '26)
2026APeer-reviewed1
Verifiable constraints on frontier training via proofs of compartmentalization
D. Reuter et al. · ICML 2026 Workshop on Technical AI Governance Research
2026BPreprint1
Verifiable Semiconductor Manufacturing2026BTechnical report1
Verifiable-ClawGuard: proof-of-guardrail reference code
SaharaLabsAI · GitHub
2026BCode1
Verification Plan
R. Dean · AI 2040 · AI Futures Project
2026CBlog / article15
Verifying AI Compute by Bounding Unexplained Information Exfiltration
J. Petrie & Y. Mühlhäuser · ICML 2026 Workshop on Technical AI Governance Research
2026BPreprint1
Verifying international AI deals: Plan A, the state-of-play, and what you can do to help
T. Milton et al. · Amodo (Substack) · Amodo Design
2026CBlog / article3
What we learned about TEE security from auditing WhatsApp's Private Inference
Trail of Bits · Trail of Bits blog
2026CBlog / article2
Workload Identification with Physical Side Channels for AI Governance
S. Gargiulo & G. Kulp · arXiv
2026BPreprint1
Zero knowledge verification for frontier AI training is possible
P. Peigné et al. · arXiv
2026BPreprint4
zkonduit/ezkl (GitHub repository)
Zkonduit Inc. · GitHub
2026BCode2
[Feature]: Batch Invariant Feature and Performance Optimization (vLLM issue #27433)
vLLM project contributors · GitHub (vllm-project/vllm issues)
2025CForum / discussion3
Activating AI Safety Level 3 Protections
Anthropic
2025CBlog / article1
adamkarvonen/difr (GitHub repository)
A. Karvonen · GitHub
2025BCode2
AI Security RFDs
AI Security Forum
2025CForum / discussion—
An International Agreement to Prevent the Premature Creation of Artificial Superintelligence2025BTechnical report7
Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection
M. S. Tabar et al. · 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025)
2025APeer-reviewed1
Are You Getting What You Pay For? Auditing Model Substitution in LLM APIs
W. Cai et al. · arXiv
2025BPreprint1
Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments
C. Schnabl et al. · ICML 2025 Workshop on Technical AI Governance · University of Cambridge
2025BPreprint9
BarraCUDA: Edge GPUs do Leak DNN Weights
P. Horvath et al. · 34th USENIX Security Symposium
2025APeer-reviewed2
Boost GPU Memory Performance with No Code Changes Using NVIDIA CUDA MPS
S. Nassernia · NVIDIA Technical Blog
2025BBlog / article1
California Senate Bill 53 (2025): Transparency in Frontier Artificial Intelligence Act
California State Legislature · Statutes of 2025, Chapter 138 (Business and Professions Code §22757.10 et seq.)
2025AGovernment document2
Confidential Inference via Trusted Virtual Machines
Anthropic & Pattern Labs · Anthropic research
2025CBlog / article1
Countering AI Chip Smuggling Has Become a National Security Priority2025BTechnical report3
DeepProve-1: The First zkML System to Prove a Full LLM Inference
Lagrange Labs · Lagrange blog
2025CBlog / article1
Defeating Nondeterminism in LLM Inference
H. He & Thinking Machines Lab · Thinking Machines Lab: Connectionism
2025CBlog / article5
Detecting Anomalies in Machine Learning Infrastructure via Hardware Telemetry
Z. Chen et al. · arXiv
2025BPreprint1
DiFR: Inference Verification Despite Nondeterminism
A. Karvonen et al. · ICML 2026 Workshop on Technical AI Governance Research
2025BPreprint9
EigenCloud Brings Verifiable AI to Mass Market with EigenAI and EigenCompute Launches
EigenCloud · Eigen Labs blog
2025CBlog / article1
Embedded Off-Switches for AI Compute
J. Petrie · arXiv
2025BPreprint1
Empirical Evaluation of Memory-Erasure Protocols
R. Gil-Pons et al. · Proceedings of the 22nd International Conference on Security and Cryptography (SECRYPT 2025), pp. 209–220
2025APeer-reviewed1
Executive Order 14148: Initial Rescissions of Harmful Executive Orders and Actions
Executive Office of the President · Federal Register, 90 FR 8237 (document 2025-01901, published 2025-01-28)
2025AGovernment document3
EZKL documentation (overview)
Zkonduit Inc. · EZKL documentation
2025BDocumentation1
Faster AI Diffusion Through Hardware-Based Verification
N. Ammann & D. Dalrymple · Institute for Progress
2025CBlog / article—
Flexible Hardware-Enabled Guarantees for AI Compute
J. Petrie et al. · arXiv
2025BPreprint7
Guaranteeable Memory: An HBM-Based Chiplet for Verifiable AI Workloads
J. Petrie · ICML 2025 Workshop on Technical AI Governance
2025BPreprint1
GuardAIn: Protecting Emerging Generative AI Workloads on Heterogeneous NPU
A. Dhar et al. · 2025 IEEE Symposium on Security and Privacy
2025APeer-reviewed1
Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act)
European Commission · European Commission, Communication C(2025) 5045 final
2025AGovernment document2
Hardware-Enabled Mechanisms for Verifying Responsible AI Development
A. O'Gara et al. · arXiv
2025BPreprint5
Has My System Prompt Been Used? Large Language Model Prompt Membership Inference
R. Levin et al. · arXiv
2025BPreprint1
INTELLECT-2: A Reasoning Model Trained Through Globally Decentralized Reinforcement Learning
Prime Intellect Team et al. · arXiv
2025BTechnical report3
International AI Safety Report
Y. Bengio et al. · International AI Safety Report
2025BTechnical report—
International Security Applications of Flexible Hardware-Enabled Guarantees
O. Aarne & J. Petrie · arXiv
2025BPreprint1
Introducing Judge
Gensyn · Gensyn news · Gensyn
2025CBlog / article2
Introducing the Frontier Data Centers Hub2025CBlog / article3
JamesPetrie/off-switch (GitHub repository)
J. Petrie · GitHub
2025BCode1
Location Verification for AI Chips (issue brief)2025BTechnical report3
Mechanisms to Verify International Agreements About AI Development
A. Scher & L. Thiergart · arXiv · Machine Intelligence Research Institute
2025BPreprint18
Meta WhatsApp Private Processing (security review)
Trail of Bits · Trail of Bits publications library
2025BDocumentation2
Model Equality Testing: Which Model Is This API Serving?
I. Gao et al. · International Conference on Learning Representations (ICLR 2025)
2025APeer-reviewed1
MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs
R. Ding et al. · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS 2025)
2025APeer-reviewed—
No Backdoors. No Kill Switches. No Spyware.
D. Reber Jr. · NVIDIA Blog
2025BBlog / article2
NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper)
NVIDIA · NVIDIA documentation
2025BDocumentation4
Open Problems in Technical AI Governance
A. Reuel et al. · Transactions on Machine Learning Research
2025APeer-reviewed2
Opt-In NVIDIA Software Enables Data Center Fleet Management
NVIDIA · NVIDIA Blog
2025BBlog / article3
Ping-based Location
Ulyssean · Ulyssean demonstration site
2025BDocumentation1
PrimeIntellect-ai/toploc (GitHub repository)
Prime Intellect · GitHub
2025BCode3
Private AI Compute: our next step in building private and helpful AI
J. Yagnik · Google blog (The Keyword)
2025CBlog / article1
Proofs of Useful Work from Arbitrary Matrix Multiplication
I. Komargodski & O. Weinstein · arXiv
2025BPreprint4
RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP
B. Schlüter & S. Shinde · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)
2025APeer-reviewed6
SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020)
AMD · AMD product security bulletin
2025BDocumentation5
Shortcut-connected Expert Parallelism for Accelerating Mixture of Experts
W. Cai et al. · ICML 2025, Proceedings of Machine Learning Research 267
2025APeer-reviewed5
Single-Node Power Demand During AI Training: Measurements on an 8-GPU NVIDIA H100 System
I. Latif et al. · IEEE Access, vol. 13, pp. 61740–61747
2025APeer-reviewed1
Sovereignty Certificates: draft specification, version 0.1.0
Sovereignty Certificates Working Group · GitHub (Lucid-Computing/sovereignty-certificate-specification) · Lucid Computing
2025BDocumentation4
SYNTHETIC-2
Prime Intellect · Prime Intellect blog
2025CBlog / article2
SYNTHETIC-2 Release: Four Million Collaboratively Generated Reasoning Traces
Prime Intellect · Prime Intellect blog
2025CBlog / article3
Technical Options for Flexible Hardware-Enabled Guarantees
J. Petrie & O. Aarne · arXiv
2025BPreprint3
thinking-machines-lab/batch_invariant_ops (GitHub repository)2025BCode3
TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference
J. M. Ong et al. · Proceedings of the 42nd International Conference on Machine Learning (PMLR 267), pp. 47196-47211 · Prime Intellect
2025APeer-reviewed3
TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference (blog post)
Prime Intellect · Prime Intellect blog
2025CBlog / article2
Towards Deterministic Inference in SGLang and Reproducible RL Training
The SGLang Team · LMSYS Org blog
2025CBlog / article3
TSMC most definitely has a golden record of all AI chips it made
N. Cankaya · The Datacenter Lie Detector (Substack)
2025CBlog / article1
U.S. Authorities Shut Down Major China-Linked AI Tech Smuggling Network
U.S. Department of Justice · U.S. Department of Justice, Office of Public Affairs
2025AGovernment document2
Verde Verification System In Production
O. Ersoy · Gensyn research blog · Gensyn
2025CBlog / article4
Verde: Verification via Refereed Delegation for Machine Learning Programs
A. Arun et al. · arXiv · Gensyn
2025BPreprint6
Verification for International AI Governance2025BTechnical report8
Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment
M. Baker et al. · RAND Corporation
2025BTechnical report20
Verifying LLM Inference to Detect Model Weight Exfiltration
R. Rinberg et al. · arXiv
2025BPreprint9
VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs
G. Liao et al. · arXiv
2025BPreprint2
WireTap: Breaking Server SGX via DRAM Bus Interposition
A. Seto et al. · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)
2025APeer-reviewed1
zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM Inference
W. Qu et al. · 34th USENIX Security Symposium (USENIX Security 25), pp. 2045–2063
2025APeer-reviewed1
Zkonduit EZKL Security Assessment
F. Casal et al. · Trail of Bits (prepared for Zkonduit Inc.)
2025BTechnical report3
Accurate and Convenient Energy Measurements for GPUs: A Detailed Study of NVIDIA GPU's Built-In Power Sensor
Z. Yang et al. · SC24: International Conference for High Performance Computing, Networking, Storage and Analysis
2024APeer-reviewed2
BWC at 50: Taking Bold Steps to Secure the Future
G. Essix · NTI
2024CBlog / article—
Computing Power and the Governance of Artificial Intelligence2024BPreprint12
DeepTheft: Stealing DNN Model Architectures through Power Side Channel
Y. Gao et al. · 2024 IEEE Symposium on Security and Privacy
2024APeer-reviewed2
DiLoCo: Distributed Low-Communication Training of Language Models
A. Douillard et al. · ICML 2024 Workshop on Advancing Neural Network Training (WANT)
2024BPreprint2
Foundational Challenges in Assuring Alignment and Safety of Large Language Models
U. Anwar et al. · Transactions on Machine Learning Research
2024APeer-reviewed—
Governing Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation2024BTechnical report1
Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090
G. Kulp et al. · RAND Corporation
2024BTechnical report12
Input-Dependent Power Usage in GPUs
T. Gregersen et al. · SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis (Sustainable Supercomputing workshop), pp. 1872–1877
2024BPreprint1
Limitations of Satellite Imagery Analysis for AI-Specific Data Centers
L. Heim & K. Pilz · Lennart Heim's blog
2024CBlog / article1
Location Verification for AI Chips2024BTechnical report5
Now in General Availability: NVIDIA H100 GPUs in Microsoft Azure Confidential Virtual Machines
C. Su · NVIDIA Blog
2024CBlog / article1
Optimistic Verifiable Training by Controlling Hardware Nondeterminism
M. Srivastava et al. · Advances in Neural Information Processing Systems 37 (NeurIPS 2024)
2024APeer-reviewed1
Preventing model exfiltration with upload limits
R. Greenblatt · AI Alignment Forum
2024CForum / discussion1
Private Cloud Compute: A new frontier for AI privacy in the cloud
Apple Security Engineering and Architecture (SEAR) · Apple Security Research blog
2024CBlog / article3
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
European Parliament & Council of the European Union · Official Journal of the European Union, OJ L, 2024/1689
2024AGovernment document2
Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing2024BTechnical report7
Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models
S. Nevo et al. · RAND Corporation
2024BTechnical report3
Security research on Private Cloud Compute
Apple Security Engineering and Architecture (SEAR) · Apple Security Research blog
2024CBlog / article1
Software-Based Memory Erasure with Relaxed Isolation Requirements
S. Bursuc et al. · 2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024)
2024APeer-reviewed3
Trustless Audits without Revealing Data or Models
S. Waiwitlikhit et al. · 41st International Conference on Machine Learning (ICML 2024)
2024APeer-reviewed3
Verifiable evaluations of machine learning models using zkSNARKs
T. South et al. · arXiv · Zkonduit
2024BPreprint3
Verifiable Training of AI Models
A. Aguirre & R. Millet · Future of Life Institute
2024CBlog / article1
Verification methods for international AI agreements
A. R. Wasil et al. · arXiv
2024BPreprint8
Zero-Knowledge Proofs of Training for Deep Neural Networks
K. Abbaszadeh et al. · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330
2024APeer-reviewed2
zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models
H. Sun · GitHub; archived on Zenodo · University of Waterloo
2024BCode3
zkLLM: Zero Knowledge Proofs for Large Language Models
H. Sun et al. · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024) · University of Waterloo
2024APeer-reviewed8
ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs
B.-J. Chen et al. · 19th European Conference on Computer Systems (EuroSys 2024)
2024APeer-reviewed1
A Practical Introduction to Side-Channel Extraction of Deep Neural Network Parameters
R. Joud et al. · 21st International Conference on Smart Card Research and Advanced Applications (CARDIS 2022), LNCS 13820, pp. 45–65
2023APeer-reviewed—
Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI
E. Apsey et al. · NVIDIA Technical Blog
2023CBlog / article2
Exploration of secure hardware solutions for safe AI deployment2023CBlog / article2
ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection
T. Mosavirik et al. · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325
2023APeer-reviewed1
International Governance of Civilian AI: A Jurisdictional Certification Approach2023BTechnical report1
Nuclear Arms Control Verification and Lessons for AI Treaties
M. Baker · arXiv
2023BPreprint—
OPCW confirms: All declared chemical weapons stockpiles verified as irreversibly destroyed
Organisation for the Prohibition of Chemical Weapons · OPCW
2023AGovernment document—
Proof-of-Learning is Currently More Broken Than You Think
C. Fang et al. · 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023)
2023APeer-reviewed3
Remote ATtestation procedureS (RATS) Architecture (RFC 9334)
H. Birkholz et al. · Internet Engineering Task Force (RATS Working Group)
2023BTechnical report4
SAGE: Software-based Attestation for GPU Execution
A. Ivanov et al. · 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 485–499
2023APeer-reviewed1
Tools for Verifying Neural Models' Training Data
D. Choi et al. · Advances in Neural Information Processing Systems 36 (NeurIPS 2023)
2023APeer-reviewed2
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring
Y. Shavit · arXiv
2023BPreprint20
"Adversarial Examples" for Proof-of-Learning
R. Zhang et al. · 2022 IEEE Symposium on Security and Privacy (SP), pp. 1408-1422
2022APeer-reviewed1
Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems
P. Staat et al. · 2022 IEEE Symposium on Security and Privacy
2022APeer-reviewed1
Common Terminology for Confidential Computing
Confidential Computing Consortium
2022BTechnical report2
ZKProof Community Reference
D. Benarroch et al. · ZKProof
2022BTechnical report4
Proof-of-Learning: code for Proof-of-Learning: Definitions and Practice
CleverHans Lab · GitHub
2021BCode1
Proof-of-Learning: Definitions and Practice
H. Jia et al. · 2021 IEEE Symposium on Security and Privacy (SP), pp. 1039-1056
2021APeer-reviewed1
Detecting Covert Cryptomining Using HPC
A. Gangwal et al. · Cryptology and Network Security – CANS 2020, LNCS 12579, pp. 344–364
2020APeer-reviewed1
Secure Physical Enclosures from Covers with Tamper-Resistance
V. Immler et al. · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96
2019APeer-reviewed1
Platform Firmware Resiliency Guidelines (NIST SP 800-193)
A. Regenscheid · National Institute of Standards and Technology
2018AGovernment document1
The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond
J. Obermaier & V. Immler · Journal of Hardware and Systems Security
2018APeer-reviewed1
Proofs of Useful Work
M. Ball et al. · IACR Cryptology ePrint Archive 2017/203
2017BPreprint2
TCG Glossary
Trusted Computing Group
2017BDocumentation2
Proofs of Space
S. Dziembowski et al. · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796)
2015APeer-reviewed5
Tamper-Indicating Enclosures, A Current Survey
H. A. Smartt & Z. N. Gastelum · Sandia National Laboratories, SAND2015-4251C
2015BTechnical report1
A zero-knowledge protocol for nuclear warhead verification
A. Glaser et al. · Nature 510, 497–502
2014APeer-reviewed—
IBM 4765 Cryptographic Coprocessor Security Module: Security Policy
IBM Corporation · NIST Cryptographic Module Validation Program
2012BTechnical report1
Cryptographic Module Validation Program Certificate #1505: IBM 4765 Cryptographic Coprocessor Security Module
National Institute of Standards and Technology · NIST Cryptographic Module Validation Program
2011AGovernment document1
Secure Code Update for Embedded Devices via Proofs of Secure Erasure
D. Perito & G. Tsudik · Computer Security – ESORICS 2010, LNCS 6345, pp. 643–662
2010APeer-reviewed2
On the Difficulty of Software-Based Attestation of Embedded Devices
C. Castelluccia et al. · Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), pp. 400–409
2009APeer-reviewed1
SWATT: SoftWare-based ATTestation for Embedded Devices
A. Seshadri et al. · IEEE Symposium on Security and Privacy 2004, pp. 272–282
2004APeer-reviewed1
Guidelines for Writing RFC Text on Security Considerations (RFC 3552, BCP 72)
E. Rescorla et al. · Internet Engineering Task Force
2003AStandard1
The Biological Weapons Convention
Nuclear Threat Initiative · NTI
2003BTechnical report—
Security Requirements for Cryptographic Modules (FIPS PUB 140-2)
National Institute of Standards and Technology
2001AStandard1
Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials
R. G. Johnston · The Nonproliferation Review, Spring 2001, pp. 102–114
2001APeer-reviewed1
Physical Security and Tamper-Indicating Devices
R. G. Johnston & A. R. E. Garcia · Los Alamos National Laboratory, LA-UR-96-3827
1996BTechnical report2
Remarks on Signing the Intermediate-Range Nuclear Forces Treaty
R. Reagan · Ronald Reagan Presidential Library and Museum
1987AGovernment document—
Treaty between the United States of America and the Union of Soviet Socialist Republics on the Limitation of Anti-Ballistic Missile Systems
United States of America & Union of Soviet Socialist Republics · United Nations Treaty Series, vol. 944, No. 13446
1972AGovernment document—

Search

Full search page