{"name":"AI Verification Tech Map","schema_version":"1.0.0","rubric_version":"1.1","generated":"2026-09-24T12:26:38.188Z","includes_drafts":true,"license":"CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)","notes":"Fields marked assessment:true are editorial judgments under the published rubric, not statements of fact. flags_all includes computed flags (ai-drafted, review-overdue, critical-flaw-open).","nodeTypes":[{"k":"C","type":"claim","label":"Claim","plural":"Claims","shape":"square","r":11,"desc":"Something one party wants to check about another party’s AI hardware or software."},{"k":"M","type":"mechanism","label":"Mechanism","plural":"Mechanisms","shape":"circle","r":7.5,"desc":"A technical means of checking a claim. Shaded by readiness."},{"k":"I","type":"implementation","label":"Implementation","plural":"Implementations","shape":"diamond","r":6.5,"desc":"A built or specified system that realises a mechanism. Shaded by readiness."},{"k":"O","type":"organization","label":"Organization","plural":"Organizations","shape":"hexagon","r":6.5,"desc":"Who builds, studies or publishes the work."},{"k":"B","type":"blocker","label":"Blocker","plural":"Blockers","shape":"triangle","r":4.6,"desc":"An obstacle to a mechanism’s next readiness level or to real use."},{"k":"F","type":"flaw","label":"Known flaw","plural":"Known flaws","shape":"triangle-down","r":4.6,"desc":"A published attack, argument or open question that weakens a mechanism."},{"k":"K","type":"concept","label":"Concept","plural":"Concepts","shape":"ring","r":5,"desc":"A glossary term that records use."},{"k":"T","type":"theme","label":"Challenge theme","plural":"Challenge themes","shape":"pill","r":7,"desc":"A recurring kind of obstacle, shared across mechanisms."},{"k":"G","type":"category","label":"Category","plural":"Categories","shape":"frame","r":9,"desc":"Where a mechanism acts: on the chip, next to it, in cryptography and so on."},{"k":"S","type":"source","label":"Source","plural":"Sources","shape":"dot","r":3,"desc":"A cited paper, report, standard or post."}],"edgeTypes":{"verifies":{"fwd":"Helps verify","rev":"Checked by","family":"verify","desc":"Aimed at the claim (primary) or contributes to it (supporting)."},"realises":{"fwd":"Implements","rev":"Implemented by","family":"build","desc":"An implementation realises a mechanism."},"develops":{"fwd":"Develops","rev":"Developed by","family":"org","desc":"An organization develops an implementation."},"works_on":{"fwd":"Works on","rev":"Worked on by","family":"org","desc":"An organization designed, built, evaluated or supplied the work."},"works_toward":{"fwd":"Works toward","rev":"Worked toward by","family":"org","derived":true,"desc":"Derived: the organization develops or works on something that helps verify the claim."},"depends_on":{"fwd":"Depends on","rev":"Needed by","family":"depend","desc":"One mechanism or implementation needs another to work."},"waits_on":{"fwd":"Waits on","rev":"Its immaturity blocks","family":"obstacle","desc":"A blocker that lifts only when another mechanism matures."},"blocks":{"fwd":"Blocks","rev":"Blockers","family":"obstacle","desc":"An obstacle to the next readiness level or to real use."},"weakens":{"fwd":"Weakens","rev":"Known flaws","family":"flaw","desc":"A published flaw in the mechanism or implementation."},"complements":{"fwd":"Complements","rev":"Complements","family":"peer","sym":true,"desc":"Works well alongside."},"alternative":{"fwd":"Alternative to","rev":"Alternative to","family":"peer","sym":true,"desc":"Another way to check the same thing."},"uses_concept":{"fwd":"Uses concept","rev":"Used by","family":"knowledge","desc":"The record relies on a glossary concept."},"related":{"fwd":"Related to","rev":"Related to","family":"knowledge","sym":true,"desc":"A glossary concept points to a related record."},"theme":{"fwd":"Challenge theme","rev":"Blockers","family":"knowledge","desc":"The theme a blocker belongs to."},"faces":{"fwd":"Faces","rev":"Faced by","family":"knowledge","desc":"A challenge theme the record faces."},"in_category":{"fwd":"In category","rev":"Contains","family":"knowledge","desc":"The mechanism’s primary category."},"cites":{"fwd":"Cites","rev":"Cited by","family":"evidence","desc":"The record cites the source."},"published":{"fwd":"Published","rev":"Published by","family":"evidence","desc":"The organization authored or published the source."},"mentions":{"fwd":"Mentions","rev":"Mentioned in","family":"mention","desc":"Named in the record’s text, with no structured link."}},"edgeStyle":{"verifies":{"c":"verify","w":1.5,"arrow":true},"realises":{"c":"edge","w":1.2,"arrow":true},"develops":{"c":"org","w":1.2,"arrow":true},"works_on":{"c":"org","w":1,"dash":[5,3],"arrow":true},"works_toward":{"c":"org","w":1,"dash":[1.5,3],"arrow":true},"depends_on":{"c":"ink","w":1.2,"arrow":true},"waits_on":{"c":"blocker","w":1.2,"dash":[5,3],"arrow":true},"blocks":{"c":"blocker","w":1,"arrow":true},"weakens":{"c":"flaw","w":1,"arrow":true},"complements":{"c":"edge","w":1,"dash":[6,4]},"alternative":{"c":"edge","w":1,"dash":[1.5,3]},"uses_concept":{"c":"concept","w":0.9,"arrow":true},"related":{"c":"concept","w":0.9,"dash":[4,3]},"theme":{"c":"theme","w":0.9,"arrow":true},"faces":{"c":"theme","w":0.8,"dash":[4,3],"arrow":true},"in_category":{"c":"edge","w":0.8,"dash":[2,4],"arrow":true},"cites":{"c":"source","w":0.7,"arrow":true},"published":{"c":"source","w":0.7,"dash":[4,3],"arrow":true},"mentions":{"c":"source","w":0.7,"dash":[1,3],"arrow":true}},"supportingStyle":{"w":1,"dash":[4,3]},"presets":[{"key":"landscape","label":"Landscape","desc":"Claims, the mechanisms and implementations aimed at them, and who builds them.","types":"CMIO","rels":["verifies","realises","develops","works_on","depends_on","complements","alternative"]},{"key":"obstacles","label":"Obstacles","desc":"What blocks each mechanism, which flaws weaken it, and what it waits on.","types":"CMIBF","rels":["verifies","realises","blocks","weakens","waits_on","depends_on"]},{"key":"builders","label":"Who builds what","desc":"Organizations, what they build or study, and the claims it serves.","types":"OIMC","rels":["develops","works_on","realises","verifies"],"supporting":false},{"key":"challenges","label":"Challenges","desc":"Blockers grouped by challenge theme, and the mechanisms they hold back.","types":"TBMI","rels":["theme","blocks","waits_on","realises"]},{"key":"concepts","label":"Concepts","desc":"Glossary concepts and the records that use them.","types":"KMIC","rels":["uses_concept","related","verifies"]},{"key":"evidence","label":"Evidence","desc":"Sources, who published them, and the records that cite them.","types":"SOMIC","rels":["cites","published","verifies","realises"]},{"key":"everything","label":"Everything","desc":"Every node and relation except text mentions. Dense.","types":"CMIOBFKTGS","rels":["verifies","realises","develops","works_on","depends_on","waits_on","blocks","weakens","complements","alternative","uses_concept","related","theme","faces","in_category","cites","published"]}],"levels":[{"k":"R0","label":"Idea"},{"k":"R1","label":"Proposed"},{"k":"R2","label":"Demonstrated"},{"k":"R3","label":"In production"},{"k":"R4","label":"Deployment-ready"}],"categories":[{"k":"on-chip","label":"On-chip & hardware-enabled","short":"On-chip"},{"k":"off-chip-devices","label":"Off-chip devices & sensors","short":"Off-chip devices"},{"k":"cryptographic-computational","label":"Cryptographic & computational","short":"Crypto / compute"},{"k":"isolation-architecture","label":"Isolation & system architectures","short":"Isolation & architecture"},{"k":"accounting-provenance","label":"Compute accounting & provenance","short":"Accounting"},{"k":"remote-sensing","label":"Remote & side-channel sensing","short":"Sensing"}],"themes":[{"k":"coverage-hidden-compute","label":"Coverage & hidden compute"},{"k":"hardware-trust","label":"Hardware trust"},{"k":"evidence-binding","label":"Evidence binding"},{"k":"protocol-soundness","label":"Protocol soundness"},{"k":"adversarial-validation","label":"Adversarial validation"},{"k":"capacity-bounds","label":"Capacity bounds"},{"k":"performance-compatibility","label":"Performance & compatibility"},{"k":"privacy-leakage","label":"Privacy & leakage"},{"k":"access-governance","label":"Access & governance"}],"counts":{"C":10,"M":25,"I":16,"O":23,"B":146,"F":140,"K":25,"T":9,"G":6,"S":212},"rings":{"claims":250,"concepts":350,"mechanisms":480,"implementations":660,"categories":760,"organizations":860,"sources":1080,"sectors":[{"cat":"on-chip","a0":-2.0206,"a1":-1.121},{"cat":"off-chip-devices","a0":-1.051,"a1":-0.384},{"cat":"remote-sensing","a0":-0.314,"a1":0.1203},{"cat":"accounting-provenance","a0":0.1903,"a1":0.7022},{"cat":"isolation-architecture","a0":0.7722,"a1":1.7494},{"cat":"cryptographic-computational","a0":1.8194,"a1":4.1926}]},"nodes":[{"id":"C-0001","k":"C","l":"Compute stock is at most a declared amount","d":"A party holds no more AI-relevant compute, counted in chips or equivalent capacity, than the total it has declared.","h":"/claims/compute-stock-is-bounded/","cls":"Negative","w":7,"x":204.6,"y":143.7},{"id":"C-0002","k":"C","l":"Chips are where they are declared to be","d":"Specific AI chips are physically located at the sites a party has declared, throughout the declared period.","h":"/claims/chips-are-where-declared/","cls":"Positive","w":9,"x":250,"y":-4},{"id":"C-0003","k":"C","l":"Declared hardware is idle or shut down","d":"Specified AI chips or facilities are not performing computation, or are powered off, throughout a declared period.","h":"/claims/declared-hardware-is-idle/","cls":"Negative","w":8,"x":-81.1,"y":-236.5},{"id":"C-0004","k":"C","l":"This compute runs inference, not training","d":"A declared cluster is used only to run existing models to produce outputs, and not to train new or more capable models.","h":"/claims/inference-not-training/","cls":"Mixed","w":28,"x":199.9,"y":-150.2},{"id":"C-0005","k":"C","l":"The declared model is the one being served","d":"Outputs delivered to users or auditors come from the specific model, weights and configuration the provider declared, not from a substitute.","h":"/claims/declared-model-is-served/","cls":"Positive","w":30,"x":-199.9,"y":150.2},{"id":"C-0006","k":"C","l":"Declared safeguards were applied during inference","d":"Specified safety measures, such as input filters, output checks or monitoring, actually ran on the requests a deployed model served.","h":"/claims/safeguards-were-applied/","cls":"Positive","w":13,"x":-250,"y":4},{"id":"C-0007","k":"C","l":"A training run stayed within declared limits","d":"A declared training run used no more compute than permitted and had its declared properties, such as data, hyperparameters and resulting weights.","h":"/claims/training-within-declared-limits/","cls":"Mixed","w":17,"x":-204.6,"y":-143.7},{"id":"C-0008","k":"C","l":"Communication between compute groups is bounded","d":"Data flowing between specified groups of chips, or out of a facility, stays below a declared rate, so the groups cannot jointly run large workloads.","h":"/claims/bandwidth-is-bounded/","cls":"Negative","w":10,"x":81.1,"y":236.5},{"id":"C-0009","k":"C","l":"Model weights or data have not left the facility","d":"No copy of specified model weights or sensitive data has left a designated facility through networks, physical media or other channels.","h":"/claims/weights-have-not-left/","cls":"Negative","w":14,"x":-73.4,"y":239},{"id":"C-0010","k":"C","l":"There is no undeclared relevant compute","d":"A party controls no AI-relevant computing hardware or facilities, above an agreed threshold, beyond those it has declared.","h":"/claims/no-undeclared-compute/","cls":"Negative","w":12,"x":73.4,"y":-239},{"id":"M-0014","k":"M","l":"Bandwidth limits and compartmentalization","d":"Capping or removing the network links between groups of accelerators, so that serving models still works but large training runs become impractically slow.","h":"/mechanisms/bandwidth-limits-and-compartmentalization/","lv":"R1","cat":"isolation-architecture","cats":["off-chip-devices"],"aka":["Traffic shaping","Isolated inference units","Interconnect limits"],"w":45,"x":85.5,"y":449.9},{"id":"M-0024","k":"M","l":"Bounding unexplained information in outputs","d":"Limits the hidden information a facility's outputs can carry by measuring how much of those outputs the declared computation fails to predict.","h":"/mechanisms/bounding-unexplained-information/","lv":"R2","cat":"isolation-architecture","cats":["cryptographic-computational"],"aka":["Unexplained-information bound","Output compressibility bounds","Egress limiting by compression"],"w":33,"x":-29.4,"y":521.2},{"id":"M-0018","k":"M","l":"Chip location verification","d":"Timing a chip's signed replies to trusted servers at known places, so that the speed of light bounds how far away the chip can be.","h":"/mechanisms/chip-location-verification/","lv":"R1","cat":"accounting-provenance","cats":["on-chip"],"aka":["Delay-based location verification","Ping-based location attestation","Latency-based geolocation of chips"],"w":31,"x":435,"y":143.3},{"id":"M-0019","k":"M","l":"Chip registries and manufacturing records","d":"Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.","h":"/mechanisms/chip-registries-and-manufacturing-records/","lv":"R1","cat":"accounting-provenance","cats":["cryptographic-computational"],"aka":["AI chip registry","Chain-of-custody tracking for AI chips","Commitments to manufacturing records"],"w":26,"x":438.3,"y":283.5},{"id":"M-0025","k":"M","l":"Confidential multi-party verification","d":"Lets mutually distrusting parties run an agreed check over private models or records inside attested enclaves or zero-knowledge proofs, revealing only the result.","h":"/mechanisms/confidential-multi-party-verification/","lv":"R2","cat":"cryptographic-computational","cats":["on-chip"],"aka":["Confidential audits","Attested confidential workflows","Trustless audits"],"w":33,"x":-443.3,"y":115.2},{"id":"M-0002","k":"M","l":"Deterministic and bit-exact inference","d":"Making model inference reproducible bit for bit, so that a verifier's re-run must match the provider's output exactly rather than approximately.","h":"/mechanisms/deterministic-inference/","lv":"R2","cat":"cryptographic-computational","aka":["Bit-exact inference","Batch-invariant inference","Reproducible inference"],"w":36,"x":-296.7,"y":429.5},{"id":"M-0011","k":"M","l":"Hardware performance throttling and licensing","d":"On-chip mechanisms that cut an AI accelerator's performance when a license expires or a trusted trigger fires, bounding what the hardware can do.","h":"/mechanisms/hardware-performance-throttling/","lv":"R1","cat":"on-chip","cats":["accounting-provenance"],"aka":["Offline licensing","Performance limits","Microarchitectural throttling","Compute licensing","Usage limits"],"w":25,"x":51.4,"y":-455.1},{"id":"M-0009","k":"M","l":"Hardware-enabled guarantees (flexHEG) and guarantee processors","d":"Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used.","h":"/mechanisms/flexheg-guarantee-processors/","lv":"R1","cat":"on-chip","cats":["isolation-architecture"],"aka":["flexHEG","Flexible hardware-enabled guarantees","Guarantee processor","Interlock","Hardware-enabled governance mechanisms (HEMs)","On-chip governance mechanisms"],"w":44,"x":-58.6,"y":-518.7},{"id":"M-0015","k":"M","l":"Memory wiping and proofs of secure erasure","d":"Overwriting all of a device's memory in a way a verifier can check, so that nothing from earlier, undeclared work survives the wipe.","h":"/mechanisms/memory-wiping-and-secure-erasure/","lv":"R1","cat":"isolation-architecture","cats":["cryptographic-computational"],"aka":["Proofs of secure erasure (PoSE)","Periodic memory wipes","Forced memorization"],"w":31,"x":218.6,"y":474},{"id":"M-0012","k":"M","l":"Model identity attestation","d":"Establishes that responses come from a specific, committed set of model weights, using enclave measurements or recomputation of sampled outputs.","h":"/mechanisms/model-identity-attestation/","lv":"R3","cat":"cryptographic-computational","cats":["on-chip"],"crit":true,"aka":["Model integrity verification","Proving which model is served","Weight commitment and attestation","Model provenance attestation"],"w":38,"x":-341.6,"y":305.1},{"id":"M-0013","k":"M","l":"Network taps and certifiers","d":"Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work.","h":"/mechanisms/network-taps-and-certifiers/","lv":"R1","cat":"off-chip-devices","cats":["cryptographic-computational"],"aka":["Secure network taps","Cluster I/O fingerprinting","Secure Gateway Device"],"w":66,"x":270.2,"y":-369.8},{"id":"M-0010","k":"M","l":"On-chip telemetry from timing, memory and performance counters","d":"Uses timing, memory-residency and performance-counter signals measured on AI accelerators as evidence about which workloads they are running.","h":"/mechanisms/on-chip-telemetry/","lv":"R2","cat":"on-chip","cats":["remote-sensing"],"crit":true,"aka":["GPU telemetry","Performance counters","NVML telemetry","Compute metering","VRAM residency challenges"],"w":39,"x":172.8,"y":-492.6},{"id":"M-0006","k":"M","l":"Proof-of-learning and training-transcript verification","d":"A trainer logs checkpoints, data order and settings, so a verifier can re-run sampled training segments and check that the claimed training happened.","h":"/mechanisms/proof-of-learning/","lv":"R2","cat":"cryptographic-computational","crit":true,"aka":["proof-of-learning","PoL","proof of training transcript","PoTT","proof-of-training-data","PoTD"],"w":25,"x":-468.3,"y":-230.7},{"id":"M-0007","k":"M","l":"Proofs of useful work and resource exhaustion","d":"Cryptographic evidence that hardware performed a given amount of agreed computation, proposed as a way to show no spare capacity remained for other work.","h":"/mechanisms/proofs-of-useful-work/","lv":"R1","cat":"cryptographic-computational","aka":["proof of useful work","PoUW","proof-of-work accounting","resource exhaustion"],"w":26,"x":-311.1,"y":-419.2},{"id":"M-0020","k":"M","l":"Remote detection of data centres","d":"Remote detection locates large data centres and estimates their power capacity without site access, using satellite imagery, heat signatures and public records such as permits.","h":"/mechanisms/remote-detection-of-data-centres/","lv":"R1","cat":"remote-sensing","aka":["Satellite monitoring of data centres","Remote sensing of AI compute facilities","National technical means for AI compute"],"w":20,"x":448.4,"y":-93.4},{"id":"M-0003","k":"M","l":"Reproducible computation packets","d":"Organizing all AI workloads in a facility into discrete, reproducible units, so that a verifier can recompute a random sample and check each one.","h":"/mechanisms/reproducible-computation-packets/","lv":"R1","cat":"isolation-architecture","cats":["cryptographic-computational"],"aka":["Packet-based verification"],"w":29,"x":286.7,"y":357.1},{"id":"M-0023","k":"M","l":"Safeguard attestation","d":"Hardware-signed evidence that an AI service ran its declared safeguards, such as a guardrail classifier or monitor, when producing a given response.","h":"/mechanisms/safeguard-attestation/","lv":"R2","cat":"cryptographic-computational","cats":["on-chip"],"aka":["Proof of guardrail","Attested safeguards","Verifiable safeguard execution"],"w":35,"x":-521.9,"y":8.9},{"id":"M-0001","k":"M","l":"Sampled inference recomputation","d":"A verifier re-runs a random sample of an AI provider's logged queries on a trusted copy of the declared model and checks the outputs match.","h":"/mechanisms/sampled-inference-recomputation/","lv":"R3","cat":"cryptographic-computational","aka":["Inference recomputation","Recomputation-based inference verification","Partial recomputation"],"w":49,"x":-164.4,"y":427.5},{"id":"M-0022","k":"M","l":"Side-channel suppression for isolated facilities","d":"Shielding, filtering, jamming and inspecting an AI facility so that no hidden physical channel can bypass the checks placed on its official links.","h":"/mechanisms/side-channel-suppression/","lv":"R1","cat":"off-chip-devices","cats":["isolation-architecture"],"aka":["Covert-channel suppression","TEMPEST-style shielding for verification","Retrofitted side-channel defences"],"w":33,"x":403,"y":-217.6},{"id":"M-0017","k":"M","l":"Tamper evidence for verifier devices","d":"Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating.","h":"/mechanisms/tamper-evidence-for-verifier-devices/","lv":"R2","cat":"off-chip-devices","cats":["isolation-architecture"],"aka":["Tamper-evident enclosures","Tamper-respondent enclosures","Tamper-indicating enclosures","Anti-tamper sensing"],"w":33,"x":393.3,"y":-343.2},{"id":"M-0008","k":"M","l":"TEE remote attestation for AI workloads","d":"Trusted execution environments (TEEs) in CPUs and GPUs sign reports of loaded software, so a remote party can check which code ran an AI workload.","h":"/mechanisms/tee-remote-attestation/","lv":"R3","cat":"on-chip","cats":["cryptographic-computational"],"crit":true,"aka":["Confidential computing","GPU confidential computing","Remote attestation","Confidential VM attestation"],"w":67,"x":-151.6,"y":-432.2},{"id":"M-0016","k":"M","l":"Timed challenge-response and memory-occupation challenges","d":"A verifier sends unpredictable questions that a device can answer in time only if it holds specified data, or dedicates specified resources, locally.","h":"/mechanisms/timed-challenge-response/","lv":"R1","cat":"cryptographic-computational","cats":["accounting-provenance"],"aka":["Memory challenges","Memory-occupation challenges","Software-based attestation","Proof-of-space-style challenges"],"w":34,"x":-351.8,"y":-293.3},{"id":"M-0021","k":"M","l":"Workload classification from telemetry and side channels","d":"Telling whether chips are training, serving or doing non-AI work from GPU counters or power draw, signals that do not read weights or data.","h":"/mechanisms/workload-classification-from-telemetry/","lv":"R2","cat":"remote-sensing","cats":["on-chip","off-chip-devices"],"aka":["Workload classification","Training detection from GPU telemetry","Power-based workload identification","Training-versus-inference classification"],"w":23,"x":522,"y":6.1},{"id":"M-0004","k":"M","l":"Zero-knowledge proofs of inference","d":"A prover produces a cryptographic proof that an output came from running a committed model on a given input, without revealing the weights.","h":"/mechanisms/zk-proofs-of-inference/","lv":"R2","cat":"cryptographic-computational","aka":["ZKML inference proofs","verifiable inference with zkSNARKs"],"w":36,"x":-460.2,"y":246.4},{"id":"M-0005","k":"M","l":"Zero-knowledge proofs of training constraints","d":"Cryptographic proofs that a training run followed a committed dataset, procedure and rules, checkable without revealing the model or the data.","h":"/mechanisms/zk-proofs-of-training-constraints/","lv":"R2","cat":"cryptographic-computational","aka":["zero-knowledge proofs of training","zkPoT","verifiable training"],"w":25,"x":-446.9,"y":-100.1},{"id":"I-0011","k":"I","l":"AI 2040 inference-only verification stack","d":"A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs.","h":"/implementations/ai-2040-inference-only-verification-plan/","lv":"R1","cat":"isolation-architecture","cats":["off-chip-devices","cryptographic-computational"],"kind":"Proposed architecture","aka":["AI 2040 verification plan (inference-only retrofit)","Inference-only retrofit"],"w":35,"x":212.3,"y":662.8},{"id":"I-0013","k":"I","l":"Apple Private Cloud Compute","d":"Apple's cloud AI inference service, in which user devices send requests only to servers that attest to running software published in a public transparency log.","h":"/implementations/apple-private-cloud-compute/","lv":"R3","cat":"on-chip","cats":["cryptographic-computational"],"kind":"Product","aka":["PCC","Private Cloud Compute"],"w":15,"x":155.2,"y":-678.5},{"id":"I-0007","k":"I","l":"Attestable Audits","d":"A research prototype that runs AI safety benchmarks inside a trusted execution environment and publishes attestations binding the model, the audit and the results.","h":"/implementations/attestable-audits/","lv":"R2","cat":"on-chip","cats":["cryptographic-computational"],"kind":"Research prototype","aka":["Attestable Audits prototype","Verifiable AI safety benchmarks in TEEs"],"w":20,"x":-143.6,"y":-627.8},{"id":"I-0005","k":"I","l":"Attestable zero-knowledge inference prover","d":"Attestable's zero-knowledge prover, which the company reports proves large language model outputs came from committed weights at tens of tokens per second.","h":"/implementations/attestable-zk-inference/","lv":"R1","cat":"cryptographic-computational","kind":"Product","aka":["Attestable ZK prover"],"w":17,"x":-638.1,"y":87.1},{"id":"I-0016","k":"I","l":"Batch-invariant inference kernels (Thinking Machines)","d":"Open-source kernels from Thinking Machines Lab that make LLM outputs independent of batch size, adopted in vLLM and SGLang to give reproducible inference.","h":"/implementations/batch-invariant-inference-kernels/","lv":"R2","cat":"cryptographic-computational","kind":"Open-source project","aka":["batch_invariant_ops","VLLM_BATCH_INVARIANT","SGLang deterministic inference"],"w":10,"x":-507.6,"y":396.4},{"id":"I-0002","k":"I","l":"DiFR (Divergence From Reference)","d":"DiFR checks that an inference provider ran its declared model by comparing output tokens or activations with a trusted re-run using the same random seed.","h":"/implementations/difr/","lv":"R2","cat":"cryptographic-computational","kind":"Research prototype","aka":["Token-DiFR","Activation-DiFR"],"w":17,"x":-417.9,"y":556.5},{"id":"I-0014","k":"I","l":"EZKL","d":"EZKL is a library from Zkonduit that turns neural networks into zero-knowledge circuits, so a prover can show an output came from a committed model.","h":"/implementations/ezkl/","lv":"R2","cat":"cryptographic-computational","kind":"Product","aka":["ezkl","Easy Zero-Knowledge Inference"],"w":13,"x":-690.3,"y":-88.9},{"id":"I-0012","k":"I","l":"Low-trust AI compute verification system overview","d":"A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records.","h":"/implementations/low-trust-compute-verification-system-overview/","lv":"R1","cat":"isolation-architecture","cats":["off-chip-devices","cryptographic-computational"],"kind":"Proposed architecture","aka":["Cankaya system overview","Near-term, low-trust AI compute verification"],"w":40,"x":-10.1,"y":643.9},{"id":"I-0009","k":"I","l":"Lucid sovereignty (location) certificates","d":"A draft specification, hosted by Lucid Computing, for short-lived certificates that bound where a workload runs by timing signed exchanges with fixed anchors.","h":"/implementations/lucid-location-certificates/","lv":"R1","cat":"accounting-provenance","cats":["on-chip"],"kind":"Standard","aka":["Sovereignty Certificates","Ping-based location attestation","sovcert"],"w":18,"x":580.9,"y":277.9},{"id":"I-0004","k":"I","l":"Pearl proof-of-useful-work blockchain","d":"A blockchain whose mining is designed to be a by-product of GPU matrix multiplications in AI workloads, with public node and miner code.","h":"/implementations/pearl-proof-of-useful-work/","lv":"R3","cat":"cryptographic-computational","kind":"Open-source project","aka":["Pearl","Pearl protocol","PRL"],"w":16,"x":-390.6,"y":-512},{"id":"I-0010","k":"I","l":"RAND secure inference data center (SIDC) design","d":"A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.","h":"/implementations/rand-secure-inference-data-centers/","lv":"R1","cat":"isolation-architecture","cats":["off-chip-devices"],"kind":"Proposed architecture","aka":["Secure inference data center","SIDC","Highly Secure Inference Data Centers"],"w":24,"x":382.4,"y":518.2},{"id":"I-0008","k":"I","l":"SASH confidential network logger","d":"An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference.","h":"/implementations/sash-confidential-network-logger/","lv":"R1","cat":"off-chip-devices","cats":["cryptographic-computational"],"kind":"Research prototype","aka":["Confidential Network Logger (CNL)","SASH inference verification prototype"],"w":23,"x":485.2,"y":-423.4},{"id":"I-0006","k":"I","l":"Tinfoil model identity (Modelwrap)","d":"Tinfoil's method for proving which model weights its enclave-hosted inference service runs, by binding a dm-verity hash of the weights into remote attestation.","h":"/implementations/tinfoil-model-identity/","lv":"R3","cat":"cryptographic-computational","cats":["on-chip"],"crit":true,"kind":"Product","aka":["Modelwrap","Tinfoil model integrity"],"w":19,"x":-551.8,"y":-424.2},{"id":"I-0001","k":"I","l":"TOPLOC","d":"TOPLOC is a hashing scheme from Prime Intellect that lets a verifier check whether an inference provider ran the model, prompt and precision it claims.","h":"/implementations/toploc/","lv":"R3","cat":"cryptographic-computational","kind":"Open-source project","aka":["TOPLOC v2"],"w":16,"x":-239.1,"y":598},{"id":"I-0015","k":"I","l":"Verde and RepOps (Gensyn)","d":"Gensyn's system for checking delegated machine-learning jobs, which settles disagreements between providers by re-running a single operation with bitwise-reproducible operators.","h":"/implementations/gensyn-verde-repops/","lv":"R2","cat":"cryptographic-computational","kind":"Product","aka":["Verde","RepOps","Reproducible Operators","Gensyn Reproducible Execution Environment (REE)"],"w":13,"x":-595.2,"y":-245.9},{"id":"I-0003","k":"I","l":"zkLLM","d":"zkLLM is a GPU-accelerated zero-knowledge proof system that proves a large language model's output came from committed weights without revealing those weights.","h":"/implementations/zkllm/","lv":"R2","cat":"cryptographic-computational","kind":"Research prototype","aka":["zkLLM-CCS2024"],"w":16,"x":-641.2,"y":270.6},{"id":"O-0201","k":"O","l":"AI Futures Project","d":"A small research group forecasting the future of AI; publisher of the AI 2040 scenario, including an inference-only verification plan.","h":"/organizations/ai-futures-project/","kind":"Research organization","w":11,"x":557.4,"y":654.9},{"id":"O-0101","k":"O","l":"Amodo Design","d":"A hardware engineering company that builds and publishes prototypes for verifying AI agreements, including inference recomputation, network taps and memory wiping.","h":"/organizations/amodo-design/","kind":"Company","w":22,"x":454.1,"y":730.3},{"id":"O-0120","k":"O","l":"Attestable","d":"A company developing zero-knowledge proofs for AI systems; it reports a prover for large language model inference and proposes proof-based compute accounting.","h":"/organizations/attestable/","kind":"Company","w":6,"x":-859.2,"y":-37.2},{"id":"O-0207","k":"O","l":"Center for a New American Security","d":"An independent, bipartisan, nonprofit national-security policy organization; publisher of a report proposing on-chip mechanisms, including location verification, for governing AI chips.","h":"/organizations/center-for-a-new-american-security/","kind":"Research organization","aka":["CNAS"],"w":4,"x":424.3,"y":-748},{"id":"O-0211","k":"O","l":"Centre for the Governance of AI","d":"A think tank that aims to help decision-makers navigate the transition to advanced AI, whose research includes work on compute governance.","h":"/organizations/centre-for-the-governance-of-ai/","kind":"Research organization","aka":["GovAI"],"w":3,"x":789.8,"y":-340.3},{"id":"O-0208","k":"O","l":"Epoch AI","d":"A research institute studying trends in AI; it runs the Frontier Data Centers Hub, which estimates AI data-centre capacity from satellite imagery and permits.","h":"/organizations/epoch-ai/","kind":"Research organization","aka":["Epoch"],"w":2,"x":845.7,"y":-156},{"id":"O-0206","k":"O","l":"Future of Life Institute","d":"A nonprofit working to steer transformative technology away from extreme risks; it built a secure-hardware AI governance demonstration and partners on a network-logger prototype.","h":"/organizations/future-of-life-institute/","kind":"Nonprofit","aka":["FLI"],"w":3,"x":219.4,"y":-831.5},{"id":"O-0209","k":"O","l":"Hardware AI Governance Lab","d":"A University of Oxford lab, hosted by the Oxford Martin AI Governance Initiative, that studies how computer hardware can support AI governance and international coordination.","h":"/organizations/oxford-hardware-ai-governance-lab/","kind":"Academic","aka":["HAIGL","Oxford Hardware AI Governance Lab"],"w":4,"x":499.9,"y":-699.8},{"id":"O-0204","k":"O","l":"Institute for AI Policy and Strategy","d":"A nonpartisan think tank on AI policy; its work on AI chips includes a design and prototype for delay-based location verification.","h":"/organizations/institute-for-ai-policy-and-strategy/","kind":"Research organization","aka":["IAPS"],"w":5,"x":775.8,"y":371.2},{"id":"O-0210","k":"O","l":"Intelligence Security Laboratories","d":"A nonprofit lab doing implementation-driven research on high-security AI systems, including secure data centres, to demonstrate the security critical AI deployments will need.","h":"/organizations/intelligence-security-laboratories/","kind":"Nonprofit","aka":["ISL"],"w":2,"x":507.1,"y":694.6},{"id":"O-0180","k":"O","l":"Lucid Computing","d":"A company offering attested, confidential-computing AI clusters; it hosts the Sovereignty Certificates location specification and runs a verification research programme.","h":"/organizations/lucid-computing/","kind":"Company","w":9,"x":678,"y":529.1},{"id":"O-0202","k":"O","l":"Machine Intelligence Research Institute","d":"A nonprofit focused on preventing human extinction from artificial superintelligence; its Technical Governance Team publishes designs and analyses for verifying AI agreements.","h":"/organizations/machine-intelligence-research-institute/","kind":"Nonprofit","aka":["MIRI"],"w":17,"x":-668.5,"y":541.1},{"id":"O-0140","k":"O","l":"NVIDIA","d":"An accelerated-computing company whose Hopper and Blackwell data-centre GPUs offer a confidential-computing mode with hardware attestation.","h":"/organizations/nvidia/","kind":"Company","w":7,"x":642.5,"y":-571.7},{"id":"O-0205","k":"O","l":"Oxford Martin AI Governance Initiative","d":"A research programme at the University of Oxford that studies AI governance from technical and policy angles and hosts the Hardware AI Governance Lab.","h":"/organizations/oxford-martin-ai-governance-initiative/","kind":"Academic","aka":["AIGI","Oxford Martin AIGI"],"w":6,"x":550.6,"y":-660.7},{"id":"O-0121","k":"O","l":"Pearl Research Labs","d":"A company building AI inference infrastructure and Pearl, a blockchain whose proof-of-useful-work mining is a by-product of GPU matrix multiplication.","h":"/organizations/pearl-research/","kind":"Company","w":5,"x":-518,"y":-686.5},{"id":"O-0102","k":"O","l":"Planet Labs","d":"A company that builds and operates Earth-imaging satellites and sells their imagery; it is one commercial source used to track AI data-centre construction.","h":"/organizations/planet-labs/","kind":"Company","aka":["Planet","Planet Labs PBC"],"w":2,"x":831.8,"y":-218.4},{"id":"O-0100","k":"O","l":"Prime Intellect","d":"A company offering an integrated compute, training, inference and sandbox stack; developer of TOPLOC, a hashing scheme for verifying LLM inference.","h":"/organizations/prime-intellect/","kind":"Company","w":7,"x":-315.1,"y":800.2},{"id":"O-0200","k":"O","l":"RAND","d":"A nonprofit, nonpartisan research organization; its reports cover verification of international AI agreements, hardware-enabled governance mechanisms and secure inference data centres.","h":"/organizations/rand/","kind":"Research organization","w":8,"x":855,"y":-92.7},{"id":"O-0160","k":"O","l":"Singapore AI Safety Hub (SASH)","d":"An independent nonprofit building Singapore and Asia's AI safety field; with international partners, it develops a confidential network logger for inference verification.","h":"/organizations/singapore-ai-safety-hub/","kind":"Nonprofit","aka":["SASH"],"w":4,"x":598.2,"y":-617.9},{"id":"O-0141","k":"O","l":"Tinfoil","d":"A company offering AI inference inside secure hardware enclaves, with remote attestation that clients can check; developer of the Modelwrap model-identity tool.","h":"/organizations/tinfoil/","kind":"Company","w":8,"x":-761,"y":-400.7},{"id":"O-0142","k":"O","l":"University of Cambridge","d":"A UK university; researchers in its Department of Computer Science and Technology developed Attestable Audits, AI benchmarks run and attested inside trusted execution environments.","h":"/organizations/university-of-cambridge/","kind":"Academic","w":6,"x":-788.7,"y":-343},{"id":"O-0122","k":"O","l":"University of Waterloo","d":"A university in Waterloo, Ontario, Canada, whose researchers developed zkLLM, a zero-knowledge proof system for large language model inference.","h":"/organizations/university-of-waterloo/","kind":"Academic","w":4,"x":-779.5,"y":363.4},{"id":"O-0203","k":"O","l":"Verifiable Compute Foundation","d":"An independent nonprofit that, according to Lucid Computing, decides who may use a bare-metal GPU cluster offered free for AI verification research.","h":"/organizations/verifiable-compute-foundation/","kind":"Nonprofit","aka":["VCF"],"w":0,"x":860,"y":0},{"id":"K-0017","k":"K","l":"Compartmentalization","d":"Dividing a facility's accelerators into isolated groups with restricted communication between them, so that no group can join a larger prohibited workload.","h":"/concepts/compartmentalization/","aka":["pods","compute compartments"],"w":10,"x":270.4,"y":222.2},{"id":"K-0024","k":"K","l":"Cryptographic commitment","d":"A way to fix a value now without revealing it, so that it can later be opened and shown not to have changed.","h":"/concepts/cryptographic-commitment/","aka":["commitment scheme","hash commitment"],"w":24,"x":-332.8,"y":-108.2},{"id":"K-0019","k":"K","l":"Evidence binding","d":"Tying verification evidence to the specific device, workload, data and time it describes, so it cannot be substituted, replayed or misattributed.","h":"/concepts/evidence-binding/","aka":["binding","attribution of evidence"],"w":14,"x":-254.1,"y":-240.7},{"id":"K-0023","k":"K","l":"FLOP accounting","d":"Estimating or verifying how many floating-point operations a training run or other workload used, often to compare against a threshold in a rule.","h":"/concepts/flop-accounting/","aka":["training compute accounting","compute thresholds"],"w":11,"x":-98.8,"y":-335.8},{"id":"K-0007","k":"K","l":"Hardware-enabled mechanism (HEM)","d":"A governance or verification function built into AI chips or closely attached hardware, such as usage reporting, location attestation or enforced limits.","h":"/concepts/hardware-enabled-mechanism/","aka":["HEM","hardware-enabled governance mechanism","on-chip mechanism"],"w":10,"x":168.8,"y":-306.6},{"id":"K-0025","k":"K","l":"Inference and training workloads","d":"Training updates a model's weights from data; inference runs fixed weights to produce outputs, and their different resource use underpins several verification methods.","h":"/concepts/inference-and-training-workloads/","aka":["training vs inference"],"w":12,"x":319.3,"y":-143.3},{"id":"K-0021","k":"K","l":"Interconnect bandwidth","d":"The data rate of links between accelerators or groups of them; large-scale training needs far more of it than inference, so limiting it constrains workloads.","h":"/concepts/interconnect-bandwidth/","aka":["chip-to-chip bandwidth","network bandwidth"],"w":11,"x":297.2,"y":184.9},{"id":"K-0014","k":"K","l":"Network tap","d":"A device that copies the traffic on a network link for inspection without disrupting it; proposed for checking what AI data centres compute.","h":"/concepts/network-tap/","aka":["TAP","traffic tap"],"w":15,"x":238.9,"y":255.8},{"id":"K-0008","k":"K","l":"Numerical nondeterminism","d":"Differences between runs, or between machines, in the results of the same AI computation, because floating-point rounding depends on the order of operations.","h":"/concepts/numerical-nondeterminism/","aka":["floating-point nondeterminism","non-reproducibility"],"w":16,"x":-329.6,"y":117.6},{"id":"K-0003","k":"K","l":"Positive and negative claims","d":"A positive claim asserts that something is present or happened; a negative claim, that an activity or resource is absent; a mixed claim, both.","h":"/concepts/positive-and-negative-claims/","aka":["negative claim","positive claim","mixed claim"],"w":9,"x":256,"y":-238.7},{"id":"K-0011","k":"K","l":"Proof of (useful) work","d":"Evidence that a party spent a given amount of computation; in useful variants, the same work also solves a problem someone wants solved.","h":"/concepts/proof-of-useful-work/","aka":["proof of work","PoW","proof of useful work","PoUW"],"w":5,"x":-220.4,"y":-271.9},{"id":"K-0012","k":"K","l":"Proof of space","d":"A protocol in which a prover shows that it is dedicating a given amount of storage or memory, rather than computation, to a task.","h":"/concepts/proof-of-space/","aka":["proof of storage capacity","proof of secure erasure","memory challenge"],"w":7,"x":-342.2,"y":73.4},{"id":"K-0001","k":"K","l":"Prover","d":"The party that makes a claim about its own AI hardware, models or workloads and supplies the evidence a verifier checks.","h":"/concepts/prover/","w":17,"x":-349.5,"y":-18},{"id":"K-0009","k":"K","l":"Recomputation","d":"Checking a claimed computation by re-running all of it, or a random sample, on hardware the verifier trusts and comparing the results.","h":"/concepts/recomputation/","aka":["re-execution","replay"],"w":21,"x":-148.9,"y":316.7},{"id":"K-0004","k":"K","l":"Remote attestation","d":"A process in which a device sends signed evidence about its state, such as software measurements, so a remote party can judge its trustworthiness.","h":"/concepts/remote-attestation/","aka":["attestation"],"w":19,"x":-283.4,"y":-205.3},{"id":"K-0005","k":"K","l":"Root of trust","d":"A component that anchors security functions such as measurement, storage and reporting, and must be trusted because its misbehaviour cannot be detected.","h":"/concepts/root-of-trust/","aka":["RoT","hardware root of trust"],"w":19,"x":34.3,"y":-348.3},{"id":"K-0020","k":"K","l":"Sampling and assurance","d":"Checking a random sample of accelerators, workload segments or outputs rather than all of them, so that violations are caught with a calculable probability.","h":"/concepts/sampling-and-assurance/","aka":["random sampling","spot checks","statistical assurance"],"w":24,"x":-189.1,"y":294.5},{"id":"K-0013","k":"K","l":"Side channel","d":"An unintended path by which information leaks from a system through effects of its operation, such as timing, power draw or electromagnetic emissions.","h":"/concepts/side-channel/","aka":["side-channel attack","covert channel"],"w":15,"x":335.3,"y":-100.2},{"id":"K-0015","k":"K","l":"Tamper evidence and tamper resistance","d":"Tamper evidence makes interference detectable; tamper resistance makes it difficult or costly; tamper response reacts to it, often by erasing secrets.","h":"/concepts/tamper-evidence/","aka":["tamper evidence","tamper resistance","tamper response","anti-tamper"],"w":10,"x":349.9,"y":-9.7},{"id":"K-0018","k":"K","l":"Threat model","d":"An explicit statement of who might attack a system, what they can do, and which threats the design covers or leaves out of scope.","h":"/concepts/threat-model/","aka":["adversary model"],"w":21,"x":203.3,"y":284.9},{"id":"K-0006","k":"K","l":"Trusted execution environment (TEE)","d":"An execution area protected by the processor that keeps the data inside confidential and unaltered, and the code unaltered, even from the host's own software.","h":"/concepts/trusted-execution-environment/","aka":["TEE","enclave","confidential computing","confidential VM"],"w":14,"x":-315.8,"y":-150.9},{"id":"K-0016","k":"K","l":"Undeclared compute","d":"AI-relevant hardware, or uses of declared hardware, that a prover has not reported, and that verification must therefore detect or rule out.","h":"/concepts/undeclared-compute/","aka":["dark compute","hidden compute","covert compute"],"w":20,"x":164.3,"y":309.1},{"id":"K-0002","k":"K","l":"Verifier","d":"The party that examines evidence supplied by, or collected about, a prover and decides whether the prover's claim holds.","h":"/concepts/verifier/","w":18,"x":-344.2,"y":-63.7},{"id":"K-0022","k":"K","l":"Weight exfiltration","d":"Unauthorized copying of a model's trained parameters out of the environment meant to contain them, by theft or through covert channels.","h":"/concepts/weight-exfiltration/","aka":["model weight theft","data exfiltration"],"w":11,"x":63.2,"y":344.3},{"id":"K-0010","k":"K","l":"Zero-knowledge proof","d":"A cryptographic protocol by which a prover convinces a verifier that a statement is true while revealing nothing beyond the fact that it is true.","h":"/concepts/zero-knowledge-proof/","aka":["ZKP","zkSNARK","SNARK"],"w":12,"x":-348.9,"y":27.9},{"id":"S-1109","k":"S","l":"Zhang et al. (2022)","n":"\"Adversarial Examples\" for Proof-of-Learning","d":"R. Zhang, J. Liu, Y. Ding, Z. Wang et al. · 2022 · 2022 IEEE Symposium on Security and Privacy (SP)","h":"/sources/zhang-adversarial-examples-proof-of-learning/","tier":"A","kind":"Peer-reviewed","w":0,"x":-976.1,"y":-462.1},{"id":"S-1814","k":"S","l":"contributors (2025)","n":"[Feature]: Batch Invariant Feature and Performance Optimization (vLLM issue #27433)","d":"vLLM project contributors · 2025 · GitHub (vllm-project/vllm issues)","h":"/sources/vllm-batch-invariance-tracking-issue/","tier":"C","kind":"Forum / discussion","w":0,"x":-768.9,"y":758.4},{"id":"S-0047","k":"S","l":"Joud et al. (2023)","n":"A Practical Introduction to Side-Channel Extraction of Deep Neural Network Parameters","d":"R. Joud, P.-A. Moëllic, S. Pontié, J.-B. Rigaud · 2023 · 21st International Conference on Smart Card Research and Advanced Applications (CARDIS 2022), LNCS 13820, pp. 45–65","h":"/sources/joud-practical-side-channel-extraction/","tier":"A","kind":"Peer-reviewed","w":0,"x":1061.8,"y":-197.2},{"id":"S-1206","k":"S","l":"Tinfoil (2026)","n":"A primer on secure enclaves","d":"Tinfoil · 2026 · Tinfoil documentation","h":"/sources/tinfoil-docs-secure-enclave-primer/","tier":"B","kind":"Documentation","w":1,"x":-788.6,"y":-737.9},{"id":"S-1100","k":"S","l":"Peng et al. (2026)","n":"A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning","d":"Z. Peng, C. Zhao, T. Wang, G. Liao et al. · 2026 · Artificial Intelligence Review, vol. 59, no. 7, article 157","h":"/sources/peng-survey-zkp-verifiable-ml/","tier":"A","kind":"Peer-reviewed","w":0,"x":-1071.9,"y":131.9},{"id":"S-0018","k":"S","l":"Cankaya (2026)","n":"A System Overview for Near-Term, Low-Trust AI Compute Verification","d":"N. Cankaya · 2026 · Machine Intelligence Research Institute","h":"/sources/cankaya-system-overview-low-trust-compute-verification/","tier":"B","kind":"Technical report","w":1,"x":-539.5,"y":935.6},{"id":"S-2007","k":"S","l":"Glaser et al. (2014)","n":"A zero-knowledge protocol for nuclear warhead verification","d":"A. Glaser, B. Barak, R. J. Goldston · 2014 · Nature 510, 497–502","h":"/sources/glaser-zero-knowledge-warhead-verification/","tier":"A","kind":"Peer-reviewed","w":0,"x":1079.2,"y":42},{"id":"S-1818","k":"S","l":"About us: Centre for the Governance of…","n":"About us: Centre for the Governance of AI (GovAI)","d":"2026 · Centre for the Governance of AI","h":"/sources/govai-about/","tier":"B","kind":"Documentation","w":1,"x":972,"y":-470.7},{"id":"S-1705","k":"S","l":"About: Oxford Martin AIGI","n":"About: Oxford Martin AIGI","d":"2026 · Oxford Martin AI Governance Initiative","h":"/sources/oxford-martin-aigi-about/","tier":"B","kind":"Documentation","w":1,"x":705,"y":-818.2},{"id":"S-1005","k":"S","l":"Karvonen (2025)","n":"adamkarvonen/difr (GitHub repository)","d":"A. Karvonen · 2025 · GitHub","h":"/sources/karvonen-difr-code/","tier":"B","kind":"Code","w":0,"x":-516.8,"y":948.3},{"id":"S-1507","k":"S","l":"Kezins (2026)","n":"Adversarial Entropy Inflation Against Gumbel-Based Inference Verification","d":"N. Kezins · 2026 · arXiv","h":"/sources/kezins-adversarial-entropy-inflation/","tier":"B","kind":"Preprint","w":0,"x":-269.8,"y":1045.8},{"id":"S-1008","k":"S","l":"Design (2026)","n":"AI 2040 Plan A — Verification SITREP","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-plan-a-verification-sitrep/","tier":"C","kind":"Blog / article","w":1,"x":-13.8,"y":1079.9},{"id":"S-0008","k":"S","l":"Forum (2025)","n":"AI Security RFDs","d":"AI Security Forum · 2025 · AI Security Forum","h":"/sources/ai-security-forum-rfds/","tier":"C","kind":"Forum / discussion","w":0,"x":1049,"y":-256.8},{"id":"S-2010","k":"S","l":"Harack (2026)","n":"AI Verification: Infrastructure for Prosperity, Governance, and Peace","d":"B. Harack · 2026 · Lawfare","h":"/sources/harack-ai-verification-infrastructure/","tier":"C","kind":"Blog / article","w":0,"x":1075.7,"y":95.8},{"id":"S-1007","k":"S","l":"Design (2026)","n":"Amodo-Design/Inference-Recomputation-Prototype (GitHub repository)","d":"Amodo Design · 2026 · GitHub","h":"/sources/amodo-inference-recomputation-prototype-code/","tier":"B","kind":"Code","w":1,"x":-39.8,"y":1079.3},{"id":"S-1321","k":"S","l":"Design (2026)","n":"Amodo-Design/PoSE-Memory-Wiping (GitHub repository)","d":"Amodo Design · 2026 · GitHub","h":"/sources/amodo-pose-memory-wiping-code/","tier":"B","kind":"Code","w":1,"x":510.5,"y":951.7},{"id":"S-0063","k":"S","l":"Scher et al. (2025)","n":"An International Agreement to Prevent the Premature Creation of Artificial Superintelligence","d":"A. Scher, D. Abecassis, P. Barnett, B. Abeyta · 2025 · Machine Intelligence Research Institute","h":"/sources/scher-agreement-prevent-premature-asi/","tier":"B","kind":"Technical report","w":1,"x":394.5,"y":-1005.4},{"id":"S-0052","k":"S","l":"Staat et al. (2022)","n":"Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems","d":"P. Staat, J. Tobisch, C. Zenger, C. Paar · 2022 · 2022 IEEE Symposium on Security and Privacy","h":"/sources/staat-anti-tamper-radio/","tier":"A","kind":"Peer-reviewed","w":0,"x":815.4,"y":-708.2},{"id":"S-0009","k":"S","l":"Schnabl et al. (2025)","n":"Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments","d":"C. Schnabl, D. Hugenroth, B. Marino, A. R. Beresford · 2025 · ICML 2025 Workshop on Technical AI Governance","h":"/sources/schnabl-attestable-audits/","tier":"B","kind":"Preprint","w":1,"x":-1057,"y":-221.9},{"id":"S-1504","k":"S","l":"Rinberg & Penchas (2026)","n":"Auditor-in-a-Box: Tools for Third-Party Auditing","d":"R. Rinberg, B. Penchas · 2026 · LessWrong","h":"/sources/rinberg-auditor-in-a-box/","tier":"C","kind":"Blog / article","w":0,"x":-1076.9,"y":81.1},{"id":"S-1207","k":"S","l":"Tinfoil (2026)","n":"Backend infrastructure","d":"Tinfoil · 2026 · Tinfoil documentation","h":"/sources/tinfoil-docs-attestation-architecture/","tier":"B","kind":"Documentation","w":1,"x":-953.2,"y":-507.8},{"id":"S-0043","k":"S","l":"Horvath et al. (2025)","n":"BarraCUDA: Edge GPUs do Leak DNN Weights","d":"P. Horvath, L. Chmielewski, L. Weissbart, L. Batina et al. · 2025 · 34th USENIX Security Symposium","h":"/sources/horvath-barracuda/","tier":"A","kind":"Peer-reviewed","w":0,"x":982.5,"y":-448.5},{"id":"S-1013","k":"S","l":"project (2026)","n":"Batch Invariance (vLLM documentation)","d":"vLLM project · 2026 · vLLM documentation (GitHub, docs/features/batch_invariance.md)","h":"/sources/vllm-batch-invariance-docs/","tier":"B","kind":"Documentation","w":0,"x":-731.5,"y":794.5},{"id":"S-1210","k":"S","l":"Meulemeester et al. (2026)","n":"Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing","d":"J. De Meulemeester, D. Oswald, I. Verbauwhede, J. Van Bulck · 2026 · 47th IEEE Symposium on Security and Privacy (S&P 2026)","h":"/sources/de-meulemeester-battering-ram/","tier":"A","kind":"Peer-reviewed","w":0,"x":-1079,"y":-46.6},{"id":"S-1804","k":"S","l":"Selmanaj (2026)","n":"Beyond Prompt Injection: Hacking Apple's Private Cloud Compute","d":"D. Selmanaj · 2026 · Sentry blog","h":"/sources/selmanaj-hacking-apple-pcc/","tier":"C","kind":"Blog / article","w":0,"x":-47.7,"y":-1078.9},{"id":"S-0020","k":"S","l":"Cankaya (2026)","n":"Bit-Exact AI Inference Verification Without Performance Tradeoffs","d":"N. Cankaya · 2026 · ICML 2026 Workshop on Technical AI Governance Research","h":"/sources/cankaya-bit-exact-inference-verification/","tier":"B","kind":"Preprint","w":0,"x":-583.3,"y":909},{"id":"S-1611","k":"S","l":"Nassernia (2025)","n":"Boost GPU Memory Performance with No Code Changes Using NVIDIA CUDA MPS","d":"S. Nassernia · 2025 · NVIDIA Technical Blog","h":"/sources/nassernia-cuda-mps-gpu-memory-performance/","tier":"B","kind":"Blog / article","w":1,"x":184.2,"y":-1064.2},{"id":"S-2011","k":"S","l":"Essix (2024)","n":"BWC at 50: Taking Bold Steps to Secure the Future","d":"G. Essix · 2024 · NTI","h":"/sources/nti-bwc-at-50/","tier":"C","kind":"Blog / article","w":0,"x":1074,"y":113.8},{"id":"S-1604","k":"S","l":"Consortium (2022)","n":"Common Terminology for Confidential Computing","d":"Confidential Computing Consortium · 2022 · Confidential Computing Consortium","h":"/sources/ccc-common-terminology-confidential-computing/","tier":"B","kind":"Technical report","w":0,"x":-871.3,"y":-638.2},{"id":"S-0065","k":"S","l":"Chan (2026)","n":"Components of a Frontier AI Slowdown","d":"A. Chan · 2026 · A Strange Attractor","h":"/sources/chan-components-frontier-ai-slowdown/","tier":"C","kind":"Blog / article","w":0,"x":1075.1,"y":-102.4},{"id":"S-0053","k":"S","l":"Sastry et al. (2024)","n":"Computing Power and the Governance of Artificial Intelligence","d":"G. Sastry, L. Heim, H. Belfield, M. Anderljung et al. · 2024 · arXiv","h":"/sources/sastry-computing-power-governance-ai/","tier":"B","kind":"Preprint","w":2,"x":1031.9,"y":-318.7},{"id":"S-1201","k":"S","l":"Apsey et al. (2023)","n":"Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI","d":"E. Apsey, P. Rogers, M. O'Connor, R. Nertney · 2023 · NVIDIA Technical Blog","h":"/sources/apsey-confidential-computing-h100-gpus/","tier":"C","kind":"Blog / article","w":1,"x":418.6,"y":-995.6},{"id":"S-1817","k":"S","l":"Anthropic & Labs (2025)","n":"Confidential Inference via Trusted Virtual Machines","d":"Anthropic, Pattern Labs · 2025 · Anthropic research","h":"/sources/anthropic-confidential-inference-trusted-vms/","tier":"C","kind":"Blog / article","w":0,"x":-320.5,"y":-1031.4},{"id":"S-0011","k":"S","l":"Ding et al. (2026)","n":"Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance","d":"S. Ding, E. Lee, R. Cheng, D. Kang · 2026 · ICML 2026 Workshop on Technical AI Governance Research","h":"/sources/ding-cove/","tier":"B","kind":"Preprint","w":0,"x":-1027.6,"y":332.3},{"id":"S-1505","k":"S","l":"covehub (2026)","n":"Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance (reference implementation)","d":"covehub · 2026 · GitHub","h":"/sources/ding-cove-code/","tier":"B","kind":"Code","w":0,"x":-1035.2,"y":307.7},{"id":"S-1410","k":"S","l":"Halstead & Larsen (2026)","n":"Covert AI Projects","d":"B. Halstead, T. Larsen · 2026 · AI 2040","h":"/sources/halstead-covert-ai-projects/","tier":"C","kind":"Blog / article","w":1,"x":1002.6,"y":401.5},{"id":"S-1805","k":"S","l":"Authority) (2026)","n":"CVE-2026-20685 (Apple Private Cloud Compute Server Software)","d":"Apple (CVE Numbering Authority) · 2026 · CVE Program","h":"/sources/cve-2026-20685/","tier":"B","kind":"Documentation","w":0,"x":260.5,"y":-1048.1},{"id":"S-1807","k":"S","l":"Labs (2025)","n":"DeepProve-1: The First zkML System to Prove a Full LLM Inference","d":"Lagrange Labs · 2025 · Lagrange blog","h":"/sources/lagrange-deepprove-1/","tier":"C","kind":"Blog / article","w":0,"x":-949.2,"y":515.2},{"id":"S-1011","k":"S","l":"DeepSeek-AI (2026)","n":"DeepSeek-V4: Towards Highly Efficient Million-Token Context Intelligence","d":"DeepSeek-AI · 2026 · arXiv","h":"/sources/deepseek-v4/","tier":"B","kind":"Technical report","w":0,"x":-605,"y":894.7},{"id":"S-0046","k":"S","l":"Gao et al. (2024)","n":"DeepTheft: Stealing DNN Model Architectures through Power Side Channel","d":"Y. Gao, H. Qiu, Z. Zhang, B. Wang et al. · 2024 · 2024 IEEE Symposium on Security and Privacy","h":"/sources/gao-deeptheft/","tier":"A","kind":"Peer-reviewed","w":0,"x":1025.2,"y":-339.8},{"id":"S-1009","k":"S","l":"He & Lab (2025)","n":"Defeating Nondeterminism in LLM Inference","d":"H. He, Thinking Machines Lab · 2025 · Thinking Machines Lab: Connectionism","h":"/sources/he-defeating-nondeterminism-llm-inference/","tier":"C","kind":"Blog / article","w":0,"x":-857,"y":657.2},{"id":"S-0039","k":"S","l":"Chen et al. (2025)","n":"Detecting Anomalies in Machine Learning Infrastructure via Hardware Telemetry","d":"Z. Chen, S. Chien, P. Qian, N. Zilberman · 2025 · arXiv","h":"/sources/chen-detecting-anomalies-hardware-telemetry/","tier":"B","kind":"Preprint","w":0,"x":1071.9,"y":132},{"id":"S-0059","k":"S","l":"Seferis & Fist (2026)","n":"Detecting Compute Structuring in AI Governance Is Likely Feasible","d":"E. Seferis, T. Fist · 2026 · Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment)","h":"/sources/seferis-detecting-compute-structuring/","tier":"A","kind":"Peer-reviewed","w":0,"x":1070.9,"y":-139.7},{"id":"S-0040","k":"S","l":"Gangwal et al. (2020)","n":"Detecting Covert Cryptomining Using HPC","d":"A. Gangwal, S. G. Piazzetta, G. Lain, M. Conti · 2020 · Cryptology and Network Security – CANS 2020, LNCS 12579, pp. 344–364","h":"/sources/gangwal-detecting-covert-cryptomining/","tier":"A","kind":"Peer-reviewed","w":0,"x":1069.5,"y":150.2},{"id":"S-0037","k":"S","l":"Rahman & Tajdari (2026)","n":"Detecting Hidden ML Training With Zero-Overhead Telemetry","d":"R. Rahman, S. Tajdari · 2026 · ICML 2026 Workshop on Technical AI Governance Research","h":"/sources/rahman-detecting-hidden-ml-training/","tier":"B","kind":"Preprint","w":0,"x":743.5,"y":-783.3},{"id":"S-0016","k":"S","l":"Karvonen et al. (2025)","n":"DiFR: Inference Verification Despite Nondeterminism","d":"A. Karvonen, D. Reuter, R. Rinberg, L. Marks et al. · 2025 · arXiv","h":"/sources/karvonen-difr/","tier":"B","kind":"Preprint","w":0,"x":-647.3,"y":864.5},{"id":"S-1314","k":"S","l":"Douillard et al. (2024)","n":"DiLoCo: Distributed Low-Communication Training of Language Models","d":"A. Douillard, Q. Feng, A. A. Rusu, R. Chhaparia et al. · 2024 · ICML 2024 Workshop on Advancing Neural Network Training (WANT)","h":"/sources/douillard-diloco/","tier":"B","kind":"Preprint","w":0,"x":274.9,"y":1044.4},{"id":"S-0060","k":"S","l":"Rahman (2026)","n":"Does Distributed Training Undermine Compute Governance?","d":"R. Rahman · 2026 · ICML 2026 Workshop on Technical AI Governance Research","h":"/sources/rahman-distributed-training-compute-governance/","tier":"B","kind":"Preprint","w":0,"x":201.7,"y":1061},{"id":"S-1503","k":"S","l":"Penchas et al. (2026)","n":"Enabling Verifiably-Scoped Monitoring through Large Language Models and Trusted Compute","d":"B. Penchas, G. Zhao, R. Rinberg · 2026 · ICML 2026 Workshop on Technical AI Governance Research","h":"/sources/penchas-verifiably-scoped-monitoring/","tier":"B","kind":"Preprint","w":0,"x":-1074.7,"y":106.5},{"id":"S-0017","k":"S","l":"Design (2026)","n":"Example Schemes for Verifying High-Stakes AI Agreements","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-example-schemes-high-stakes-ai-agreements/","tier":"C","kind":"Blog / article","w":1,"x":-455.1,"y":979.4},{"id":"S-0069","k":"S","l":"President (2025)","n":"Executive Order 14148: Initial Rescissions of Harmful Executive Orders and Actions","d":"Executive Office of the President · 2025 · Federal Register, 90 FR 8237 (document 2025-01901, published 2025-01-28)","h":"/sources/eo-14148-initial-rescissions/","tier":"A","kind":"Government document","w":0,"x":-595.8,"y":-900.8},{"id":"S-1802","k":"S","l":"(SEAR) (2026)","n":"Expanding Private Cloud Compute","d":"Apple Security Engineering and Architecture (SEAR) · 2026 · Apple Security Research blog","h":"/sources/apple-expanding-pcc-2026/","tier":"C","kind":"Blog / article","w":0,"x":-73.7,"y":-1077.5},{"id":"S-1702","k":"S","l":"Experiments: Lucid Labs","n":"Experiments: Lucid Labs","d":"2026 · Lucid Computing","h":"/sources/lucid-experimentation-cluster/","tier":"B","kind":"Documentation","w":1,"x":931.2,"y":547},{"id":"S-1203","k":"S","l":"Institute (2023)","n":"Exploration of secure hardware solutions for safe AI deployment","d":"Future of Life Institute · 2023 · Future of Life Institute","h":"/sources/fli-hardware-backed-compute-governance/","tier":"C","kind":"Blog / article","w":1,"x":18.6,"y":-1079.8},{"id":"S-0066","k":"S","l":"Ammann & Dalrymple (2025)","n":"Faster AI Diffusion Through Hardware-Based Verification","d":"N. Ammann, D. Dalrymple · 2025 · Institute for Progress","h":"/sources/ammann-faster-ai-diffusion-hardware-verification/","tier":"C","kind":"Blog / article","w":0,"x":1076.7,"y":-84},{"id":"S-1300","k":"S","l":"Cankaya et al. (2026)","n":"Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors","d":"N. Cankaya, J. Kryś, J. Ng, L. Marks et al. · 2026 · arXiv","h":"/sources/cankaya-fingerprinting-ai-cluster-io/","tier":"B","kind":"Preprint","w":1,"x":879.7,"y":-626.5},{"id":"S-1312","k":"S","l":"Design (2026)","n":"Fitting a Network TAP to our Inference Verification Prototype","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-network-tap-inference-verification-prototype/","tier":"C","kind":"Blog / article","w":1,"x":1010.5,"y":381.2},{"id":"S-0035","k":"S","l":"Petrie et al. (2025)","n":"Flexible Hardware-Enabled Guarantees for AI Compute","d":"J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv","h":"/sources/petrie-flexible-hardware-enabled-guarantees/","tier":"B","kind":"Preprint","w":0,"x":544.6,"y":-932.6},{"id":"S-0055","k":"S","l":"Anwar et al. (2024)","n":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","d":"U. Anwar, A. Saparov, J. Rando, D. Paleka et al. · 2024 · Transactions on Machine Learning Research","h":"/sources/anwar-foundational-challenges-assuring-alignment-safety/","tier":"A","kind":"Peer-reviewed","w":0,"x":1068.3,"y":-158.7},{"id":"S-1103","k":"S","l":"Attestable (2026)","n":"From Verifiability to Model-Weight Security","d":"Attestable · 2026 · Attestable blog","h":"/sources/attestable-model-weight-security/","tier":"C","kind":"Blog / article","w":1,"x":-1068.5,"y":157.3},{"id":"S-0003","k":"S","l":"Brundage et al. (2026)","n":"Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies","d":"M. Brundage, N. Dreksler, A. Homewood, S. McGregor et al. · 2026 · arXiv","h":"/sources/brundage-frontier-ai-auditing/","tier":"B","kind":"Preprint","w":0,"x":-1080,"y":4.8},{"id":"S-1812","k":"S","l":"Gensyn (2026)","n":"gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository)","d":"Gensyn · 2026 · GitHub","h":"/sources/gensyn-ree-code/","tier":"B","kind":"Code","w":0,"x":-1015.3,"y":-368.2},{"id":"S-1511","k":"S","l":"Project (2026)","n":"Get Involved in Verification","d":"AI Futures Project · 2026 · AI 2040","h":"/sources/ai-futures-get-involved-verification/","tier":"C","kind":"Blog / article","w":1,"x":1037.1,"y":301.5},{"id":"S-0058","k":"S","l":"Heim et al. (2024)","n":"Governing Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation","d":"L. Heim, T. Fist, J. Egan, S. Huang et al. · 2024 · Oxford Martin AI Governance Initiative","h":"/sources/heim-governing-through-cloud/","tier":"B","kind":"Technical report","w":1,"x":685.1,"y":-834.9},{"id":"S-1403","k":"S","l":"Tee & Happel (2026)","n":"GPU Fingerprinting for Location Verification","d":"W. Tee, J. Happel · 2026 · arXiv","h":"/sources/tee-gpu-fingerprinting-location-verification/","tier":"B","kind":"Preprint","w":0,"x":965.4,"y":484.1},{"id":"S-0034","k":"S","l":"Petrie (2025)","n":"Guaranteeable Memory: An HBM-Based Chiplet for Verifiable AI Workloads","d":"J. Petrie · 2025 · ICML 2025 Workshop on Technical AI Governance","h":"/sources/petrie-guaranteeable-memory/","tier":"B","kind":"Preprint","w":0,"x":357.5,"y":-1019.1},{"id":"S-0010","k":"S","l":"Dhar et al. (2025)","n":"GuardAIn: Protecting Emerging Generative AI Workloads on Heterogeneous NPU","d":"A. Dhar, C. Thorens, L. M. Lazier, L. Cavigelli · 2025 · 2025 IEEE Symposium on Security and Privacy","h":"/sources/dhar-guardain/","tier":"A","kind":"Peer-reviewed","w":0,"x":-394,"y":-1005.5},{"id":"S-0072","k":"S","l":"Rescorla et al. (2003)","n":"Guidelines for Writing RFC Text on Security Considerations (RFC 3552, BCP 72)","d":"E. Rescorla, B. Korver, Internet Architecture Board · 2003 · Internet Engineering Task Force","h":"/sources/rescorla-rfc-3552-security-considerations/","tier":"A","kind":"Standard","w":0,"x":599,"y":898.6},{"id":"S-1508","k":"S","l":"Rinberg et al. (2026)","n":"Haiku to Opus in Just 10 bits: LLMs Unlock Large Compression Gains","d":"R. Rinberg, A. M. Carrell, S. Henniger, N. Carlini et al. · 2026 · arXiv","h":"/sources/rinberg-haiku-to-opus-compression/","tier":"B","kind":"Preprint","w":0,"x":44.7,"y":1079.1},{"id":"S-1703","k":"S","l":"Hardware AI Governance Lab","n":"Hardware AI Governance Lab","d":"2026 · Oxford Martin AI Governance Initiative","h":"/sources/oxford-hardware-ai-governance-lab/","tier":"B","kind":"Documentation","w":1,"x":644.1,"y":-866.9},{"id":"S-0036","k":"S","l":"Ma et al. (2026)","n":"Hardware Mechanisms to Dynamically Throttle AI Performance","d":"H. Ma, J. Forzani, L. Malek, D. Wentzlaff · 2026 · arXiv","h":"/sources/ma-hardware-mechanisms-dynamically-throttle-ai/","tier":"B","kind":"Preprint","w":0,"x":148.2,"y":-1069.8},{"id":"S-0057","k":"S","l":"Kulp et al. (2024)","n":"Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090","d":"G. Kulp, D. Gonzales, E. Smith, L. Heim et al. · 2024 · RAND Corporation","h":"/sources/kulp-hardware-enabled-governance-mechanisms/","tier":"B","kind":"Technical report","w":1,"x":459.8,"y":-977.2},{"id":"S-0006","k":"S","l":"O'Gara et al. (2025)","n":"Hardware-Enabled Mechanisms for Verifying Responsible AI Development","d":"A. O'Gara, G. Kulp, W. Hodgkins, J. Petrie et al. · 2025 · arXiv","h":"/sources/ogara-hardware-enabled-verifying-responsible-ai/","tier":"B","kind":"Preprint","w":0,"x":122.4,"y":-1073},{"id":"S-0007","k":"S","l":"Ansari (2026)","n":"Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification","d":"S. Ansari · 2026 · arXiv","h":"/sources/ansari-hardware-level-governance-ai-compute/","tier":"B","kind":"Preprint","w":0,"x":1052.2,"y":243.5},{"id":"S-1502","k":"S","l":"Levin et al. (2025)","n":"Has My System Prompt Been Used? Large Language Model Prompt Membership Inference","d":"R. Levin, V. Cherepanova, A. Hans, A. Schwarzschild et al. · 2025 · arXiv","h":"/sources/levin-prompt-detective/","tier":"B","kind":"Preprint","w":0,"x":-1079.6,"y":30.3},{"id":"S-1010","k":"S","l":"Badash et al. (2026)","n":"Hawkeye: Reproducing GPU-Level Non-Determinism","d":"E. Badash, D. Boneh, I. Komargodski, M. Srivastava · 2026 · Proceedings of Machine Learning and Systems 8 (MLSys 2026)","h":"/sources/badash-hawkeye/","tier":"A","kind":"Peer-reviewed","w":0,"x":-841,"y":677.6},{"id":"S-1510","k":"S","l":"Comer et al. (2026)","n":"Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering","d":"S. F. Comer, H. Pavela, V. Gandhi, K. Siler-Evans et al. · 2026 · RAND Corporation (Research Report RR-A4827-1)","h":"/sources/comer-highly-secure-inference-data-centers/","tier":"B","kind":"Technical report","w":1,"x":759.6,"y":767.7},{"id":"S-1112","k":"S","l":"Gong et al. (2026)","n":"Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference","d":"C. Gong, B. Liu, M. Li · 2026 · arXiv","h":"/sources/gong-hollow-llm-attack/","tier":"B","kind":"Preprint","w":0,"x":-983.9,"y":445.4},{"id":"S-0013","k":"S","l":"Team (2026)","n":"How Tinfoil Proves Exactly What Model Is Running","d":"Tinfoil Team · 2026 · Tinfoil","h":"/sources/tinfoil-proving-model-identity/","tier":"C","kind":"Blog / article","w":1,"x":-1038.7,"y":-295.7},{"id":"S-1208","k":"S","l":"Tinfoil (2026)","n":"How verification works in Tinfoil","d":"Tinfoil · 2026 · Tinfoil documentation","h":"/sources/tinfoil-docs-verification-in-tinfoil/","tier":"B","kind":"Documentation","w":1,"x":-940.9,"y":-530.2},{"id":"S-2004","k":"S","l":"Agency (2026)","n":"IAEA Safeguards Overview: Comprehensive Safeguards Agreements and Additional Protocols","d":"International Atomic Energy Agency · 2026 · IAEA fact sheet","h":"/sources/iaea-safeguards-overview/","tier":"A","kind":"Government document","w":0,"x":1079.9,"y":-11.6},{"id":"S-0050","k":"S","l":"Corporation (2012)","n":"IBM 4765 Cryptographic Coprocessor Security Module: Security Policy","d":"IBM Corporation · 2012 · NIST Cryptographic Module Validation Program","h":"/sources/ibm-4765-security-policy/","tier":"B","kind":"Technical report","w":0,"x":780.4,"y":-746.6},{"id":"S-0051","k":"S","l":"Mosavirik et al. (2023)","n":"ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection","d":"T. Mosavirik, P. Schaumont, S. Tajik · 2023 · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325","h":"/sources/mosavirik-impedanceverif/","tier":"A","kind":"Peer-reviewed","w":0,"x":798.1,"y":-727.6},{"id":"S-1303","k":"S","l":"Design (2026)","n":"Improving Disk Wiping Speed for Memory Wipes","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-improving-disk-wiping-speed/","tier":"C","kind":"Blog / article","w":1,"x":533.3,"y":939.2},{"id":"S-1319","k":"S","l":"(SASH) (2026)","n":"inference-verification: Inference Verification Prototype","d":"Singapore AI Safety Hub (SASH) · 2026 · GitHub","h":"/sources/sash-inference-verification-repo/","tier":"B","kind":"Code","w":1,"x":724.5,"y":-801},{"id":"S-0042","k":"S","l":"Gregersen et al. (2024)","n":"Input-Dependent Power Usage in GPUs","d":"T. Gregersen, P. Patel, E. Choukse · 2024 · SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis (Sustainable Supercomputing workshop), pp. 1872–1877","h":"/sources/gregersen-input-dependent-power-usage-gpus/","tier":"B","kind":"Preprint","w":0,"x":1063.7,"y":187.1},{"id":"S-1003","k":"S","l":"Team et al. (2025)","n":"INTELLECT-2: A Reasoning Model Trained Through Globally Decentralized Reinforcement Learning","d":"Prime Intellect Team, S. Jaghouar, J. Mattern, J. M. Ong et al. · 2025 · arXiv","h":"/sources/primeintellect-intellect-2/","tier":"B","kind":"Technical report","w":1,"x":-668,"y":848.7},{"id":"S-1706","k":"S","l":"Intelligence Security Laboratories:…","n":"Intelligence Security Laboratories: Building secure infrastructure for transformative AI","d":"2026 · Intelligence Security Laboratories","h":"/sources/intelligence-security-laboratories-home/","tier":"B","kind":"Documentation","w":1,"x":641.6,"y":868.8},{"id":"S-0054","k":"S","l":"Bengio et al. (2025)","n":"International AI Safety Report","d":"Y. Bengio, S. Mindermann, D. Privitera, T. Besiroglu et al. · 2025 · International AI Safety Report","h":"/sources/bengio-international-ai-safety-report-2025/","tier":"B","kind":"Technical report","w":0,"x":1065.3,"y":-177.8},{"id":"S-0061","k":"S","l":"Trager et al. (2023)","n":"International Governance of Civilian AI: A Jurisdictional Certification Approach","d":"R. Trager, B. Harack, A. Reuel, A. Carnegie et al. · 2023 · Centre for the Governance of AI","h":"/sources/trager-international-governance-civilian-ai/","tier":"B","kind":"Technical report","w":2,"x":935.9,"y":-538.9},{"id":"S-1205","k":"S","l":"Aarne & Petrie (2025)","n":"International Security Applications of Flexible Hardware-Enabled Guarantees","d":"O. Aarne, J. Petrie · 2025 · arXiv","h":"/sources/aarne-international-security-applications-flexheg/","tier":"B","kind":"Preprint","w":0,"x":-108.3,"y":-1074.6},{"id":"S-1320","k":"S","l":"(SASH) (2026)","n":"Internationalising AI Verification","d":"Singapore AI Safety Hub (SASH) · 2026 · SASH blog","h":"/sources/sash-internationalising-ai-verification/","tier":"C","kind":"Blog / article","w":1,"x":664.8,"y":-851.1},{"id":"S-1811","k":"S","l":"Gensyn (2025)","n":"Introducing Judge","d":"Gensyn · 2025 · Gensyn news","h":"/sources/gensyn-introducing-judge/","tier":"C","kind":"Blog / article","w":0,"x":-1023.7,"y":-344.2},{"id":"S-1411","k":"S","l":"AI (2025)","n":"Introducing the Frontier Data Centers Hub","d":"Epoch AI · 2025 · Epoch AI","h":"/sources/epoch-frontier-data-centers-hub/","tier":"C","kind":"Blog / article","w":1,"x":1056.4,"y":224.5},{"id":"S-0044","k":"S","l":"Horvath et al. (2026)","n":"Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field","d":"P. Horvath, I. Shumailov, L. Chmielewski, L. Batina et al. · 2026 · IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026)","h":"/sources/horvath-kraken/","tier":"A","kind":"Peer-reviewed","w":0,"x":949.1,"y":-515.4},{"id":"S-1808","k":"S","l":"Labs (2026)","n":"Lagrange-Labs/deep-prove (GitHub repository)","d":"Lagrange Labs · 2026 · GitHub","h":"/sources/lagrange-deep-prove-code/","tier":"B","kind":"Code","w":0,"x":-961.3,"y":492.2},{"id":"S-1014","k":"S","l":"Gond et al. (2026)","n":"LLM-42: Enabling Determinism in LLM Inference with Verified Speculation","d":"R. Gond, A. K. Kamath, R. Ramjee, A. Panwar · 2026 · arXiv","h":"/sources/gond-llm-42/","tier":"B","kind":"Preprint","w":0,"x":-626.3,"y":879.8},{"id":"S-1400","k":"S","l":"Brass & Aarne (2024)","n":"Location Verification for AI Chips","d":"A. Brass, O. Aarne · 2024 · Institute for AI Policy and Strategy","h":"/sources/brass-location-verification-ai-chips/","tier":"B","kind":"Technical report","w":1,"x":985.2,"y":442.6},{"id":"S-1401","k":"S","l":"Brass & Aarne (2025)","n":"Location Verification for AI Chips (issue brief)","d":"A. Brass, O. Aarne · 2025 · Institute for AI Policy and Strategy","h":"/sources/brass-location-verification-issue-brief/","tier":"B","kind":"Technical report","w":1,"x":1042.5,"y":282},{"id":"S-1406","k":"S","l":"Lucid Computing: Verifiable AI. Proven…","n":"Lucid Computing: Verifiable AI. Proven in hardware.","d":"2026 · Lucid Computing","h":"/sources/lucid-computing-homepage/","tier":"B","kind":"Documentation","w":1,"x":918.5,"y":568},{"id":"S-1407","k":"S","l":"Lucid Developer Platform documentation","n":"Lucid Developer Platform documentation","d":"2026 · Lucid Computing","h":"/sources/lucid-developer-platform-docs/","tier":"B","kind":"Documentation","w":1,"x":876.4,"y":631.1},{"id":"S-1701","k":"S","l":"Lucid Labs: the verification flywheel","n":"Lucid Labs: the verification flywheel","d":"2026 · Lucid Computing","h":"/sources/lucid-labs-overview/","tier":"B","kind":"Documentation","w":1,"x":943.3,"y":526},{"id":"S-0005","k":"S","l":"Scher & Thiergart (2025)","n":"Mechanisms to Verify International Agreements About AI Development","d":"A. Scher, L. Thiergart · 2025 · arXiv","h":"/sources/scher-mechanisms-verify-ai-agreements/","tier":"B","kind":"Preprint","w":1,"x":1001.4,"y":-404.4},{"id":"S-1302","k":"S","l":"Design (2026)","n":"Memory Wipes - Performance Analysis","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-memory-wipes-performance-analysis/","tier":"C","kind":"Blog / article","w":1,"x":299.9,"y":1037.5},{"id":"S-1209","k":"S","l":"Tinfoil (2026)","n":"modelwrap: Reproducible dm-verity read-only image of Huggingface models","d":"Tinfoil · 2026 · GitHub","h":"/sources/tinfoil-modelwrap-code/","tier":"B","kind":"Code","w":1,"x":-928,"y":-552.4},{"id":"S-0045","k":"S","l":"Ding et al. (2025)","n":"MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs","d":"R. Ding, T. Xu, X. Shen, A. A. Ding et al. · 2025 · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS 2025)","h":"/sources/ding-moecho/","tier":"A","kind":"Peer-reviewed","w":0,"x":1058,"y":-216.8},{"id":"S-0068","k":"S","l":"Wang (2026)","n":"NanoZK: Privacy-Preserving Verifiable Inference for Large Language Models via Layerwise Zero-Knowledge Proofs","d":"Z. Wang · 2026 · International Conference on Information and Communications Security (ICICS 2026)","h":"/sources/wang-nanozk/","tier":"A","kind":"Peer-reviewed","w":0,"x":-936.5,"y":537.9},{"id":"S-1402","k":"S","l":"Avellar & Grunewald (2026)","n":"Near-Term Verification Methods for AI Chip Exports","d":"B. Avellar, E. Grunewald · 2026 · arXiv","h":"/sources/avellar-near-term-verification-ai-chip-exports/","tier":"B","kind":"Preprint","w":1,"x":994.2,"y":422},{"id":"S-1310","k":"S","l":"Design (2026)","n":"Network Tapping for AI Verification: A Technical Assessment","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-network-tapping-technical-assessment/","tier":"C","kind":"Blog / article","w":1,"x":1024.8,"y":341},{"id":"S-1309","k":"S","l":"Design (2026)","n":"Network Taps — A First Test","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-network-taps-first-test/","tier":"C","kind":"Blog / article","w":1,"x":1031.1,"y":321.1},{"id":"S-1311","k":"S","l":"Design (2026)","n":"Network Traffic Hashing","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-network-traffic-hashing/","tier":"C","kind":"Blog / article","w":1,"x":1017.9,"y":361},{"id":"S-1600","k":"S","l":"Technology (2026)","n":"NIST Computer Security Resource Center (CSRC) Glossary","d":"National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center","h":"/sources/nist-csrc-glossary/","tier":"A","kind":"Government document","w":0,"x":-529.2,"y":-941.4},{"id":"S-1815","k":"S","l":"Su (2024)","n":"Now in General Availability: NVIDIA H100 GPUs in Microsoft Azure Confidential Virtual Machines","d":"C. Su · 2024 · NVIDIA Blog","h":"/sources/nvidia-azure-confidential-h100-ga/","tier":"C","kind":"Blog / article","w":1,"x":44.6,"y":-1079.1},{"id":"S-2001","k":"S","l":"Baker (2023)","n":"Nuclear Arms Control Verification and Lessons for AI Treaties","d":"M. Baker · 2023 · arXiv","h":"/sources/baker-nuclear-arms-control-lessons-ai-treaties/","tier":"B","kind":"Preprint","w":0,"x":1078,"y":-65.8},{"id":"S-1200","k":"S","l":"NVIDIA (2025)","n":"NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper)","d":"NVIDIA · 2025 · NVIDIA documentation","h":"/sources/nvidia-secure-ai-blackwell-hopper-whitepaper/","tier":"B","kind":"Documentation","w":1,"x":285.7,"y":-1041.5},{"id":"S-0064","k":"S","l":"Carlsmith (2026)","n":"On restraining AI development for the sake of safety","d":"J. Carlsmith · 2026 · Joseph Carlsmith","h":"/sources/carlsmith-restraining-ai-development-safety/","tier":"C","kind":"Blog / article","w":0,"x":1073.2,"y":-121},{"id":"S-0014","k":"S","l":"Z (2026)","n":"On TEEs for Privacy-Preserving Monitoring in AI Governance","d":"Gloria Z · 2026 · MIRI Technical Governance Team","h":"/sources/zhao-tees-privacy-preserving-monitoring/","tier":"C","kind":"Blog / article","w":1,"x":-1031.5,"y":-320},{"id":"S-1308","k":"S","l":"Castelluccia et al. (2009)","n":"On the Difficulty of Software-Based Attestation of Embedded Devices","d":"C. Castelluccia, A. Francillon, D. Perito, C. Soriente · 2009 · ACM Conference on Computer and Communications Security (CCS 2009)","h":"/sources/castelluccia-difficulty-software-based-attestation/","tier":"A","kind":"Peer-reviewed","w":0,"x":-806.2,"y":-718.7},{"id":"S-2008","k":"S","l":"Weapons (2023)","n":"OPCW confirms: All declared chemical weapons stockpiles verified as irreversibly destroyed","d":"Organisation for the Prohibition of Chemical Weapons · 2023 · OPCW","h":"/sources/opcw-declared-stockpiles-destroyed/","tier":"A","kind":"Government document","w":0,"x":1078.3,"y":59.9},{"id":"S-0001","k":"S","l":"Reuel et al. (2025)","n":"Open Problems in Technical AI Governance","d":"A. Reuel, B. Bucknall, S. Casper, T. Fist et al. · 2025 · Transactions on Machine Learning Research","h":"/sources/reuel-open-problems-technical-ai-governance/","tier":"A","kind":"Peer-reviewed","w":0,"x":1009.9,"y":-382.7},{"id":"S-1413","k":"S","l":"NVIDIA (2025)","n":"Opt-In NVIDIA Software Enables Data Center Fleet Management","d":"NVIDIA · 2025 · NVIDIA Blog","h":"/sources/nvidia-opt-in-fleet-management-software/","tier":"B","kind":"Blog / article","w":1,"x":1043.8,"y":-277.2},{"id":"S-1707","k":"S","l":"Our Team: Intelligence Security…","n":"Our Team: Intelligence Security Laboratories","d":"2026 · Intelligence Security Laboratories","h":"/sources/intelligence-security-laboratories-team/","tier":"B","kind":"Documentation","w":1,"x":620.5,"y":884},{"id":"S-1102","k":"S","l":"Attestable (2026)","n":"Pacing AI Requires Proof","d":"Attestable · 2026 · Attestable blog","h":"/sources/attestable-pacing-ai-requires-proof/","tier":"C","kind":"Blog / article","w":1,"x":-855.8,"y":-658.8},{"id":"S-0012","k":"S","l":"Chantasantitam et al. (2026)","n":"PAL*M: Property Attestation for Large Generative Models","d":"P. Chantasantitam, A. I. Caulfield, V. Duddu, L. J. Gunn et al. · 2026 · arXiv","h":"/sources/chantasantitam-palm/","tier":"B","kind":"Preprint","w":0,"x":-1069.9,"y":-147},{"id":"S-0073","k":"S","l":"Yang et al. (2023)","n":"Part-time Power Measurements: nvidia-smi's Lack of Attention","d":"Z. Yang, K. Adamek, W. Armour · 2023 · arXiv","h":"/sources/yang-part-time-power-measurements/","tier":"B","kind":"Preprint","w":0,"x":894.5,"y":-605.1},{"id":"S-1105","k":"S","l":"Team (2026)","n":"Pearl Floating Point Scheme Specification","d":"Pearl Research Team · 2026 · Pearl Research Labs","h":"/sources/pearl-floating-point-scheme-specification/","tier":"B","kind":"Technical report","w":1,"x":-679.6,"y":-839.3},{"id":"S-1106","k":"S","l":"Labs (2026)","n":"Pearl INT Whitepaper","d":"Pearl Research Labs · 2026 · Pearl Research Labs","h":"/sources/pearl-int-whitepaper/","tier":"B","kind":"Technical report","w":1,"x":-659.2,"y":-855.5},{"id":"S-1107","k":"S","l":"Labs (2026)","n":"pearl: Monorepo for the Pearl network","d":"Pearl Research Labs · 2026 · GitHub","h":"/sources/pearl-network-monorepo/","tier":"B","kind":"Code","w":1,"x":-638.5,"y":-871.1},{"id":"S-1317","k":"S","l":"Johnston & Garcia (1996)","n":"Physical Security and Tamper-Indicating Devices","d":"R. G. Johnston, A. R. E. Garcia · 1996 · Los Alamos National Laboratory, LA-UR-96-3827","h":"/sources/johnston-physical-security-tamper-indicating-devices/","tier":"B","kind":"Technical report","w":0,"x":992.3,"y":-426.4},{"id":"S-1700","k":"S","l":"PBC (2026)","n":"Planet Reports Financial Results for Second Quarter of Fiscal Year 2027","d":"Planet Labs PBC · 2026 · Business Wire (press release)","h":"/sources/planet-q2-fy2027-financial-results/","tier":"C","kind":"Blog / article","w":1,"x":1017.8,"y":-361.1},{"id":"S-1601","k":"S","l":"Regenscheid (2018)","n":"Platform Firmware Resiliency Guidelines (NIST SP 800-193)","d":"A. Regenscheid · 2018 · National Institute of Standards and Technology","h":"/sources/nist-sp-800-193-platform-firmware-resiliency/","tier":"A","kind":"Government document","w":0,"x":96.5,"y":-1075.7},{"id":"S-1509","k":"S","l":"Greenblatt (2024)","n":"Preventing model exfiltration with upload limits","d":"R. Greenblatt · 2024 · AI Alignment Forum","h":"/sources/greenblatt-upload-limits/","tier":"C","kind":"Forum / discussion","w":0,"x":-91.7,"y":1076.1},{"id":"S-1001","k":"S","l":"Intellect (2025)","n":"PrimeIntellect-ai/toploc (GitHub repository)","d":"Prime Intellect · 2025 · GitHub","h":"/sources/primeintellect-toploc-code/","tier":"B","kind":"Code","w":1,"x":-383.3,"y":1009.7},{"id":"S-1506","k":"S","l":"Abdelghafar & Kulp (2026)","n":"Privacy-Preserving AI Verification via Minimal Information Disclosure","d":"S. Abdelghafar, G. Kulp · 2026 · arXiv","h":"/sources/abdelghafar-minimal-information-disclosure/","tier":"B","kind":"Preprint","w":0,"x":-1042.3,"y":282.9},{"id":"S-1816","k":"S","l":"Yagnik (2025)","n":"Private AI Compute: our next step in building private and helpful AI","d":"J. Yagnik · 2025 · Google blog (The Keyword)","h":"/sources/google-private-ai-compute/","tier":"C","kind":"Blog / article","w":0,"x":-345.2,"y":-1023.3},{"id":"S-1800","k":"S","l":"(SEAR) (2024)","n":"Private Cloud Compute: A new frontier for AI privacy in the cloud","d":"Apple Security Engineering and Architecture (SEAR) · 2024 · Apple Security Research blog","h":"/sources/apple-private-cloud-compute-2024/","tier":"C","kind":"Blog / article","w":0,"x":-573.9,"y":-914.9},{"id":"S-1500","k":"S","l":"Jin et al. (2026)","n":"Proof-of-Guardrail in AI Agents and What (Not) to Trust from It","d":"X. Jin, M. Duan, Q. Lin, A. Chan et al. · 2026 · arXiv","h":"/sources/jin-proof-of-guardrail/","tier":"B","kind":"Preprint","w":0,"x":-1079.8,"y":-20.6},{"id":"S-0027","k":"S","l":"Fang et al. (2023)","n":"Proof-of-Learning is Currently More Broken Than You Think","d":"C. Fang, H. Jia, A. Thudi, M. Yaghini et al. · 2023 · 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023)","h":"/sources/fang-proof-of-learning-broken/","tier":"A","kind":"Peer-reviewed","w":0,"x":-900.7,"y":-595.9},{"id":"S-1111","k":"S","l":"Lab (2021)","n":"Proof-of-Learning: code for Proof-of-Learning: Definitions and Practice","d":"CleverHans Lab · 2021 · GitHub","h":"/sources/jia-proof-of-learning-code/","tier":"B","kind":"Code","w":0,"x":-964.9,"y":-485.1},{"id":"S-0028","k":"S","l":"Jia et al. (2021)","n":"Proof-of-Learning: Definitions and Practice","d":"H. Jia, M. Yaghini, C. A. Choquette-Choo, N. Dullerud et al. · 2021 · 42nd IEEE Symposium on Security and Privacy","h":"/sources/jia-proof-of-learning-definitions-practice/","tier":"A","kind":"Peer-reviewed","w":0,"x":-986.8,"y":-439},{"id":"S-1607","k":"S","l":"Dziembowski et al. (2015)","n":"Proofs of Space","d":"S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak · 2015 · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796)","h":"/sources/dziembowski-proofs-of-space/","tier":"A","kind":"Peer-reviewed","w":0,"x":-914.7,"y":-574.3},{"id":"S-1608","k":"S","l":"Ball et al. (2017)","n":"Proofs of Useful Work","d":"M. Ball, A. Rosen, M. Sabin, P. N. Vasudevan · 2017 · IACR Cryptology ePrint Archive 2017/203","h":"/sources/ball-proofs-of-useful-work/","tier":"B","kind":"Preprint","w":0,"x":-719.2,"y":-805.7},{"id":"S-1609","k":"S","l":"Komargodski et al. (2025)","n":"Proofs of Useful Work from Arbitrary Matrix Multiplication","d":"I. Komargodski, I. Schen, O. Weinstein · 2025 · arXiv","h":"/sources/komargodski-proofs-useful-work-matrix-multiplication/","tier":"B","kind":"Preprint","w":0,"x":-699.6,"y":-822.7},{"id":"S-1101","k":"S","l":"Attestable (2026)","n":"Proving LLMs at Scale","d":"Attestable · 2026 · Attestable blog","h":"/sources/attestable-proving-llms-at-scale/","tier":"C","kind":"Blog / article","w":1,"x":-1064.5,"y":182.6},{"id":"S-2002","k":"S","l":"Reagan (1987)","n":"Remarks on Signing the Intermediate-Range Nuclear Forces Treaty","d":"R. Reagan · 1987 · Ronald Reagan Presidential Library and Museum","h":"/sources/reagan-remarks-signing-inf-treaty/","tier":"A","kind":"Government document","w":0,"x":1078.9,"y":-47.6},{"id":"S-1603","k":"S","l":"Birkholz et al. (2023)","n":"Remote ATtestation procedureS (RATS) Architecture (RFC 9334)","d":"H. Birkholz, D. Thaler, M. Richardson, N. Smith et al. · 2023 · Internet Engineering Task Force (RATS Working Group)","h":"/sources/birkholz-rats-architecture-rfc-9334/","tier":"B","kind":"Technical report","w":0,"x":-1006.4,"y":-392},{"id":"S-1212","k":"S","l":"Schlüter & Shinde (2025)","n":"RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP","d":"B. Schlüter, S. Shinde · 2025 · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)","h":"/sources/schluter-rmpocalypse/","tier":"A","kind":"Peer-reviewed","w":0,"x":-1077.6,"y":-71.3},{"id":"S-1306","k":"S","l":"Ivanov et al. (2023)","n":"SAGE: Software-based Attestation for GPU Execution","d":"A. Ivanov, B. Rothenberger, A. Dethise, M. Canini et al. · 2023 · 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 485–499","h":"/sources/ivanov-sage-gpu-attestation/","tier":"A","kind":"Peer-reviewed","w":0,"x":-839.8,"y":-679.1},{"id":"S-1006","k":"S","l":"Design (2026)","n":"Scaling Recomputation Inference Verification","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-scaling-recomputation-inference-verification/","tier":"C","kind":"Blog / article","w":1,"x":129.8,"y":1072.2},{"id":"S-1304","k":"S","l":"Perito & Tsudik (2010)","n":"Secure Code Update for Embedded Devices via Proofs of Secure Erasure","d":"D. Perito, G. Tsudik · 2010 · Computer Security – ESORICS 2010, LNCS 6345, pp. 643–662","h":"/sources/perito-proofs-of-secure-erasure/","tier":"A","kind":"Peer-reviewed","w":0,"x":-872.6,"y":636.4},{"id":"S-1315","k":"S","l":"Immler et al. (2019)","n":"Secure Physical Enclosures from Covers with Tamper-Resistance","d":"V. Immler, J. Obermaier, K. K. Ng, F. X. Ke et al. · 2019 · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96","h":"/sources/immler-secure-physical-enclosures-covers/","tier":"A","kind":"Peer-reviewed","w":0,"x":832.2,"y":-688.3},{"id":"S-0056","k":"S","l":"Aarne et al. (2024)","n":"Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing","d":"O. Aarne, T. Fist, C. Withers · 2024 · Center for a New American Security","h":"/sources/aarne-secure-governable-chips/","tier":"B","kind":"Technical report","w":1,"x":575.7,"y":-913.8},{"id":"S-1610","k":"S","l":"Nevo et al. (2024)","n":"Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models","d":"S. Nevo, D. Lahav, A. Karpur, Y. Bar-On et al. · 2024 · RAND Corporation","h":"/sources/nevo-securing-ai-model-weights/","tier":"B","kind":"Technical report","w":1,"x":682.7,"y":836.9},{"id":"S-1605","k":"S","l":"Technology (2001)","n":"Security Requirements for Cryptographic Modules (FIPS PUB 140-2)","d":"National Institute of Standards and Technology · 2001 · National Institute of Standards and Technology","h":"/sources/nist-fips-140-2/","tier":"A","kind":"Standard","w":0,"x":1038.1,"y":-297.8},{"id":"S-1801","k":"S","l":"(SEAR) (2024)","n":"Security research on Private Cloud Compute","d":"Apple Security Engineering and Architecture (SEAR) · 2024 · Apple Security Research blog","h":"/sources/apple-pcc-security-research-2024/","tier":"C","kind":"Blog / article","w":0,"x":209.8,"y":-1059.4},{"id":"S-1213","k":"S","l":"AMD (2025)","n":"SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020)","d":"AMD · 2025 · AMD product security bulletin","h":"/sources/amd-sb-3020-rmp-initialization/","tier":"B","kind":"Documentation","w":0,"x":-1061.9,"y":-197},{"id":"S-0041","k":"S","l":"Latif et al. (2025)","n":"Single-Node Power Demand During AI Training: Measurements on an 8-GPU NVIDIA H100 System","d":"I. Latif, A. C. Newkirk, M. R. Carbone, A. Munir et al. · 2025 · IEEE Access, vol. 13, pp. 61740–61747","h":"/sources/latif-empirical-ai-training-power-demand/","tier":"A","kind":"Peer-reviewed","w":0,"x":1066.8,"y":168.6},{"id":"S-0032","k":"S","l":"Bursuc et al. (2024)","n":"Software-Based Memory Erasure with Relaxed Isolation Requirements","d":"S. Bursuc, R. Gil-Pons, S. Mauw, R. Trujillo-Rasua · 2024 · 2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024)","h":"/sources/bursuc-software-based-memory-erasure/","tier":"A","kind":"Peer-reviewed","w":0,"x":-1010.5,"y":381.2},{"id":"S-1405","k":"S","l":"Sovereignty Certificates Working Group","n":"Sovereignty Certificates Working Group","d":"2026 · sovcert.org","h":"/sources/sovereignty-certificates-working-group-site/","tier":"B","kind":"Documentation","w":0,"x":905.2,"y":589.1},{"id":"S-1404","k":"S","l":"Group (2025)","n":"Sovereignty Certificates: draft specification, version 0.1.0","d":"Sovereignty Certificates Working Group · 2025 · GitHub (Lucid-Computing/sovereignty-certificate-specification)","h":"/sources/sovereignty-certificates-specification/","tier":"B","kind":"Documentation","w":1,"x":954.7,"y":505},{"id":"S-0038","k":"S","l":"Cankaya (2026)","n":"Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses","d":"N. Cankaya · 2026 · MIRI Technical Governance Team","h":"/sources/cankaya-suppressing-side-channels/","tier":"C","kind":"Blog / article","w":1,"x":440.9,"y":985.9},{"id":"S-1307","k":"S","l":"Seshadri et al. (2004)","n":"SWATT: SoftWare-based ATTestation for Embedded Devices","d":"A. Seshadri, A. Perrig, L. van Doorn, P. Khosla · 2004 · IEEE Symposium on Security and Privacy 2004","h":"/sources/seshadri-swatt/","tier":"A","kind":"Peer-reviewed","w":0,"x":-823.2,"y":-699.1},{"id":"S-1004","k":"S","l":"Intellect (2025)","n":"SYNTHETIC-2","d":"Prime Intellect · 2025 · Prime Intellect blog","h":"/sources/primeintellect-synthetic-2/","tier":"C","kind":"Blog / article","w":1,"x":-431.4,"y":990.1},{"id":"S-1318","k":"S","l":"Johnston (2001)","n":"Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials","d":"R. G. Johnston · 2001 · The Nonproliferation Review, Spring 2001, pp. 102–114","h":"/sources/johnston-tamper-detection-safeguards-treaty-monitoring/","tier":"A","kind":"Peer-reviewed","w":0,"x":864.4,"y":-647.5},{"id":"S-1316","k":"S","l":"Smartt & Gastelum (2015)","n":"Tamper-Indicating Enclosures, A Current Survey","d":"H. A. Smartt, Z. N. Gastelum · 2015 · Sandia National Laboratories, SAND2015-4251C","h":"/sources/smartt-tamper-indicating-enclosures-survey/","tier":"B","kind":"Technical report","w":0,"x":848.6,"y":-668.1},{"id":"S-1602","k":"S","l":"Group (2017)","n":"TCG Glossary","d":"Trusted Computing Group · 2017 · Trusted Computing Group","h":"/sources/tcg-glossary/","tier":"B","kind":"Documentation","w":0,"x":-443.2,"y":-984.9},{"id":"S-1204","k":"S","l":"Petrie & Aarne (2025)","n":"Technical Options for Flexible Hardware-Enabled Guarantees","d":"J. Petrie, O. Aarne · 2025 · arXiv","h":"/sources/petrie-technical-options-flexheg/","tier":"B","kind":"Preprint","w":0,"x":-134.1,"y":-1071.6},{"id":"S-1202","k":"S","l":"Chuang et al. (2026)","n":"TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition","d":"J. Chuang, A. Seto, N. Berrios, S. van Schaik et al. · 2026 · 2026 IEEE Symposium on Security and Privacy (SP)","h":"/sources/chuang-tee-fail/","tier":"A","kind":"Peer-reviewed","w":0,"x":-1051.5,"y":-246.6},{"id":"S-2009","k":"S","l":"Initiative (2003)","n":"The Biological Weapons Convention","d":"Nuclear Threat Initiative · 2003 · NTI","h":"/sources/nti-biological-weapons-convention/","tier":"B","kind":"Technical report","w":0,"x":1077.2,"y":77.8},{"id":"S-2006","k":"S","l":"Commission (2026)","n":"The Comprehensive Nuclear-Test-Ban Treaty (CTBT)","d":"CTBTO Preparatory Commission · 2026 · CTBTO","h":"/sources/ctbto-the-treaty/","tier":"A","kind":"Government document","w":0,"x":1079.7,"y":24.2},{"id":"S-0031","k":"S","l":"Cankaya (2026)","n":"The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use","d":"N. Cankaya · 2026 · The Datacenter Lie Detector","h":"/sources/cankaya-secure-network-taps/","tier":"C","kind":"Blog / article","w":0,"x":975.6,"y":463.3},{"id":"S-2005","k":"S","l":"Commission (2026)","n":"The International Monitoring System","d":"CTBTO Preparatory Commission · 2026 · CTBTO","h":"/sources/ctbto-international-monitoring-system/","tier":"A","kind":"Government document","w":0,"x":1080,"y":6.3},{"id":"S-0049","k":"S","l":"Obermaier & Immler (2018)","n":"The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond","d":"J. Obermaier, V. Immler · 2018 · Journal of Hardware and Systems Security","h":"/sources/obermaier-physical-security-enclosures/","tier":"A","kind":"Peer-reviewed","w":0,"x":762.2,"y":-765.2},{"id":"S-1313","k":"S","l":"Design (2026)","n":"The Tray as a Bandwidth Boundary","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-tray-bandwidth-boundary/","tier":"C","kind":"Blog / article","w":1,"x":407.1,"y":1000.3},{"id":"S-0071","k":"S","l":"Basu (2026)","n":"The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol","d":"A. Basu · 2026 · arXiv","h":"/sources/basu-usefulness-gap-pearl/","tier":"B","kind":"Preprint","w":0,"x":-617.3,"y":-886.2},{"id":"S-1813","k":"S","l":"Lab (2025)","n":"thinking-machines-lab/batch_invariant_ops (GitHub repository)","d":"Thinking Machines Lab · 2025 · GitHub","h":"/sources/thinking-machines-batch-invariant-ops-code/","tier":"B","kind":"Code","w":0,"x":-750.4,"y":776.7},{"id":"S-0033","k":"S","l":"Monfared et al. (2026)","n":"Timing and Memory Telemetry on GPUs for AI Governance","d":"S. K. Monfared, F. Ganji, D. E. Holcomb, S. Tajik · 2026 · arXiv","h":"/sources/monfared-timing-memory-telemetry-gpus/","tier":"B","kind":"Preprint","w":0,"x":-7.4,"y":-1080},{"id":"S-0030","k":"S","l":"Choi et al. (2023)","n":"Tools for Verifying Neural Models' Training Data","d":"D. Choi, Y. Shavit, D. K. Duvenaud · 2023 · Advances in Neural Information Processing Systems 36 (NeurIPS 2023)","h":"/sources/choi-tools-verifying-training-data/","tier":"A","kind":"Peer-reviewed","w":0,"x":-886.3,"y":-617.2},{"id":"S-1000","k":"S","l":"Ong et al. (2025)","n":"TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference","d":"J. M. Ong, M. Di Ferrante, A. Pazdera, R. Garner et al. · 2025 · Proceedings of the 42nd International Conference on Machine Learning (PMLR 267), pp. 47196-47211","h":"/sources/ong-toploc/","tier":"A","kind":"Peer-reviewed","w":1,"x":-358.9,"y":1018.6},{"id":"S-1002","k":"S","l":"Intellect (2025)","n":"TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference (blog post)","d":"Prime Intellect · 2025 · Prime Intellect blog","h":"/sources/primeintellect-toploc-blog/","tier":"C","kind":"Blog / article","w":1,"x":-407.5,"y":1000.2},{"id":"S-1012","k":"S","l":"Team (2025)","n":"Towards Deterministic Inference in SGLang and Reproducible RL Training","d":"The SGLang Team · 2025 · LMSYS Org blog","h":"/sources/sglang-deterministic-inference/","tier":"C","kind":"Blog / article","w":0,"x":-712.2,"y":811.9},{"id":"S-1409","k":"S","l":"Krawec (2026)","n":"Tracking Hyperscale AI Data Center Growth with Satellite Imagery","d":"C. Krawec · 2026 · Federation of American Scientists","h":"/sources/krawec-tracking-hyperscale-satellite-imagery/","tier":"B","kind":"Technical report","w":0,"x":960.9,"y":-493},{"id":"S-1301","k":"S","l":"Computing (2026)","n":"Traffic Shaping for Workload Classification","d":"Lucid Computing · 2026 · Lucid Computing (Substack)","h":"/sources/lucid-traffic-shaping-workload-classification/","tier":"C","kind":"Blog / article","w":1,"x":555.7,"y":926},{"id":"S-2003","k":"S","l":"America & Republics (1972)","n":"Treaty between the United States of America and the Union of Soviet Socialist Republics on the Limitation of Anti-Ballistic Missile Systems","d":"United States of America, Union of Soviet Socialist Republics · 1972 · United Nations Treaty Series, vol. 944, No. 13446","h":"/sources/abm-treaty-1972/","tier":"A","kind":"Government document","w":0,"x":1079.6,"y":-29.6},{"id":"S-0022","k":"S","l":"Waiwitlikhit et al. (2024)","n":"Trustless Audits without Revealing Data or Models","d":"S. Waiwitlikhit, I. Stoica, Y. Sun, T. Hashimoto et al. · 2024 · 41st International Conference on Machine Learning (ICML 2024)","h":"/sources/waiwitlikhit-trustless-audits/","tier":"A","kind":"Peer-reviewed","w":0,"x":-1066.2,"y":-172.1},{"id":"S-1408","k":"S","l":"Cankaya (2025)","n":"TSMC most definitely has a golden record of all AI chips it made","d":"N. Cankaya · 2025 · Substack (Naci Cankaya)","h":"/sources/cankaya-tsmc-golden-record/","tier":"C","kind":"Blog / article","w":0,"x":891.1,"y":610.1},{"id":"S-0048","k":"S","l":"Design (2026)","n":"Understanding Data Center Power Delivery","d":"Amodo Design · 2026 · Amodo Design","h":"/sources/amodo-understanding-data-center-power-delivery/","tier":"C","kind":"Blog / article","w":1,"x":861,"y":652},{"id":"S-1803","k":"S","l":"Dittmar et al. (2026)","n":"Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence","d":"Y. Dittmar, M. J. Stephan, T. Völkl, M. Hollick et al. · 2026 · Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '26)","h":"/sources/dittmar-unlocking-apple-pcc/","tier":"A","kind":"Peer-reviewed","w":0,"x":235.2,"y":-1054.1},{"id":"S-1810","k":"S","l":"Ersoy (2025)","n":"Verde Verification System In Production","d":"O. Ersoy · 2025 · Gensyn research blog","h":"/sources/gensyn-verde-in-production/","tier":"C","kind":"Blog / article","w":0,"x":-972.9,"y":468.9},{"id":"S-1809","k":"S","l":"Arun et al. (2025)","n":"Verde: Verification via Refereed Delegation for Machine Learning Programs","d":"A. Arun, A. St. Arnaud, A. Titov, B. Wilcox et al. · 2025 · arXiv","h":"/sources/arun-verde-refereed-delegation/","tier":"B","kind":"Preprint","w":0,"x":-1019.3,"y":356.9},{"id":"S-0026","k":"S","l":"Reuter et al. (2026)","n":"Verifiable constraints on frontier training via proofs of compartmentalization","d":"D. Reuter, L. Marks, A. Carlucci, J. Ng et al. · 2026 · ICML 2026 Workshop on Technical AI Governance Research","h":"/sources/reuter-proofs-compartmentalization/","tier":"B","kind":"Preprint","w":0,"x":1053.7,"y":-236.7},{"id":"S-0024","k":"S","l":"South et al. (2024)","n":"Verifiable evaluations of machine learning models using zkSNARKs","d":"T. South, A. Camuto, S. Jain, S. Nguyen et al. · 2024 · arXiv","h":"/sources/south-verifiable-evaluations-zksnarks/","tier":"B","kind":"Preprint","w":0,"x":-1054.6,"y":232.9},{"id":"S-1704","k":"S","l":"Ilhan et al. (2026)","n":"Verifiable Semiconductor Manufacturing","d":"A. Ilhan, C. Withers, H. Gietz, B. Harack · 2026 · Oxford Martin AI Governance Initiative","h":"/sources/ilhan-verifiable-semiconductor-manufacturing/","tier":"B","kind":"Technical report","w":2,"x":623.1,"y":-882.2},{"id":"S-1501","k":"S","l":"SaharaLabsAI (2026)","n":"Verifiable-ClawGuard: proof-of-guardrail reference code","d":"SaharaLabsAI · 2026 · GitHub","h":"/sources/sahara-verifiable-clawguard-code/","tier":"B","kind":"Code","w":0,"x":-1078.6,"y":55.7},{"id":"S-0004","k":"S","l":"Harack et al. (2025)","n":"Verification for International AI Governance","d":"B. Harack, R. F. Trager, A. Reuel, D. Manheim et al. · 2025 · Oxford Martin AI Governance Initiative","h":"/sources/harack-verification-international-ai-governance/","tier":"B","kind":"Technical report","w":1,"x":-551.7,"y":-928.4},{"id":"S-0062","k":"S","l":"Wasil et al. (2024)","n":"Verification methods for international AI agreements","d":"A. R. Wasil, T. Reed, J. W. Miller, P. Barnett · 2024 · arXiv","h":"/sources/wasil-verification-methods-international-ai-agreements/","tier":"B","kind":"Preprint","w":0,"x":70.6,"y":-1077.7},{"id":"S-0067","k":"S","l":"Dean (2026)","n":"Verification Plan","d":"R. Dean · 2026 · AI 2040","h":"/sources/dean-verification-plan/","tier":"C","kind":"Blog / article","w":1,"x":662.3,"y":853.1},{"id":"S-0019","k":"S","l":"Petrie & Mühlhäuser (2026)","n":"Verifying AI Compute by Bounding Unexplained Information Exfiltration","d":"J. Petrie, Y. Mühlhäuser · 2026 · ICML 2026 Workshop on Technical AI Governance Research","h":"/sources/petrie-bounding-unexplained-information-exfiltration/","tier":"B","kind":"Preprint","w":0,"x":-65.8,"y":1078},{"id":"S-0002","k":"S","l":"Baker et al. (2025)","n":"Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment","d":"M. Baker, G. Kulp, O. Marks, M. Brundage et al. · 2025 · RAND Corporation","h":"/sources/baker-verifying-international-agreements-ai/","tier":"B","kind":"Technical report","w":1,"x":1047.6,"y":262.7},{"id":"S-1512","k":"S","l":"Milton et al. (2026)","n":"Verifying international AI deals: Plan A, the state-of-play, and what you can do to help","d":"T. Milton, S. Reynolds, C. Jacobi, J. Foster · 2026 · Amodo (Substack)","h":"/sources/milton-verifying-international-ai-deals/","tier":"C","kind":"Blog / article","w":1,"x":820,"y":702.8},{"id":"S-0015","k":"S","l":"Rinberg et al. (2025)","n":"Verifying LLM Inference to Detect Model Weight Exfiltration","d":"R. Rinberg, A. Karvonen, A. Hoover, D. Reuter et al. · 2025 · arXiv","h":"/sources/rinberg-verifying-llm-inference-weight-exfiltration/","tier":"B","kind":"Preprint","w":0,"x":-329,"y":1028.7},{"id":"S-0029","k":"S","l":"Shavit (2023)","n":"What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring","d":"Y. Shavit · 2023 · arXiv","h":"/sources/shavit-catch-a-chinchilla/","tier":"B","kind":"Preprint","w":0,"x":331.3,"y":-1027.9},{"id":"S-1211","k":"S","l":"Seto et al. (2025)","n":"WireTap: Breaking Server SGX via DRAM Bus Interposition","d":"A. Seto, O. K. Duran, S. Amer, J. Chuang et al. · 2025 · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)","h":"/sources/seto-wiretap/","tier":"A","kind":"Peer-reviewed","w":0,"x":-369.7,"y":-1014.7},{"id":"S-1412","k":"S","l":"Gargiulo & Kulp (2026)","n":"Workload Identification with Physical Side Channels for AI Governance","d":"S. Gargiulo, G. Kulp · 2026 · arXiv","h":"/sources/gargiulo-workload-identification-physical-side-channels/","tier":"B","kind":"Preprint","w":0,"x":1060.2,"y":205.7},{"id":"S-0025","k":"S","l":"Peigné et al. (2026)","n":"Zero knowledge verification for frontier AI training is possible","d":"P. Peigné, K. Nguyen, P. Wang · 2026 · arXiv","h":"/sources/peigne-zero-knowledge-frontier-training/","tier":"B","kind":"Preprint","w":0,"x":-1045.4,"y":-271.3},{"id":"S-1110","k":"S","l":"Abbaszadeh et al. (2024)","n":"Zero-Knowledge Proofs of Training for Deep Neural Networks","d":"K. Abbaszadeh, C. Pappas, J. Katz, D. Papadopoulos · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330","h":"/sources/abbaszadeh-zero-knowledge-proofs-of-training/","tier":"A","kind":"Peer-reviewed","w":0,"x":-996.8,"y":-415.6},{"id":"S-1108","k":"S","l":"Sun (2024)","n":"zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models","d":"H. Sun · 2024 · GitHub; archived on Zenodo","h":"/sources/sun-zkllm-code/","tier":"B","kind":"Code","w":1,"x":-994.3,"y":421.6},{"id":"S-0023","k":"S","l":"Sun et al. (2024)","n":"zkLLM: Zero Knowledge Proofs for Large Language Models","d":"H. Sun, J. Li, H. Zhang · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024)","h":"/sources/sun-zkllm/","tier":"A","kind":"Peer-reviewed","w":1,"x":-1048.7,"y":257.9},{"id":"S-0021","k":"S","l":"Chen et al. (2024)","n":"ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs","d":"B.-J. Chen, S. Waiwitlikhit, I. Stoica, D. Kang · 2024 · 19th European Conference on Computer Systems (EuroSys 2024)","h":"/sources/chen-zkml/","tier":"A","kind":"Peer-reviewed","w":0,"x":-923.3,"y":560.3},{"id":"S-0070","k":"S","l":"Casal et al. (2025)","n":"Zkonduit EZKL Security Assessment","d":"F. Casal, T. Hess, L. Bourtoule, S. Hussain et al. · 2025 · Trail of Bits (prepared for Zkonduit Inc.)","h":"/sources/trailofbits-ezkl-security-assessment/","tier":"B","kind":"Technical report","w":0,"x":-1059.8,"y":207.8},{"id":"S-1806","k":"S","l":"Inc. (2026)","n":"zkonduit/ezkl (GitHub repository)","d":"Zkonduit Inc. · 2026 · GitHub","h":"/sources/zkonduit-ezkl-code/","tier":"B","kind":"Code","w":0,"x":-1073.1,"y":-121.9},{"id":"S-1606","k":"S","l":"Benarroch et al. (2022)","n":"ZKProof Community Reference","d":"D. Benarroch, L. Brandão, M. Maller, E. Tromer · 2022 · ZKProof","h":"/sources/zkproof-community-reference/","tier":"B","kind":"Technical report","w":0,"x":-1075.7,"y":-96.6},{"id":"T.coverage-hidden-compute","k":"T","l":"Coverage & hidden compute","d":"Challenge theme","h":"/browse/?theme=coverage-hidden-compute","w":44,"x":-69.3,"y":343.1},{"id":"T.hardware-trust","k":"T","l":"Hardware trust","d":"Challenge theme","h":"/browse/?theme=hardware-trust","w":46,"x":285,"y":-203.1},{"id":"T.evidence-binding","k":"T","l":"Evidence binding","d":"Challenge theme","h":"/browse/?theme=evidence-binding","w":20,"x":-142,"y":-319.9},{"id":"T.protocol-soundness","k":"T","l":"Protocol soundness","d":"Challenge theme","h":"/browse/?theme=protocol-soundness","w":27,"x":-311.4,"y":159.8},{"id":"T.adversarial-validation","k":"T","l":"Adversarial validation","d":"Challenge theme","h":"/browse/?theme=adversarial-validation","w":61,"x":-259.2,"y":235.2},{"id":"T.capacity-bounds","k":"T","l":"Capacity bounds","d":"Challenge theme","h":"/browse/?theme=capacity-bounds","w":9,"x":-182.8,"y":-298.5},{"id":"T.performance-compatibility","k":"T","l":"Performance & compatibility","d":"Challenge theme","h":"/browse/?theme=performance-compatibility","w":67,"x":-287.8,"y":199.2},{"id":"T.privacy-leakage","k":"T","l":"Privacy & leakage","d":"Challenge theme","h":"/browse/?theme=privacy-leakage","w":23,"x":-226.1,"y":267.2},{"id":"T.access-governance","k":"T","l":"Access & governance","d":"Challenge theme","h":"/browse/?theme=access-governance","w":22,"x":345.6,"y":-55.4},{"id":"G.on-chip","k":"G","l":"On-chip & hardware-enabled","short":"On-chip","d":"Mechanisms built into accelerators or their firmware: trusted execution, attestation, hardware-enabled governance, on-chip telemetry and limits.","h":"/categories/on-chip/","cat":"on-chip","w":6,"a0":-2.020617421790156,"a1":-1.1209752317996373,"cx":4.653657836759942e-14,"x":0,"cy":-760,"y":-760},{"id":"G.off-chip-devices","k":"G","l":"Off-chip devices & sensors","short":"Off-chip devices","d":"Retrofittable devices outside the accelerator: network taps and certifiers, power and analog sensors, tamper-evident enclosures.","h":"/categories/off-chip-devices/","cat":"off-chip-devices","w":4,"a0":-1.0509752317996373,"a1":-0.38399912542735626,"cx":572.6298050110845,"x":572.6,"cy":-499.6950133961388,"y":-499.7},{"id":"G.remote-sensing","k":"G","l":"Remote & side-channel sensing","short":"Sensing","d":"Inferring activity from outside or from physical signals: detecting data centres, classifying workloads from power or other emissions.","h":"/categories/remote-sensing/","cat":"remote-sensing","w":2,"a0":-0.31399912542735625,"a1":0.12031089732668715,"cx":756.4388472567815,"x":756.4,"cy":-73.48653183292559,"y":-73.5},{"id":"G.accounting-provenance","k":"G","l":"Compute accounting & provenance","short":"Accounting","d":"Establishing what compute exists, where it is and what it can do: chip registries, manufacturing records, location verification, capacity bounds.","h":"/categories/accounting-provenance/","cat":"accounting-provenance","w":3,"a0":0.19031089732668716,"a1":0.7021762812868098,"cx":685.5767376229754,"x":685.6,"cy":328.0008183377564,"y":328},{"id":"G.isolation-architecture","k":"G","l":"Isolation & system architectures","short":"Isolation & architecture","d":"Ways of arranging or constraining a facility so that other checks become possible: bandwidth limits, compartmentalization, memory wiping, secure facilities, whole verification stacks.","h":"/categories/isolation-architecture/","cat":"isolation-architecture","w":7,"a0":0.7721762812868098,"a1":1.7493738324834076,"cx":231.85995824190232,"x":231.9,"cy":723.768581636467,"y":723.8},{"id":"G.cryptographic-computational","k":"G","l":"Cryptographic & computational","short":"Crypto / compute","d":"Protocols that check computation itself: recomputation, zero-knowledge proofs, proofs of learning, proofs of work, challenge-response.","h":"/categories/cryptographic-computational/","cat":"cryptographic-computational","w":19,"a0":1.8193738324834077,"a1":4.1925678853894315,"cx":-753.0212636102681,"x":-753,"cy":102.7568807953763,"y":102.8},{"id":"M-0014.B1","k":"B","l":"No cap that a verifier can check has been implemented…","n":"No cap that a verifier can check has been implemented or red-teamed.","d":"Adversarial validation","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#blocker-1","host":"M-0014","theme":"adversarial-validation","cat":"isolation-architecture","w":2,"x":116.4,"y":461.1},{"id":"M-0014.B2","k":"B","l":"The verifier must know that all traffic leaving a pod…","n":"The verifier must know that all traffic leaving a pod crosses the capped, monitored links.","d":"Coverage & hidden compute","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#blocker-2","host":"M-0014","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":114.3,"y":436},{"id":"M-0014.B3","k":"B","l":"Shaping devices and routing assignments must be trusted…","n":"Shaping devices and routing assignments must be trusted by both parties; Amodo has not yet fully analysed resilience to a compromised DPU.","d":"Hardware trust","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#blocker-3","host":"M-0014","theme":"hardware-trust","cat":"isolation-architecture","w":3,"x":108.2,"y":472.2},{"id":"M-0014.B4","k":"B","l":"Advances in low-communication training could shrink the…","n":"Advances in low-communication training could shrink the margin that the cap enforces.","d":"Capacity bounds","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#blocker-4","host":"M-0014","theme":"capacity-bounds","cat":"isolation-architecture","w":2,"x":75.6,"y":479.9},{"id":"M-0014.F1","k":"F","l":"Low-communication training reduces the bandwidth training needs","n":"Low-communication training reduces the bandwidth training needs","d":"DiLoCo matched fully synchronous training on 8 workers while communicating 500 times less. Rahman writes that this family of methods theoretically allows large-scale training with less than 100 Mbps. Lucid includes these methods in its bounds, but notes that…","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#flaw-1","host":"M-0014","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":62.1,"y":472.7},{"id":"M-0014.F2","k":"F","l":"Operator control of pod routing collapses the bound","n":"Operator control of pod routing collapses the bound","d":"Lucid's analysis finds that if the operator can freely assign pods to routers, it could dedicate a whole cell of 100 or more pods to one pipeline stage. The bound then falls to about 90–220x uncompressed and as low as about 25x with compression. The proposed…","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#flaw-2","host":"M-0014","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":54.6,"y":461.8},{"id":"M-0014.F3","k":"F","l":"Undeclared local storage raises per-pod capacity","n":"Undeclared local storage raises per-pod capacity","d":"More memory or storage per pod helps an adversary. Lucid requires per-pod storage to be declared, capped and physically inspected.","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#flaw-3","host":"M-0014","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":53.7,"y":448.2},{"id":"M-0014.F4","k":"F","l":"Training within one pod is not covered","n":"Training within one pod is not covered","d":"Lucid's bounds concern pre-training models larger than the pods are sized for. Training models that fit in one pod, fine-tuning and reinforcement-learning post-training within one pod are outside the modelled threat.","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#flaw-4","host":"M-0014","cat":"isolation-architecture","sev":"significant","fk":"Open question","st":"open","w":1,"x":118.7,"y":448.3},{"id":"M-0014.F5","k":"F","l":"Parallel scale-up switches are hard enforcement points","n":"Parallel scale-up switches are hard enforcement points","d":"In GB200 topologies, GPUs reach GPUs in other nodes through NVSwitches without a NIC on the path. Amodo notes that limits are hard to enforce there because many switches work in parallel, so compromising one or two would bypass the limit.","h":"/mechanisms/bandwidth-limits-and-compartmentalization/#flaw-5","host":"M-0014","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":93.5,"y":480.2},{"id":"M-0024.B1","k":"B","l":"The prover's compute must be isolated so that all…","n":"The prover's compute must be isolated so that all traffic passes through the verifier's interlock; any unmonitored path voids the bound.","d":"Coverage & hidden compute","h":"/mechanisms/bounding-unexplained-information/#blocker-1","host":"M-0024","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":-13.1,"y":548.6},{"id":"M-0024.B2","k":"B","l":"Physical side channels need separate suppression, and…","n":"Physical side channels need separate suppression, and one design treats a low residual bandwidth, rather than zero, as the realistic target.","d":"Coverage & hidden compute","h":"/mechanisms/bounding-unexplained-information/#blocker-2","host":"M-0024","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":-30,"y":552.1},{"id":"M-0024.B3","k":"B","l":"Tolerance for numerical nondeterminism sets the size of…","n":"Tolerance for numerical nondeterminism sets the size of the residual channel; bit-exact replay would remove it but needs full hardware and software metadata.","d":"Protocol soundness","h":"/mechanisms/bounding-unexplained-information/#blocker-3","host":"M-0024","theme":"protocol-soundness","cat":"isolation-architecture","w":3,"x":-58.1,"y":537.6},{"id":"M-0024.B4","k":"B","l":"Recomputation over confidential weights and inputs…","n":"Recomputation over confidential weights and inputs needs a protected setting: prover recomputation in a verifier-controlled enclosure, verifier recomputation in a prover-controlled enclosure, or zero-knowledge proofs.","d":"Privacy & leakage","h":"/mechanisms/bounding-unexplained-information/#blocker-4","host":"M-0024","theme":"privacy-leakage","cat":"isolation-architecture","w":2,"x":-62.6,"y":525.4},{"id":"M-0024.B5","k":"B","l":"No prototype of the facility-level architecture exists…","n":"No prototype of the facility-level architecture exists to red-team.","d":"Adversarial validation","h":"/mechanisms/bounding-unexplained-information/#blocker-5","host":"M-0024","theme":"adversarial-validation","cat":"isolation-architecture","w":2,"x":-60.3,"y":512.4},{"id":"M-0024.F1","k":"F","l":"Prompt-controlled entropy inflation widens the covert channel","n":"Prompt-controlled entropy inflation widens the covert channel","d":"Gumbel-based inference verification tolerates token choices that honest GPU nondeterminism could produce, and the size of that tolerated set grows with the model's output entropy. Kezins, an independent researcher, showed that an adversary who controls the…","h":"/mechanisms/bounding-unexplained-information/#flaw-1","host":"M-0024","cat":"isolation-architecture","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":1.3,"y":516.1},{"id":"M-0024.F2","k":"F","l":"Information the declared computation explains is not bounded","n":"Information the declared computation explains is not bounded","d":"The bound limits unexplained bits only. Outputs that the declared computation fully explains can still carry valuable information: a compression study notes that an adversary with inference access can extract more proprietary information per bit than naive…","h":"/mechanisms/bounding-unexplained-information/#flaw-2","host":"M-0024","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-2.7,"y":540.7},{"id":"M-0024.F3","k":"F","l":"Channels other than checked outputs are outside the bound","n":"Channels other than checked outputs are outside the bound","d":"The inference-verification scheme treats side channels as out of scope. A low-trust system design argues that suppressing physical covert bandwidth below kilobits per second is much more achievable than aiming for zero, and that a malicious device can leak…","h":"/mechanisms/bounding-unexplained-information/#flaw-3","host":"M-0024","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":3,"y":529},{"id":"M-0024.F4","k":"F","l":"The facility-level design is untested","n":"The facility-level design is untested","d":"The compute-verification architecture is described with protocol details, potential attacks and prototyping plans, but no prototype results have been published.","h":"/mechanisms/bounding-unexplained-information/#flaw-4","host":"M-0024","cat":"isolation-architecture","sev":"significant","fk":"Open question","st":"open","w":1,"x":-47.7,"y":547.1},{"id":"M-0018.B1","k":"B","l":"No public, reproducible end-to-end evaluation exists;…","n":"No public, reproducible end-to-end evaluation exists; the reported H100 prototype is known only from a two-page brief and a demonstration website.","d":"Adversarial validation","h":"/mechanisms/chip-location-verification/#blocker-1","host":"M-0018","theme":"adversarial-validation","cat":"accounting-provenance","w":2,"x":432.8,"y":176.1},{"id":"M-0018.B2","k":"B","l":"Per-chip keys must be provisioned and protected against…","n":"Per-chip keys must be provisioned and protected against extraction; hardware-integrated, tamper-resistant versions still need R&D.","d":"Hardware trust","h":"/mechanisms/chip-location-verification/#blocker-2","host":"M-0018","theme":"hardware-trust","cat":"accounting-provenance","w":2,"x":446.1,"y":173.5},{"id":"M-0018.B3","k":"B","l":"The time limit forces a trade-off: a limit at the speed…","n":"The time limit forces a trade-off: a limit at the speed of light in fibre can be beaten by faster links, while one at the vacuum speed of light makes honest chips fail often.","d":"Protocol soundness","h":"/mechanisms/chip-location-verification/#blocker-3","host":"M-0018","theme":"protocol-soundness","cat":"accounting-provenance","w":2,"x":419.9,"y":171.7},{"id":"M-0018.B4","k":"B","l":"A trusted landmark network must be built and secured,…","n":"A trusted landmark network must be built and secured, and who should operate it, under what oversight, is unsettled.","d":"Access & governance","h":"/mechanisms/chip-location-verification/#blocker-4","host":"M-0018","theme":"access-governance","cat":"accounting-provenance","w":2,"x":440.4,"y":111.7},{"id":"M-0018.F1","k":"F","l":"Extracting a chip's key lets another device answer for it","n":"Extracting a chip's key lets another device answer for it","d":"Ping-based protocols rely on cryptographic keys stored on the chip. Tee and Happel argue that an adversary with physical access could extract these keys and so compromise location verification. They propose GPU fingerprints as a mitigation, so far tested on…","h":"/mechanisms/chip-location-verification/#flaw-1","host":"M-0018","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":453.5,"y":115.9},{"id":"M-0018.F2","k":"F","l":"Added delay can shift an estimated position","n":"Added delay can shift an estimated position","d":"Brass and Aarne cite internet-geolocation research in which artificially increased round-trip times moved the estimated location by up to 1,000 km, with a 74% chance of avoiding detection. Avellar and Grunewald list inflated ping times from circuitous routing…","h":"/mechanisms/chip-location-verification/#flaw-2","host":"M-0018","cat":"accounting-provenance","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":462.2,"y":125.6},{"id":"M-0018.F3","k":"F","l":"Faster-than-assumed network paths","n":"Faster-than-assumed network paths","d":"Brass and Aarne list dark fibre and other private high-speed interconnects as ways to lower measured delays artificially. They judge that leasing dark fibre would probably not be a considerable challenge for covertly or openly adversarial actors. Avellar and…","h":"/mechanisms/chip-location-verification/#flaw-3","host":"M-0018","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":466.2,"y":143.1},{"id":"M-0018.F4","k":"F","l":"Compromised landmarks can falsify measurements","n":"Compromised landmarks can falsify measurements","d":"A party that controls landmark servers can report false timing. Brass and Aarne cite research in which manipulating a third of the landmarks shifted the estimated location by about 700 km. Avellar and Grunewald note that compromised landmarks let adversaries…","h":"/mechanisms/chip-location-verification/#flaw-4","host":"M-0018","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":459,"y":163.4},{"id":"M-0019.B1","k":"B","l":"No AI chip registry operates, and covering re-exports…","n":"No AI chip registry operates, and covering re-exports would need cooperation from re-exporters and foreign governments that may not be feasible everywhere.","d":"Access & governance","h":"/mechanisms/chip-registries-and-manufacturing-records/#blocker-1","host":"M-0019","theme":"access-governance","cat":"accounting-provenance","w":2,"x":436.4,"y":315.7},{"id":"M-0019.B2","k":"B","l":"Linking records to physical chips needs hard-to-spoof…","n":"Linking records to physical chips needs hard-to-spoof unique IDs and inspections.","d":"Hardware trust","h":"/mechanisms/chip-registries-and-manufacturing-records/#blocker-2","host":"M-0019","theme":"hardware-trust","cat":"accounting-provenance","w":2,"x":421.6,"y":311},{"id":"M-0019.B3","k":"B","l":"Chips produced before a registry starts must be…","n":"Chips produced before a registry starts must be reconstructed from supplier records.","d":"Coverage & hidden compute","h":"/mechanisms/chip-registries-and-manufacturing-records/#blocker-3","host":"M-0019","theme":"coverage-hidden-compute","cat":"accounting-provenance","w":2,"x":458.3,"y":258.9},{"id":"M-0019.F1","k":"F","l":"Records cover only chips that were recorded","n":"Records cover only chips that were recorded","d":"A registry or commitment accounts only for chips entered into it. Cankaya asks how a verifier would know it had found all chips, or how much \"dark compute\" remains, and notes that a fraudulent original record would mean unregistered chips had been made in…","h":"/mechanisms/chip-registries-and-manufacturing-records/#flaw-1","host":"M-0019","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":467.3,"y":269.5},{"id":"M-0019.F2","k":"F","l":"Documents and serial numbers can be forged","n":"Documents and serial numbers can be forged","d":"Avellar and Grunewald note that export documents can be forged, that companies can hide information behind obscure corporate structures, and that it may be possible to forge serial numbers on chips and racks. They recommend cryptographic attestation of a…","h":"/mechanisms/chip-registries-and-manufacturing-records/#flaw-2","host":"M-0019","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":468.8,"y":287.7},{"id":"M-0019.F3","k":"F","l":"Insiders could alter records before they are fixed","n":"Insiders could alter records before they are fixed","d":"Cankaya argues that insiders who can photograph process secrets could also tamper with production records. A commitment makes changes after publication detectable, but it cannot show that the records were accurate when committed.","h":"/mechanisms/chip-registries-and-manufacturing-records/#flaw-3","host":"M-0019","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":454.1,"y":310},{"id":"M-0025.B1","k":"B","l":"GPU confidential computing is less mature than CPU…","n":"GPU confidential computing is less mature than CPU support and frontier inference typically needs the resources of several GPUs; a CPU-only enclave audit prototype ran at 1.84 tokens per second.","d":"Performance & compatibility","h":"/mechanisms/confidential-multi-party-verification/#blocker-1","host":"M-0025","theme":"performance-compatibility","cat":"cryptographic-computational","w":3,"x":-461.2,"y":142.4},{"id":"M-0025.B2","k":"B","l":"Zero-knowledge audits have been shown on image…","n":"Zero-knowledge audits have been shown on image classifiers and a recommender model, not language models at frontier scale, and a counterfactual audit of the recommender cost $8,456.","d":"Performance & compatibility","h":"/mechanisms/confidential-multi-party-verification/#blocker-2","host":"M-0025","theme":"performance-compatibility","cat":"cryptographic-computational","w":3,"x":-464.5,"y":88.7},{"id":"M-0025.B3","k":"B","l":"Trust rests on a small number of hardware vendors, and…","n":"Trust rests on a small number of hardware vendors, and a per-CPU Intel attestation key has been extracted by physical attack.","d":"Hardware trust","h":"/mechanisms/confidential-multi-party-verification/#blocker-3","host":"M-0025","theme":"hardware-trust","cat":"cryptographic-computational","w":3,"x":-440,"y":83.7},{"id":"M-0025.B4","k":"B","l":"Parties must negotiate the plan or workflow and handle…","n":"Parties must negotiate the plan or workflow and handle false positives and appeals, which the Auditor-in-a-Box authors list as open problems.","d":"Access & governance","h":"/mechanisms/confidential-multi-party-verification/#blocker-4","host":"M-0025","theme":"access-governance","cat":"cryptographic-computational","w":2,"x":-425.6,"y":141.6},{"id":"M-0025.B5","k":"B","l":"Released evidence must be designed to limit collateral…","n":"Released evidence must be designed to limit collateral leakage, which requires declaring protected properties in advance and calibrating on labelled executions.","d":"Privacy & leakage","h":"/mechanisms/confidential-multi-party-verification/#blocker-5","host":"M-0025","theme":"privacy-leakage","cat":"cryptographic-computational","w":2,"x":-436.7,"y":148.3},{"id":"M-0025.F1","k":"F","l":"Released verdicts can leak information about private inputs","n":"Released verdicts can leak information about private inputs","d":"Even a one-bit result can reveal more than intended. Abdelghafar and Kulp used the published evaluation of Auditor-in-a-Box, whose output filter is meant to disclose at most one bit. Given only the valid or invalid decision on a new request, a simple…","h":"/mechanisms/confidential-multi-party-verification/#flaw-1","host":"M-0025","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-449.7,"y":148.5},{"id":"M-0025.F2","k":"F","l":"Memory-bus interposition extracts attestation keys and forges…","n":"Memory-bus interposition extracts attestation keys and forges attestations","d":"With physical access to a server's DDR5 memory bus, researchers extracted a per-CPU Intel attestation provisioning key and forged TDX attestations. Against AMD SEV-SNP the same attack recovered a signing key used inside the virtual machine, not an AMD…","h":"/mechanisms/confidential-multi-party-verification/#flaw-2","host":"M-0025","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-471.2,"y":130.1},{"id":"M-0025.F3","k":"F","l":"Guarantees depend on the host software stack and on review","n":"Guarantees depend on the host software stack and on review","d":"Cove's developers state that compromise of the Docker daemon, host kernel or TEE stack breaks all guarantees. They also state that Docker policy alone cannot prove that guest code cannot generate a quote if the platform exposes quote instructions globally,…","h":"/mechanisms/confidential-multi-party-verification/#flaw-3","host":"M-0025","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-474.9,"y":112.6},{"id":"M-0025.F4","k":"F","l":"Completeness is not established","n":"Completeness is not established","d":"A confidential workflow proves facts about the records and models submitted to it. A governance analysis notes that an auditor also needs assurance that all activity is accounted for, since a host could start a second confidential virtual machine that uses a…","h":"/mechanisms/confidential-multi-party-verification/#flaw-4","host":"M-0025","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-453,"y":82.8},{"id":"M-0025.F5","k":"F","l":"Zero-knowledge audits reveal model architecture","n":"Zero-knowledge audits reveal model architecture","d":"ZkAudit keeps weights and data secret but reveals the model architecture, and it does not protect against data poisoning.","h":"/mechanisms/confidential-multi-party-verification/#flaw-5","host":"M-0025","cat":"cryptographic-computational","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":-471.9,"y":99.5},{"id":"M-0002.B1","k":"B","l":"Batch-invariant kernels cost throughput: in Thinking…","n":"Batch-invariant kernels cost throughput: in Thinking Machines' Qwen3-8B test, an improved deterministic build took 42 s against 26 s for vLLM's default, and SGLang reports an average 34.35% slowdown on its FlashInfer and FlashAttention 3 backends.","d":"Performance & compatibility","h":"/mechanisms/deterministic-inference/#blocker-1","host":"M-0002","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-273.3,"y":450.7},{"id":"M-0002.B2","k":"B","l":"Coverage is incomplete: the bit-exact emulator targets…","n":"Coverage is incomplete: the bit-exact emulator targets dense blocks on NVIDIA GPUs and excludes mixture-of-experts inference and training; SGLang's deterministic mode supported dense models and one- or two-GPU tensor parallelism as of September 2025.","d":"Performance & compatibility","h":"/mechanisms/deterministic-inference/#blocker-2","host":"M-0002","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-283.6,"y":458.9},{"id":"M-0002.B3","k":"B","l":"A reproducible inference stack for verification has not…","n":"A reproducible inference stack for verification has not been built; Amodo rates it 'not started'.","d":"Performance & compatibility","h":"/mechanisms/deterministic-inference/#blocker-3","host":"M-0002","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-301.2,"y":459.9},{"id":"M-0002.B4","k":"B","l":"Exact replay requires the prover to disclose weights,…","n":"Exact replay requires the prover to disclose weights, software versions, parallelism and batch sizes to whoever recomputes.","d":"Privacy & leakage","h":"/mechanisms/deterministic-inference/#blocker-4","host":"M-0002","theme":"privacy-leakage","cat":"cryptographic-computational","w":2,"x":-322.9,"y":445.6},{"id":"M-0002.F1","k":"F","l":"Some kernels remain genuinely nondeterministic","n":"Some kernels remain genuinely nondeterministic","d":"The bit-exact work separates kernels that are deterministic but not batch-invariant from truly nondeterministic ones that use atomic functions. Some integer de-quantization kernels use atomic additions and remain nondeterministic, so exact replay needs…","h":"/mechanisms/deterministic-inference/#flaw-1","host":"M-0002","cat":"cryptographic-computational","sev":"minor","fk":"Open question","st":"open","w":1,"x":-328.8,"y":427.8},{"id":"M-0002.F2","k":"F","l":"Cross-hardware replay relies on reverse-engineered, closed…","n":"Cross-hardware replay relies on reverse-engineered, closed behaviour","d":"Emulating one GPU's rounding on another requires reverse-engineering tensor-core arithmetic and modelling proprietary kernel choices. Hawkeye covers a subset of NVIDIA architectures and states that attention and other higher-level operations need further…","h":"/mechanisms/deterministic-inference/#flaw-2","host":"M-0002","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-324.5,"y":414},{"id":"M-0011.B1","k":"B","l":"The throttles need new microarchitecture in future…","n":"The throttles need new microarchitecture in future chips, and chipmakers would have to adopt it.","d":"Access & governance","h":"/mechanisms/hardware-performance-throttling/#blocker-1","host":"M-0011","theme":"access-governance","cat":"on-chip","w":2,"x":84.1,"y":-460.3},{"id":"M-0011.B2","k":"B","l":"Secure licensing and trigger infrastructure is missing,…","n":"Secure licensing and trigger infrastructure is missing, such as a guarantee processor that issues or checks licenses.","d":"Protocol soundness","h":"/mechanisms/hardware-performance-throttling/#blocker-2","host":"M-0011","theme":"protocol-soundness","cat":"on-chip","w":3,"x":19.3,"y":-452.7},{"id":"M-0011.B3","k":"B","l":"Licenses denominated in work need secure meters for the…","n":"Licenses denominated in work need secure meters for the licensed quantities.","d":"Hardware trust","h":"/mechanisms/hardware-performance-throttling/#blocker-3","host":"M-0011","theme":"hardware-trust","cat":"on-chip","w":3,"x":21.2,"y":-465.5},{"id":"M-0011.B4","k":"B","l":"No throttle has been evaluated on real hardware or…","n":"No throttle has been evaluated on real hardware or against red-team attempts at bypass.","d":"Adversarial validation","h":"/mechanisms/hardware-performance-throttling/#blocker-4","host":"M-0011","theme":"adversarial-validation","cat":"on-chip","w":2,"x":29.6,"y":-477.2},{"id":"M-0011.F1","k":"F","l":"Trigger and licensing path security is unresolved","n":"Trigger and licensing path security is unresolved","d":"Ma et al. assume the trigger path stays within the same trust domain as the throttle. They note that an externally sourced trigger from a trusted authority may be intercepted or blocked by the model or by adversarial humans. They state that the trigger must…","h":"/mechanisms/hardware-performance-throttling/#flaw-1","host":"M-0011","cat":"on-chip","sev":"significant","fk":"Open question","st":"open","w":1,"x":43.7,"y":-485.5},{"id":"M-0011.F2","k":"F","l":"Physical and firmware attacks on the enforcing hardware","n":"Physical and firmware attacks on the enforcing hardware","d":"RAND's threat analysis includes invasive and semi-invasive physical attacks, fault injection, and firmware and supply-chain attacks. It judges that anti-tamper measures would not be insurmountable for a determined and well-resourced adversary. Ma et al.…","h":"/mechanisms/hardware-performance-throttling/#flaw-2","host":"M-0011","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":64.8,"y":-483.3},{"id":"M-0011.F3","k":"F","l":"Sensitivity is architecture-specific and some knobs behave…","n":"Sensitivity is architecture-specific and some knobs behave non-monotonically","d":"The authors caution that exact sensitivity curves and knob rankings \"may shift across configurations\". L2 associativity throttling showed non-monotonic performance because of address-mapping effects.","h":"/mechanisms/hardware-performance-throttling/#flaw-3","host":"M-0011","cat":"on-chip","sev":"minor","fk":"Open question","st":"open","w":1,"x":78.5,"y":-472.8},{"id":"M-0011.F4","k":"F","l":"Workloads can adapt to a throttled resource","n":"Workloads can adapt to a throttled resource","d":"A throttled AI could switch to a simpler model, which the authors call \"precisely the intended effect\". They argue that highly optimized kernels leave little headroom for further adaptation.","h":"/mechanisms/hardware-performance-throttling/#flaw-4","host":"M-0011","cat":"on-chip","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":82.3,"y":-446.4},{"id":"M-0009.B1","k":"B","l":"Integrated flexHEG needs substantial help from the…","n":"Integrated flexHEG needs substantial help from the accelerator manufacturer, and the authors estimate 3.7–7.9 years, from when the manufacturer starts work, for such hardware to displace other accelerators in frontier development.","d":"Access & governance","h":"/mechanisms/flexheg-guarantee-processors/#blocker-1","host":"M-0009","theme":"access-governance","cat":"on-chip","w":2,"x":-93.2,"y":-527.7},{"id":"M-0009.B2","k":"B","l":"State-level attackers who hold the hardware can likely…","n":"State-level attackers who hold the hardware can likely compromise the best current secure enclosures.","d":"Hardware trust","h":"/mechanisms/flexheg-guarantee-processors/#blocker-2","host":"M-0009","theme":"hardware-trust","cat":"on-chip","w":3,"x":-85.7,"y":-538.3},{"id":"M-0009.B3","k":"B","l":"Rival states would need to trust the design and…","n":"Rival states would need to trust the design and manufacture of guarantee processors and enclosures, for example through open design, redundant processors from each side or oversight of production.","d":"Hardware trust","h":"/mechanisms/flexheg-guarantee-processors/#blocker-3","host":"M-0009","theme":"hardware-trust","cat":"on-chip","w":2,"x":-75.6,"y":-546.6},{"id":"M-0009.B4","k":"B","l":"Restricting future rule updates would need a formal…","n":"Restricting future rule updates would need a formal language for rules, which the authors judge most likely infeasible for early flexHEG versions.","d":"Protocol soundness","h":"/mechanisms/flexheg-guarantee-processors/#blocker-4","host":"M-0009","theme":"protocol-soundness","cat":"on-chip","w":2,"x":-28.1,"y":-536.5},{"id":"M-0009.B5","k":"B","l":"Governing all relevant chips depends on knowing where…","n":"Governing all relevant chips depends on knowing where they are, through chip registries and detection of undeclared facilities.","d":"Coverage & hidden compute","h":"/mechanisms/flexheg-guarantee-processors/#blocker-5","host":"M-0009","theme":"coverage-hidden-compute","cat":"on-chip","w":3,"x":-38.3,"y":-544.5},{"id":"M-0009.F1","k":"F","l":"State attackers can likely defeat current secure enclosures","n":"State attackers can likely defeat current secure enclosures","d":"The flexHEG authors write that \"nation-state attackers can likely compromise the best current secure enclosures\", and that the marginal cost of circumvention per device is hard to estimate. RAND similarly judges that anti-tamper measures \"would not be…","h":"/mechanisms/flexheg-guarantee-processors/#flaw-1","host":"M-0009","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-25.7,"y":-523.8},{"id":"M-0009.F2","k":"F","l":"Firmware-only retrofits rely on Secure Boot, which fault…","n":"Firmware-only retrofits rely on Secure Boot, which fault injection can bypass","d":"Part II notes that the most common attack on Secure Boot replaces the firmware and applies a voltage glitch while the signature is being checked. It also notes that sophisticated actors may use microprobing or laser voltage probing to read key registers.","h":"/mechanisms/flexheg-guarantee-processors/#flaw-2","host":"M-0009","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-28.9,"y":-511.2},{"id":"M-0009.F3","k":"F","l":"Many important rules cannot be checked on-chip","n":"Many important rules cannot be checked on-chip","d":"Malicious intent \"is not a technical property observable on-chip\", and misuse depends on what is done with a computation's results. A guarantee processor cannot easily tell whether a network is the whole system or one expert in a mixture-of-experts system.…","h":"/mechanisms/flexheg-guarantee-processors/#flaw-3","host":"M-0009","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-84.2,"y":-503.5},{"id":"M-0009.F4","k":"F","l":"FLOP accounting can be laundered through external data","n":"FLOP accounting can be laundered through external data","d":"Results of earlier or parallel workloads could be hidden in the \"external data\" fed to a device, which would falsify the total FLOP count unless the inputs are explained or time delays are imposed.","h":"/mechanisms/flexheg-guarantee-processors/#flaw-4","host":"M-0009","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-90.1,"y":-515.1},{"id":"M-0009.F5","k":"F","l":"Supply-chain diversion and hidden backdoors","n":"Supply-chain diversion and hidden backdoors","d":"Components could be diverted before a guarantee processor is added, and backdoors could be introduced during design or manufacturing. Open-source designs and physical scans of randomly selected chips are proposed as countermeasures. Part III proposes…","h":"/mechanisms/flexheg-guarantee-processors/#flaw-5","host":"M-0009","cat":"on-chip","sev":"significant","fk":"Open question","st":"open","w":1,"x":-63.2,"y":-550.5},{"id":"M-0009.F6","k":"F","l":"Coverage stops at flexHEG-equipped chips","n":"Coverage stops at flexHEG-equipped chips","d":"Motivated actors will always be able to use some compute that is not flexHEG-equipped. Recalling existing consumer GPUs would likely be impractical, and reaching perfect coverage, or conclusively proving that no secret government data centres exist, would be…","h":"/mechanisms/flexheg-guarantee-processors/#flaw-6","host":"M-0009","cat":"on-chip","sev":"significant","fk":"Open question","st":"open","w":1,"x":-50.3,"y":-549.6},{"id":"M-0015.B1","k":"B","l":"Wipes take time: tens of minutes for a pod's volatile…","n":"Wipes take time: tens of minutes for a pod's volatile memory and hours for SSDs, displacing work.","d":"Performance & compatibility","h":"/mechanisms/memory-wiping-and-secure-erasure/#blocker-1","host":"M-0015","theme":"performance-compatibility","cat":"isolation-architecture","w":2,"x":218.7,"y":504.8},{"id":"M-0015.B2","k":"B","l":"Timed challenges must exclude remote memory and other…","n":"Timed challenges must exclude remote memory and other helpers.","d":"Coverage & hidden compute","h":"/mechanisms/memory-wiping-and-secure-erasure/#blocker-2","host":"M-0015","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":200.5,"y":500.6},{"id":"M-0015.B3","k":"B","l":"All memory stores in a system must be inventoried and…","n":"All memory stores in a system must be inventoried and wiped at the same time.","d":"Coverage & hidden compute","h":"/mechanisms/memory-wiping-and-secure-erasure/#blocker-3","host":"M-0015","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":2,"x":190.9,"y":489.9},{"id":"M-0015.F1","k":"F","l":"Memory the wipe cannot reach","n":"Memory the wipe cannot reach","d":"Amodo's inventory of a GB200 system lists many memory stores beyond GPU HBM and host DRAM. It notes that SSD controller DRAM sits on a private bus that host commands cannot read or write, and that its optimized algorithm leaves 25 GiB of HBM unattested. It…","h":"/mechanisms/memory-wiping-and-secure-erasure/#flaw-1","host":"M-0015","cat":"isolation-architecture","sev":"significant","fk":"Open question","st":"open","w":1,"x":248.3,"y":462.2},{"id":"M-0015.F2","k":"F","l":"Outside help during challenges","n":"Outside help during challenges","d":"Classic proofs of secure erasure assume the device is isolated during the protocol. Bursuc et al. relax this to a bound on how close a helper can be, enforced by round-trip times. In data centres, remote memory access has round trips of about 1–2 µs, against…","h":"/mechanisms/memory-wiping-and-secure-erasure/#flaw-2","host":"M-0015","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":250.7,"y":476.9},{"id":"M-0015.F3","k":"F","l":"Gap between erased and total memory","n":"Gap between erased and total memory","d":"Bursuc et al. note that memory left between the erased region and the device's full memory could hold data, and that their bounds are tighter only against a restricted adversary.","h":"/mechanisms/memory-wiping-and-secure-erasure/#flaw-3","host":"M-0015","cat":"isolation-architecture","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":242.6,"y":493.3},{"id":"M-0012.B1","k":"B","l":"Attestation that resists physical attackers, for the…","n":"Attestation that resists physical attackers, for the enclave variant.","d":"Hardware trust","h":"/mechanisms/model-identity-attestation/#blocker-1","host":"M-0012","theme":"hardware-trust","cat":"cryptographic-computational","w":3,"x":-364.8,"y":325.2},{"id":"M-0012.B2","k":"B","l":"Numerical nondeterminism limits how tightly…","n":"Numerical nondeterminism limits how tightly recomputation can pin down the model and sampling.","d":"Protocol soundness","h":"/mechanisms/model-identity-attestation/#blocker-2","host":"M-0012","theme":"protocol-soundness","cat":"cryptographic-computational","w":3,"x":-373.2,"y":305.7},{"id":"M-0012.B3","k":"B","l":"The recomputation variant needs the verifier to hold…","n":"The recomputation variant needs the verifier to hold the declared weights.","d":"Access & governance","h":"/mechanisms/model-identity-attestation/#blocker-3","host":"M-0012","theme":"access-governance","cat":"cryptographic-computational","w":2,"x":-370.9,"y":290.4},{"id":"M-0012.F1","k":"F","l":"Underlying attestation can be forged or relayed","n":"Underlying attestation can be forged or relayed","d":"The enclave variant is only as sound as the attestation. With physical access and root privileges, TEE.fail extracted a per-CPU Intel attestation signing key and forged TDX attestations. Pairing the forgeries with genuine H100 attestations relayed from a…","h":"/mechanisms/model-identity-attestation/#flaw-1","host":"M-0012","cat":"cryptographic-computational","sev":"critical","fk":"Demonstrated attack","st":"open","crit":true,"w":1,"x":-361.5,"y":279.7},{"id":"M-0012.F2","k":"F","l":"Launch-state attestation does not by itself cover weights…","n":"Launch-state attestation does not by itself cover weights loaded later","d":"Attestation measures launch state, and weights are read from disk after boot. A signature checked at load time does not stop a malicious hypervisor from altering the disk afterwards. Tinfoil reports mitigating this with dm-verity checks on every read.…","h":"/mechanisms/model-identity-attestation/#flaw-2","host":"M-0012","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"mitigated","w":1,"x":-318.7,"y":327.6},{"id":"M-0012.F3","k":"F","l":"For private models, a user can confirm consistency but not…","n":"For private models, a user can confirm consistency but not content","d":"When weights are not published, users can check that the same root hash is served each time, but not what the model is. Pairing the hash with an attested evaluation, as in Attestable Audits, is one proposed remedy.","h":"/mechanisms/model-identity-attestation/#flaw-3","host":"M-0012","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-330.6,"y":335.9},{"id":"M-0012.F4","k":"F","l":"Recomputation depends on trusted logging and randomness, and…","n":"Recomputation depends on trusted logging and randomness, and its tolerance leaves a covert channel","d":"The recomputation variant assumes that every input, output and seed is logged correctly, and that the attacker can neither predict nor manipulate which messages are sampled for verification. Legitimate nondeterminism concentrates at a few token positions, and…","h":"/mechanisms/model-identity-attestation/#flaw-4","host":"M-0012","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-346.1,"y":336.4},{"id":"M-0013.B1","k":"B","l":"No tap or hashing hardware has been shown at production…","n":"No tap or hashing hardware has been shown at production frontend link rates; on tested CPUs, no algorithm kept up with minimum-size frames.","d":"Performance & compatibility","h":"/mechanisms/network-taps-and-certifiers/#blocker-1","host":"M-0013","theme":"performance-compatibility","cat":"off-chip-devices","w":2,"x":275.8,"y":-401.6},{"id":"M-0013.B2","k":"B","l":"Nondeterministic inference leaves covert capacity in…","n":"Nondeterministic inference leaves covert capacity in outputs that hashing cannot remove.","d":"Evidence binding","h":"/mechanisms/network-taps-and-certifiers/#blocker-2","host":"M-0013","theme":"evidence-binding","cat":"off-chip-devices","w":3,"x":302.8,"y":-371.8},{"id":"M-0013.B3","k":"B","l":"Taps and gateway devices need tamper-evident housing…","n":"Taps and gateway devices need tamper-evident housing and physical monitoring so that traffic cannot bypass them.","d":"Hardware trust","h":"/mechanisms/network-taps-and-certifiers/#blocker-3","host":"M-0013","theme":"hardware-trust","cat":"off-chip-devices","w":3,"x":295.5,"y":-347.7},{"id":"M-0013.B4","k":"B","l":"Radio, power-line and thermal channels are not…","n":"Radio, power-line and thermal channels are not addressed by network-level designs.","d":"Coverage & hidden compute","h":"/mechanisms/network-taps-and-certifiers/#blocker-4","host":"M-0013","theme":"coverage-hidden-compute","cat":"off-chip-devices","w":3,"x":284,"y":-341.7},{"id":"M-0013.B5","k":"B","l":"Red-teaming by specialists is called for but has not…","n":"Red-teaming by specialists is called for but has not been reported.","d":"Adversarial validation","h":"/mechanisms/network-taps-and-certifiers/#blocker-5","host":"M-0013","theme":"adversarial-validation","cat":"off-chip-devices","w":2,"x":239.3,"y":-375.9},{"id":"M-0013.F1","k":"F","l":"Output nondeterminism leaves covert capacity","n":"Output nondeterminism leaves covert capacity","d":"Hashing cannot remove information hidden in the outputs themselves. The Secure Gateway Device paper estimates that about 0.1 bit per token remains even with seed-synchronized replay checks. For a 200k-GPU inference cluster at full load (2,000 tokens per GPU…","h":"/mechanisms/network-taps-and-certifiers/#flaw-1","host":"M-0013","cat":"off-chip-devices","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":241.8,"y":-388.7},{"id":"M-0013.F2","k":"F","l":"Some links cannot be passively tapped","n":"Some links cannot be passively tapped","d":"Cankaya notes that copper-connected scale-up domains (for example NVL72 racks and TPU v7 cubes) are much harder to tap than fibre, and that optical budgets make passive taps impractical on 400GBASE-SR8 multimode links. Amodo found no taps advertised for 53…","h":"/mechanisms/network-taps-and-certifiers/#flaw-2","host":"M-0013","cat":"off-chip-devices","sev":"significant","fk":"Open question","st":"open","w":1,"x":262.8,"y":-402.3},{"id":"M-0013.F3","k":"F","l":"Encrypted fabrics hide plaintext from both parties","n":"Encrypted fabrics hide plaintext from both parties","d":"Cankaya notes that with TEE-protected sessions, neither the operator nor the manufacturer can recover session keys after the session, so tapped traffic could not be opened for recomputation. For other encrypted fabrics, the operator can retain keys.","h":"/mechanisms/network-taps-and-certifiers/#flaw-3","host":"M-0013","cat":"off-chip-devices","sev":"significant","fk":"Open question","st":"open","w":1,"x":250.4,"y":-398.4},{"id":"M-0013.F4","k":"F","l":"Residual side channels in simple passive setups","n":"Residual side channels in simple passive setups","d":"Amodo's analysis of its own tapped prototype lists unvalidated header fields, timing of permitted traffic and variation in response formatting as residual channels, and concludes that the passive tap must be replaced by an active one.","h":"/mechanisms/network-taps-and-certifiers/#flaw-4","host":"M-0013","cat":"off-chip-devices","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":298.6,"y":-384.1},{"id":"M-0013.F5","k":"F","l":"Completeness rests on physical monitoring left out of scope","n":"Completeness rests on physical monitoring left out of scope","d":"The Secure Gateway Device paper assumes the facility is physically monitored, and states that the whole architecture depends on the device being the only communication channel. It names radio emanation, power-line signalling and thermal channels as covert…","h":"/mechanisms/network-taps-and-certifiers/#flaw-5","host":"M-0013","cat":"off-chip-devices","sev":"significant","fk":"Open question","st":"open","w":1,"x":289,"y":-395.5},{"id":"M-0013.F6","k":"F","l":"Verifier dictionary attacks on hashes","n":"Verifier dictionary attacks on hashes","d":"Hashes of very short outputs could be brute-forced by the verifier. The paper recommends hashing at least 5 tokens together, or at least 10 if the attacker filters for likely tokens.","h":"/mechanisms/network-taps-and-certifiers/#flaw-6","host":"M-0013","cat":"off-chip-devices","sev":"minor","fk":"Theoretical argument","st":"mitigated","w":1,"x":302.2,"y":-358.8},{"id":"M-0010.B1","k":"B","l":"Shipping accelerators need a tamper-resistant,…","n":"Shipping accelerators need a tamper-resistant, authenticated telemetry path.","d":"Hardware trust","h":"/mechanisms/on-chip-telemetry/#blocker-1","host":"M-0010","theme":"hardware-trust","cat":"on-chip","w":3,"x":141.8,"y":-498},{"id":"M-0010.B2","k":"B","l":"Confidential computing disables performance counters,…","n":"Confidential computing disables performance counters, so richer telemetry conflicts with it.","d":"Privacy & leakage","h":"/mechanisms/on-chip-telemetry/#blocker-2","host":"M-0010","theme":"privacy-leakage","cat":"on-chip","w":2,"x":166.4,"y":-523.7},{"id":"M-0010.B3","k":"B","l":"Continuous challenge puzzles cost power and throughput…","n":"Continuous challenge puzzles cost power and throughput on production workloads.","d":"Performance & compatibility","h":"/mechanisms/on-chip-telemetry/#blocker-3","host":"M-0010","theme":"performance-compatibility","cat":"on-chip","w":2,"x":183.8,"y":-521.8},{"id":"M-0010.B4","k":"B","l":"Evaluation has not gone beyond single nodes,…","n":"Evaluation has not gone beyond single nodes, framework-level evasion and one vendor's hardware.","d":"Adversarial validation","h":"/mechanisms/on-chip-telemetry/#blocker-4","host":"M-0010","theme":"adversarial-validation","cat":"on-chip","w":2,"x":198.2,"y":-511.9},{"id":"M-0010.F1","k":"F","l":"Software-read telemetry can be forged by the operator","n":"Software-read telemetry can be forged by the operator","d":"NVML-based classification assumes trustworthy telemetry. Without a tamper-resistant read path, an authenticated telemetry channel and secure boot of the monitoring software, an operator who controls the full software stack could forge counter values. Monfared…","h":"/mechanisms/on-chip-telemetry/#flaw-1","host":"M-0010","cat":"on-chip","sev":"critical","fk":"Theoretical argument","st":"open","crit":true,"w":1,"x":205.1,"y":-499.6},{"id":"M-0010.F2","k":"F","l":"Adversarially disguised fine-tuning partly evades classification","n":"Adversarially disguised fine-tuning partly evades classification","d":"Across 20 evasion strategy families in five monitor-evader rounds, the classifier's accuracy against the most challenging disguised workloads held out from training was 43–87%. White-box LoRA fine-tuning was the only evasion family detected less than half the…","h":"/mechanisms/on-chip-telemetry/#flaw-2","host":"M-0010","cat":"on-chip","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":205.7,"y":-486.7},{"id":"M-0010.F3","k":"F","l":"Timing challenges do not identify the individual chip","n":"Timing challenges do not identify the individual chip","d":"GEMM and VDF challenges can be answered by identical GPUs elsewhere, and floating-point fingerprints distinguish GPU models, not individual devices. GPU virtualization adds timing leakage that prevents attributing compute use.","h":"/mechanisms/on-chip-telemetry/#flaw-3","host":"M-0010","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":199.6,"y":-475.1},{"id":"M-0010.F4","k":"F","l":"Counters leak information about protected workloads","n":"Counters leak information about protected workloads","d":"Performance counters have been used as a side channel against TEEs, for example in CounterSEVeillance. NVIDIA disables performance counters in full confidential-computing mode, stating that they could provide an avenue for side-channel attacks. Richer…","h":"/mechanisms/on-chip-telemetry/#flaw-4","host":"M-0010","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":154,"y":-519.8},{"id":"M-0010.F5","k":"F","l":"No quantified error rates or formal thresholds for timing…","n":"No quantified error rates or formal thresholds for timing primitives","d":"Monfared et al. state that false-positive and false-negative rates are not quantified and leave hardware-specific formal thresholds to future work.","h":"/mechanisms/on-chip-telemetry/#flaw-5","host":"M-0010","cat":"on-chip","sev":"minor","fk":"Open question","st":"open","w":1,"x":144.7,"y":-510.7},{"id":"M-0006.B1","k":"B","l":"The verifier must receive the training data, weights…","n":"The verifier must receive the training data, weights and code.","d":"Privacy & leakage","h":"/mechanisms/proof-of-learning/#blocker-1","host":"M-0006","theme":"privacy-leakage","cat":"cryptographic-computational","w":2,"x":-473.1,"y":-200.2},{"id":"M-0006.B2","k":"B","l":"Transcripts are large: weight checkpoints may each…","n":"Transcripts are large: weight checkpoints may each require terabytes.","d":"Performance & compatibility","h":"/mechanisms/proof-of-learning/#blocker-2","host":"M-0006","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-499.3,"y":-236.8},{"id":"M-0006.B3","k":"B","l":"The verifier must reproduce training segments, which…","n":"The verifier must reproduce training segments, which may be infeasible if the prover uses specialised or proprietary hardware.","d":"Performance & compatibility","h":"/mechanisms/proof-of-learning/#blocker-3","host":"M-0006","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-481.3,"y":-260.4},{"id":"M-0006.B4","k":"B","l":"The noise tolerance needed for honest reproduction is…","n":"The noise tolerance needed for honest reproduction is what structurally correct spoofs exploit.","d":"Protocol soundness","h":"/mechanisms/proof-of-learning/#blocker-4","host":"M-0006","theme":"protocol-soundness","cat":"cryptographic-computational","w":2,"x":-456.4,"y":-261.8},{"id":"M-0006.B5","k":"B","l":"Tying transcripts to real chips needs on-chip…","n":"Tying transcripts to real chips needs on-chip weight-snapshot logging, chip inspections and a trusted chip-owner directory.","d":"Evidence binding","h":"/mechanisms/proof-of-learning/#blocker-5","host":"M-0006","theme":"evidence-binding","cat":"cryptographic-computational","w":2,"x":-446.8,"y":-253.1},{"id":"M-0006.F1","k":"F","l":"Adversarial-example spoofs pass verification at lower cost than…","n":"Adversarial-example spoofs pass verification at lower cost than training","d":"Zhang et al. construct proofs that pass the original verification \"with significantly less cost than generating a proof by the prover\". Their attack uses adversarial-example-style perturbations, and they demonstrate it on CIFAR-10, CIFAR-100 and an ImageNet…","h":"/mechanisms/proof-of-learning/#flaw-1","host":"M-0006","cat":"cryptographic-computational","sev":"critical","fk":"Demonstrated attack","st":"disputed","w":1,"x":-486,"y":-202.3},{"id":"M-0006.F2","k":"F","l":"Structurally correct spoofs exploit tolerance thresholds and…","n":"Structurally correct spoofs exploit tolerance thresholds and sampled checks","d":"Fang et al., including the original proposers, present spoofing strategies that work across PoL configurations at \"a fraction of the cost of previous spoofing strategies\". The strategies exploit the tolerance that verification must allow for hardware noise,…","h":"/mechanisms/proof-of-learning/#flaw-2","host":"M-0006","cat":"cryptographic-computational","sev":"critical","fk":"Demonstrated attack","st":"open","crit":true,"w":1,"x":-499.9,"y":-223},{"id":"M-0006.F3","k":"F","l":"No provably robust verification without better optimisation…","n":"No provably robust verification without better optimisation theory","d":"Fang et al. conclude that \"one cannot develop a provably robust PoL verification mechanism without further understanding of optimization in deep learning\". Shavit notes that the PoL literature \"has been heuristic-based\".","h":"/mechanisms/proof-of-learning/#flaw-3","host":"M-0006","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-496,"y":-210.6},{"id":"M-0006.F4","k":"F","l":"Rule-compliance transcripts face a stronger adversary","n":"Rule-compliance transcripts face a stronger adversary","d":"Shavit argues that proving a training transcript \"appears to be strictly harder than PoL\". The adversary knows the true transcript and may spend extra compute to build a compliant-looking one.","h":"/mechanisms/proof-of-learning/#flaw-4","host":"M-0006","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-469.1,"y":-264.7},{"id":"M-0006.F5","k":"F","l":"Small data changes and masked hyperparameters may go undetected","n":"Small data changes and masked hyperparameters may go undetected","d":"Choi et al. state that their protocol cannot yet detect modest data additions, such as inserted backdoors. They note that attacks could be hidden with \"cleverly chosen hyperparameters\", such as a temporarily lower learning rate than reported, and that the…","h":"/mechanisms/proof-of-learning/#flaw-5","host":"M-0006","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-492,"y":-251.7},{"id":"M-0007.B1","k":"B","l":"Bounding spare capacity needs a credible estimate of…","n":"Bounding spare capacity needs a credible estimate of the compute available to the actor, including third-party access.","d":"Capacity bounds","h":"/mechanisms/proofs-of-useful-work/#blocker-1","host":"M-0007","theme":"capacity-bounds","cat":"cryptographic-computational","w":2,"x":-298,"y":-448.6},{"id":"M-0007.B2","k":"B","l":"Proofs of work cannot find facilities that were never…","n":"Proofs of work cannot find facilities that were never declared.","d":"Coverage & hidden compute","h":"/mechanisms/proofs-of-useful-work/#blocker-2","host":"M-0007","theme":"coverage-hidden-compute","cat":"cryptographic-computational","w":2,"x":-285.9,"y":-439},{"id":"M-0007.B3","k":"B","l":"As of September 2026 no implementation, demonstration…","n":"As of September 2026 no implementation, demonstration or independent evaluation of proofs of work for capacity bounding has been published.","d":"Adversarial validation","h":"/mechanisms/proofs-of-useful-work/#blocker-3","host":"M-0007","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-338.4,"y":-403.2},{"id":"M-0007.F1","k":"F","l":"Proves that work was done, not that no capacity remains","n":"Proves that work was done, not that no capacity remains","d":"Proof-of-work accounting bounds unmonitored compute only relative to an estimate of what the actor has. Attestable states that the verifier \"needs a credible estimate of the compute available\" to the actor, and that a proof \"cannot discover a datacenter that…","h":"/mechanisms/proofs-of-useful-work/#flaw-1","host":"M-0007","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-343.1,"y":-416.2},{"id":"M-0007.F2","k":"F","l":"Security rests on new hardness assumptions","n":"Security rests on new hardness assumptions","d":"Komargodski and Weinstein base security on hardness assumptions about batches of low-rank random linear equations, and list PoUW \"from more standard or well-studied assumptions\" as an open problem. Pearl's floating-point variant introduces a further…","h":"/mechanisms/proofs-of-useful-work/#flaw-2","host":"M-0007","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-338.1,"y":-433.8},{"id":"M-0007.F3","k":"F","l":"Known shortcuts let a miner claim somewhat more work than it did","n":"Known shortcuts let a miner claim somewhat more work than it did","d":"Pearl's specification lists known mining speedups: crafted inputs, precision shortcuts, seed grinding, work reuse, and faster kernels or hardware. A policy check caps the summands a miner may skip at one-sixteenth of those in a tile. For capacity bounding,…","h":"/mechanisms/proofs-of-useful-work/#flaw-3","host":"M-0007","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-316.5,"y":-449.5},{"id":"M-0020.B1","k":"B","l":"Wide-area, automated detection of data centres is not…","n":"Wide-area, automated detection of data centres is not yet practical and needs large training datasets.","d":"Coverage & hidden compute","h":"/mechanisms/remote-detection-of-data-centres/#blocker-1","host":"M-0020","theme":"coverage-hidden-compute","cat":"remote-sensing","w":2,"x":478.1,"y":-85.3},{"id":"M-0020.B2","k":"B","l":"No measured detection or false-alarm rates for finding…","n":"No measured detection or false-alarm rates for finding undeclared facilities have been published.","d":"Adversarial validation","h":"/mechanisms/remote-detection-of-data-centres/#blocker-2","host":"M-0020","theme":"adversarial-validation","cat":"remote-sensing","w":2,"x":469.4,"y":-69},{"id":"M-0020.B3","k":"B","l":"Recent high-resolution imagery is costly, is limited by…","n":"Recent high-resolution imagery is costly, is limited by weather and needs trained analysts.","d":"Access & governance","h":"/mechanisms/remote-detection-of-data-centres/#blocker-3","host":"M-0020","theme":"access-governance","cat":"remote-sensing","w":2,"x":455.5,"y":-62.2},{"id":"M-0020.F1","k":"F","l":"Facilities can be disguised or hidden","n":"Facilities can be disguised or hidden","d":"Halstead and Larsen discuss two ways to hide a facility. One is to disguise it as a legitimate industrial site. The other is to build it underground, with cooling that avoids visible heat plumes. They note that the underground option requires bespoke…","h":"/mechanisms/remote-detection-of-data-centres/#flaw-1","host":"M-0020","cat":"remote-sensing","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":442.8,"y":-125},{"id":"M-0020.F2","k":"F","l":"Small sites may not be detectable","n":"Small sites may not be detectable","d":"Halstead and Larsen conclude that a sufficiently small covert project could not be ruled out with confidence. In their estimates, the chance of detection is lower for smaller sites. Krawec notes that small data centres in existing buildings may lack the…","h":"/mechanisms/remote-detection-of-data-centres/#flaw-2","host":"M-0020","cat":"remote-sensing","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":458.4,"y":-124},{"id":"M-0020.F3","k":"F","l":"Search for unknown sites is undemonstrated","n":"Search for unknown sites is undemonstrated","d":"Krawec reports that telling data centres apart from other industrial facilities systematically is difficult. Automating detection would need large amounts of training imagery and a purpose-trained model. In Krawec's words, automated data-centre detection…","h":"/mechanisms/remote-detection-of-data-centres/#flaw-3","host":"M-0020","cat":"remote-sensing","sev":"significant","fk":"Open question","st":"open","w":1,"x":472.9,"y":-112},{"id":"M-0003.B1","k":"B","l":"Workloads are not reproducible by default, and…","n":"Workloads are not reproducible by default, and achieving reproducibility may cost performance.","d":"Performance & compatibility","h":"/mechanisms/reproducible-computation-packets/#blocker-1","host":"M-0003","theme":"performance-compatibility","cat":"isolation-architecture","w":3,"x":314.3,"y":370.7},{"id":"M-0003.B2","k":"B","l":"Network packets are not individually reproducible by…","n":"Network packets are not individually reproducible by default; making them so may need considerable software, firmware and hardware work. Amodo rates this 'not on track'.","d":"Performance & compatibility","h":"/mechanisms/reproducible-computation-packets/#blocker-2","host":"M-0003","theme":"performance-compatibility","cat":"isolation-architecture","w":2,"x":293,"y":387.3},{"id":"M-0003.B3","k":"B","l":"All traffic must reach the recomputation server via…","n":"All traffic must reach the recomputation server via network taps, and the server's integrity is critical.","d":"Hardware trust","h":"/mechanisms/reproducible-computation-packets/#blocker-3","host":"M-0003","theme":"hardware-trust","cat":"isolation-architecture","w":3,"x":274.5,"y":386.9},{"id":"M-0003.B4","k":"B","l":"Recomputing training steps needs checkpoints: writing…","n":"Recomputing training steps needs checkpoints: writing one at every step would cost more than 100% overhead, so Amodo's design needs a spare data-parallel replica that tracks the weights instead.","d":"Performance & compatibility","h":"/mechanisms/reproducible-computation-packets/#blocker-4","host":"M-0003","theme":"performance-compatibility","cat":"isolation-architecture","w":2,"x":262.1,"y":377.7},{"id":"M-0003.F1","k":"F","l":"Spare compute is outside the scheme","n":"Spare compute is outside the scheme","d":"The plan states that it does not verify that spare compute is not used for unapproved workloads, because this seems very challenging. Recomputation checks the correctness of declared work, not its completeness.","h":"/mechanisms/reproducible-computation-packets/#flaw-1","host":"M-0003","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":312.4,"y":337.9},{"id":"M-0003.F2","k":"F","l":"Non-compliant work could be encoded inside compliant-looking…","n":"Non-compliant work could be encoded inside compliant-looking packets","d":"The plan notes that an AI company might try to encode a non-compliant workload inside a workload that looks compliant on the surface.","h":"/mechanisms/reproducible-computation-packets/#flaw-2","host":"M-0003","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":318.5,"y":352.3},{"id":"M-0023.B1","k":"B","l":"No published design shows that all of a provider's…","n":"No published design shows that all of a provider's traffic passes through the attested safeguard path; current evidence covers individual attested responses.","d":"Coverage & hidden compute","h":"/mechanisms/safeguard-attestation/#blocker-1","host":"M-0023","theme":"coverage-hidden-compute","cat":"cryptographic-computational","w":2,"x":-547.1,"y":29.2},{"id":"M-0023.B2","k":"B","l":"Frontier model inference typically needs several GPUs,…","n":"Frontier model inference typically needs several GPUs, GPU confidential computing is less mature than CPU support, and CPU inference, which an enclave prototype had to use, ran about 100 times slower than GPU inference.","d":"Performance & compatibility","h":"/mechanisms/safeguard-attestation/#blocker-2","host":"M-0023","theme":"performance-compatibility","cat":"cryptographic-computational","w":3,"x":-552.6,"y":1.1},{"id":"M-0023.B3","k":"B","l":"Trust rests on a small number of hardware vendors, and…","n":"Trust rests on a small number of hardware vendors, and a per-CPU Intel attestation key has been extracted by physical attack.","d":"Hardware trust","h":"/mechanisms/safeguard-attestation/#blocker-3","host":"M-0023","theme":"hardware-trust","cat":"cryptographic-computational","w":3,"x":-552.4,"y":17.4},{"id":"M-0023.B4","k":"B","l":"Safeguard evidence must be bound to the model actually…","n":"Safeguard evidence must be bound to the model actually served, which depends on model-identity attestation.","d":"Evidence binding","h":"/mechanisms/safeguard-attestation/#blocker-4","host":"M-0023","theme":"evidence-binding","cat":"cryptographic-computational","w":3,"x":-539.3,"y":-20.9},{"id":"M-0023.B5","k":"B","l":"No independent red-team or audit of a…","n":"No independent red-team or audit of a safeguard-attestation system has been published, and the available prototypes are described by their authors as proofs of concept that have not been stress-tested by a counterparty.","d":"Adversarial validation","h":"/mechanisms/safeguard-attestation/#blocker-5","host":"M-0023","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-514.1,"y":-20.8},{"id":"M-0023.F1","k":"F","l":"Attestation shows a safeguard ran, not that it is effective","n":"Attestation shows a safeguard ran, not that it is effective","d":"Proof of guardrail ensures that the guardrail executed, but the guardrail can still err or be jailbroken. Because the guardrail must be open source, a malicious developer can attack it with jailbreaks while still presenting a valid proof. In the authors'…","h":"/mechanisms/safeguard-attestation/#flaw-1","host":"M-0023","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-513.4,"y":38.1},{"id":"M-0023.F2","k":"F","l":"Selective attestation leaves traffic uncovered","n":"Selective attestation leaves traffic uncovered","d":"Attestations are issued per response. In the prototype, the agent offers them when it receives high-stakes questions, so nothing shows that unattested traffic went through the same path. PALM's authors note that a prover could cherry-pick favourable…","h":"/mechanisms/safeguard-attestation/#flaw-2","host":"M-0023","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-525.9,"y":41.9},{"id":"M-0023.F3","k":"F","l":"Measurements may omit behaviour-relevant configuration or…","n":"Measurements may omit behaviour-relevant configuration or runtime changes","d":"Every component that influences inference behaviour must be covered by the launch measurement, including feature flags, environment variables and invocation arguments. A launch measurement also does not show that a program keeps running as measured if the…","h":"/mechanisms/safeguard-attestation/#flaw-3","host":"M-0023","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-538.6,"y":39},{"id":"M-0023.F4","k":"F","l":"Components outside the attested boundary","n":"Components outside the attested boundary","d":"In the proof-of-guardrail experiments, the guardrail model and the agent's backend model were both reached through external APIs, and the authors leave the decision to trust those APIs to the verifier. The measured wrapper must also have no vulnerability that…","h":"/mechanisms/safeguard-attestation/#flaw-4","host":"M-0023","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-547.7,"y":-10.9},{"id":"M-0023.F5","k":"F","l":"Memory-bus interposition extracts attestation keys and forges…","n":"Memory-bus interposition extracts attestation keys and forges attestations","d":"With physical access to a server's DDR5 memory bus and equipment costing under $1,000, researchers extracted a per-CPU Intel attestation provisioning key and forged TDX attestations. Against AMD SEV-SNP the same attack recovered a signing key used inside the…","h":"/mechanisms/safeguard-attestation/#flaw-5","host":"M-0023","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-526.7,"y":-24.1},{"id":"M-0001.B1","k":"B","l":"Recording all inference traffic needs network taps and…","n":"Recording all inference traffic needs network taps and recomputation servers that can ingest it, in the worst case one recomputation-server network interface per inference front-end interface.","d":"Coverage & hidden compute","h":"/mechanisms/sampled-inference-recomputation/#blocker-1","host":"M-0001","theme":"coverage-hidden-compute","cat":"cryptographic-computational","w":3,"x":-196.7,"y":419.6},{"id":"M-0001.B2","k":"B","l":"The recomputation server must sit inside the prover's…","n":"The recomputation server must sit inside the prover's data centre, possibly under the prover's physical control, and still be protected from a compromised provider, which Amodo rates 'not on track'.","d":"Hardware trust","h":"/mechanisms/sampled-inference-recomputation/#blocker-2","host":"M-0001","theme":"hardware-trust","cat":"cryptographic-computational","w":2,"x":-190.1,"y":408.4},{"id":"M-0001.B3","k":"B","l":"No independent red-team of a recomputation consistency…","n":"No independent red-team of a recomputation consistency check has been published (the one independent attack study targets the weight-exfiltration bound), and Amodo rates recomputation red-teaming 'not started'.","d":"Adversarial validation","h":"/mechanisms/sampled-inference-recomputation/#blocker-3","host":"M-0001","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-132.7,"y":431.8},{"id":"M-0001.B4","k":"B","l":"Tolerance-based checks need calibration on trusted…","n":"Tolerance-based checks need calibration on trusted hardware and exact knowledge of the provider's sampling procedure, and in one prototype a sampling-implementation mismatch produced large spurious differences.","d":"Performance & compatibility","h":"/mechanisms/sampled-inference-recomputation/#blocker-4","host":"M-0001","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-135.7,"y":444.5},{"id":"M-0001.B5","k":"B","l":"The verifier needs the model weights, so checking a…","n":"The verifier needs the model weights, so checking a closed-weights model requires a confidential recomputation environment inside the prover's facility.","d":"Privacy & leakage","h":"/mechanisms/sampled-inference-recomputation/#blocker-5","host":"M-0001","theme":"privacy-leakage","cat":"cryptographic-computational","w":2,"x":-144.7,"y":453.9},{"id":"M-0001.F1","k":"F","l":"Tolerance for numerical noise leaves a covert channel","n":"Tolerance for numerical noise leaves a covert channel","d":"Schemes that accept approximate matches can put an upper bound on an adversary's covert bandwidth, but they cannot close the channel. The weight-exfiltration detector cut exfiltratable information to under 0.5%, not to zero, on a 30-billion-parameter…","h":"/mechanisms/sampled-inference-recomputation/#flaw-1","host":"M-0001","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-158.1,"y":458.7},{"id":"M-0001.F2","k":"F","l":"Only recorded traffic is checked","n":"Only recorded traffic is checked","d":"Recomputation checks that recorded, declared workloads are correct. It cannot show that the record is complete. The published schemes do not cover hidden workloads run on the same compute, or substituted work. Rinberg et al. say their exfiltration-detection…","h":"/mechanisms/sampled-inference-recomputation/#flaw-2","host":"M-0001","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-176,"y":456.5},{"id":"M-0001.F3","k":"F","l":"Some inference optimizations are not covered","n":"Some inference optimizations are not covered","d":"TOPLOC's authors state that it cannot detect speculative decoding in which a cheaper model does the decoding. They did not test whether it distinguishes types of key-value (KV) cache compression. DiFR was evaluated only on sampling from a single model. Its…","h":"/mechanisms/sampled-inference-recomputation/#flaw-3","host":"M-0001","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-190.4,"y":445.7},{"id":"M-0001.F4","k":"F","l":"Mixed hardware widens the honest baseline","n":"Mixed hardware widens the honest baseline","d":"When honest reference runs span different GPU types, the spread of benign scores grows. In DiFR's tests on Qwen3-30B-A3B, mixing A100 and H200 runs made the smallest deviation tested harder to separate from honest behaviour. That deviation was a temperature…","h":"/mechanisms/sampled-inference-recomputation/#flaw-4","host":"M-0001","cat":"cryptographic-computational","sev":"minor","fk":"Open question","st":"open","w":1,"x":-197,"y":432.6},{"id":"M-0022.B1","k":"B","l":"No prototype or red-team exists; the design is a…","n":"No prototype or red-team exists; the design is a first-pass viability study.","d":"Adversarial validation","h":"/mechanisms/side-channel-suppression/#blocker-1","host":"M-0022","theme":"adversarial-validation","cat":"off-chip-devices","w":2,"x":390.3,"y":-246.9},{"id":"M-0022.B2","k":"B","l":"Costs of power-line filters, and supply of the…","n":"Costs of power-line filters, and supply of the transceivers needed for optical conversion, are uncertain at scale.","d":"Performance & compatibility","h":"/mechanisms/side-channel-suppression/#blocker-2","host":"M-0022","theme":"performance-compatibility","cat":"off-chip-devices","w":2,"x":406.7,"y":-249.1},{"id":"M-0022.F1","k":"F","l":"Supply-chain implants may evade inspection","n":"Supply-chain implants may evade inspection","d":"Cankaya identifies malicious hardware embedded deep in purchased components as a residual risk that visual inspection and disassembly may not catch. He notes that radiographic examination under high-security standards could mitigate it.","h":"/mechanisms/side-channel-suppression/#flaw-1","host":"M-0022","cat":"off-chip-devices","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":425.9,"y":-237.3},{"id":"M-0022.F2","k":"F","l":"Openings for airflow, power and optics weaken shielding","n":"Openings for airflow, power and optics weaken shielding","d":"Cankaya notes that keeping attenuation high while passing high-power airflow, cabling and optical links adds complexity beyond existing shielded-enclosure specifications.","h":"/mechanisms/side-channel-suppression/#flaw-2","host":"M-0022","cat":"off-chip-devices","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":433.1,"y":-210.4},{"id":"M-0022.F3","k":"F","l":"Inspection assumptions may not hold","n":"Inspection assumptions may not hold","d":"The design's statistical argument assumes that visual or disassembly inspection catches every flaw that is present in a sampled unit. Cankaya is unsure whether destructive teardowns are defence-dominant or offence-dominant.","h":"/mechanisms/side-channel-suppression/#flaw-3","host":"M-0022","cat":"off-chip-devices","sev":"significant","fk":"Open question","st":"open","w":1,"x":423.8,"y":-194.1},{"id":"M-0017.B1","k":"B","l":"No tamper-evident enclosure has been designed for AI…","n":"No tamper-evident enclosure has been designed for AI verifier hardware at retrofit scale.","d":"Hardware trust","h":"/mechanisms/tamper-evidence-for-verifier-devices/#blocker-1","host":"M-0017","theme":"hardware-trust","cat":"off-chip-devices","w":2,"x":423.4,"y":-330.6},{"id":"M-0017.B2","k":"B","l":"Battery-backed designs add bulk, limit operating…","n":"Battery-backed designs add bulk, limit operating temperature (+10 °C to +35 °C for the IBM 4765) and complicate transport.","d":"Performance & compatibility","h":"/mechanisms/tamper-evidence-for-verifier-devices/#blocker-2","host":"M-0017","theme":"performance-compatibility","cat":"off-chip-devices","w":2,"x":414.5,"y":-319.4},{"id":"M-0017.B3","k":"B","l":"Active monitoring needs power, and visual inspection of…","n":"Active monitoring needs power, and visual inspection of large enclosures faces access limits.","d":"Access & governance","h":"/mechanisms/tamper-evidence-for-verifier-devices/#blocker-3","host":"M-0017","theme":"access-governance","cat":"off-chip-devices","w":2,"x":373.9,"y":-367.6},{"id":"M-0017.B4","k":"B","l":"No evaluation has been published in the AI verification…","n":"No evaluation has been published in the AI verification setting.","d":"Adversarial validation","h":"/mechanisms/tamper-evidence-for-verifier-devices/#blocker-4","host":"M-0017","theme":"adversarial-validation","cat":"off-chip-devices","w":2,"x":384.6,"y":-375},{"id":"M-0017.F1","k":"F","l":"Seals are often defeated with simple methods","n":"Seals are often defeated with simple methods","d":"In 1996 a Los Alamos vulnerability assessment defeated all 94 security seals it examined, with 132 defeats in total, using rapid, inexpensive, low-tech methods. It found that seal cost did not predict security. In 2001 Johnston reported that high-tech seals…","h":"/mechanisms/tamper-evidence-for-verifier-devices/#flaw-1","host":"M-0017","cat":"off-chip-devices","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":399.1,"y":-374.2},{"id":"M-0017.F2","k":"F","l":"Security depends on inspection protocols","n":"Security depends on inspection protocols","d":"Johnston argues that a seal is no better than the protocols for using it, and that inspectors are usually given little useful information on how to detect tampering. The Sandia survey notes that larger enclosures are hard to inspect fully and that sensor data…","h":"/mechanisms/tamper-evidence-for-verifier-devices/#flaw-2","host":"M-0017","cat":"off-chip-devices","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":416.5,"y":-363.3},{"id":"M-0017.F3","k":"F","l":"Attack classes outside published models","n":"Attack classes outside published models","d":"The authors of the batteryless cover say they cannot assess chemical-solvent attacks, which exceed their expertise, and deem cover removal impractical. Anti-Tamper Radio's reference can drift as the environment or measurement system ages; the authors suggest…","h":"/mechanisms/tamper-evidence-for-verifier-devices/#flaw-3","host":"M-0017","cat":"off-chip-devices","sev":"significant","fk":"Open question","st":"open","w":1,"x":424.8,"y":-344.6},{"id":"M-0008.B1","k":"B","l":"Vendor threat models exclude sophisticated physical…","n":"Vendor threat models exclude sophisticated physical attacks, but in international verification the prover holds the hardware.","d":"Hardware trust","h":"/mechanisms/tee-remote-attestation/#blocker-1","host":"M-0008","theme":"hardware-trust","cat":"on-chip","w":3,"x":-119,"y":-447.4},{"id":"M-0008.B2","k":"B","l":"Negative claims such as \"no undeclared training\" need…","n":"Negative claims such as \"no undeclared training\" need chip-wide accounting of all workloads, which attestation does not provide.","d":"Coverage & hidden compute","h":"/mechanisms/tee-remote-attestation/#blocker-2","host":"M-0008","theme":"coverage-hidden-compute","cat":"on-chip","w":3,"x":-118.4,"y":-434.4},{"id":"M-0008.B3","k":"B","l":"Multi-GPU and multi-node coverage is incomplete,…","n":"Multi-GPU and multi-node coverage is incomplete, because Hopper leaves NVLink traffic unencrypted and NVIDIA's early-access release supported only single nodes in mid-2025.","d":"Performance & compatibility","h":"/mechanisms/tee-remote-attestation/#blocker-3","host":"M-0008","theme":"performance-compatibility","cat":"on-chip","w":2,"x":-185.8,"y":-433.3},{"id":"M-0008.B4","k":"B","l":"Rival parties have not agreed on trust roots and key…","n":"Rival parties have not agreed on trust roots and key provenance they would accept.","d":"Access & governance","h":"/mechanisms/tee-remote-attestation/#blocker-4","host":"M-0008","theme":"access-governance","cat":"on-chip","w":2,"x":-185.9,"y":-420.3},{"id":"M-0008.B5","k":"B","l":"CPU-only enclaves are costly for large models, because…","n":"CPU-only enclaves are costly for large models, because in the Attestable Audits prototype CPU inference cost 21.7 times as much per token as GPU inference and the enclave roughly doubled the CPU cost.","d":"Performance & compatibility","h":"/mechanisms/tee-remote-attestation/#blocker-5","host":"M-0008","theme":"performance-compatibility","cat":"on-chip","w":2,"x":-174.9,"y":-454.9},{"id":"M-0008.F1","k":"F","l":"DDR5 memory-bus interposer forges Intel TDX attestations and…","n":"DDR5 memory-bus interposer forges Intel TDX attestations and leaks SEV-SNP secrets (TEE.fail)","d":"Independent researchers placed an interposer, built for under $1000, on the DDR5 memory bus of servers running Intel TDX and AMD SEV-SNP. Server TEEs encrypt memory deterministically, without integrity or freshness protection, and the researchers exploited…","h":"/mechanisms/tee-remote-attestation/#flaw-1","host":"M-0008","cat":"on-chip","sev":"critical","fk":"Demonstrated attack","st":"open","crit":true,"w":1,"x":-164.5,"y":-462.7},{"id":"M-0008.F2","k":"F","l":"DDR4 memory-bus interposers forge SGX and SEV-SNP attestation…","n":"DDR4 memory-bus interposers forge SGX and SEV-SNP attestation (Battering RAM, WireTap)","d":"Two independent teams broke server TEE attestation on DDR4 memory with interposers they built themselves. Both attacks need physical access to install the device and root privileges on the host. - Battering RAM, by researchers at KU Leuven and the…","h":"/mechanisms/tee-remote-attestation/#flaw-2","host":"M-0008","cat":"on-chip","sev":"critical","fk":"Demonstrated attack","st":"open","crit":true,"w":1,"x":-138.7,"y":-463.9},{"id":"M-0008.F3","k":"F","l":"Software-only forgery of SEV-SNP attestation (RMPocalypse)","n":"Software-only forgery of SEV-SNP attestation (RMPocalypse)","d":"Researchers at ETH Zurich showed that a malicious hypervisor can corrupt the Reverse Map Table (RMP) while SEV-SNP initialises it. SEV-SNP uses the RMP to store security metadata for every DRAM page, and a single 8-byte overwrite leaves the whole table…","h":"/mechanisms/tee-remote-attestation/#flaw-3","host":"M-0008","cat":"on-chip","sev":"critical","fk":"Demonstrated attack","st":"mitigated","w":1,"x":-122.5,"y":-422.1},{"id":"M-0008.F4","k":"F","l":"H100 attestation not bound to a specific confidential VM","n":"H100 attestation not bound to a specific confidential VM","d":"The TEE.fail authors fetched genuine H100 confidential-computing attestations from a rented server running their TDX VM. They combined these with forged TDX quotes. A proxy running outside any TEE then passed both the TDX and the GPU attestation checks. The…","h":"/mechanisms/tee-remote-attestation/#flaw-4","host":"M-0008","cat":"on-chip","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-127.6,"y":-457.2},{"id":"M-0008.F5","k":"F","l":"Software side channels and controlled-channel attacks on CPU…","n":"Software side channels and controlled-channel attacks on CPU TEEs","d":"PALM and Attestable Audits cite published side-channel, single-stepping, interrupt-injection and memory-aliasing attacks on Intel TDX and AMD SEV, including T-Time, TDXploit, CIPHER-LEAKS, Heckler and BadRAM. PALM treats them as out of scope. Attestable…","h":"/mechanisms/tee-remote-attestation/#flaw-5","host":"M-0008","cat":"on-chip","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-164.8,"y":-405.4},{"id":"M-0008.F6","k":"F","l":"Attestation covers launch state, and measurements can be…","n":"Attestation covers launch state, and measurements can be incomplete","d":"Attestation measures launch state, not runtime state. Data loaded later, such as model weights, must be bound separately. Gloria Z argues that gaps in measuring feature flags, environment variables and invocation arguments are \"perhaps the most likely failure…","h":"/mechanisms/tee-remote-attestation/#flaw-6","host":"M-0008","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-176.2,"y":-411.5},{"id":"M-0008.F7","k":"F","l":"Deployment-level attestation does not cover the whole chip","n":"Deployment-level attestation does not cover the whole chip","d":"An attestation shows what one confidential VM runs. It does not show what else the hypervisor runs on the same hardware. Gloria Z calls the difference between deployment-level attestation and chip-wide monitoring \"the gaping hole in this plan\". This matters…","h":"/mechanisms/tee-remote-attestation/#flaw-7","host":"M-0008","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-184.6,"y":-446.2},{"id":"M-0008.F8","k":"F","l":"Root of trust concentrated in a few hardware vendors","n":"Root of trust concentrated in a few hardware vendors","d":"The root of trust is the certificate authorities of a small number of vendors (AMD, Intel and NVIDIA), which generate the keys and fuse them onto the chips. Gloria Z notes that whoever has access to a hardware key, or can certify one, can in principle produce…","h":"/mechanisms/tee-remote-attestation/#flaw-8","host":"M-0008","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-151.7,"y":-464.8},{"id":"M-0016.B1","k":"B","l":"No network-level memory challenge across data-centre…","n":"No network-level memory challenge across data-centre servers has been demonstrated.","d":"Adversarial validation","h":"/mechanisms/timed-challenge-response/#blocker-1","host":"M-0016","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-364.3,"y":-321.4},{"id":"M-0016.B2","k":"B","l":"Challenges that fill memory displace workloads; filling…","n":"Challenges that fill memory displace workloads; filling a pod's volatile memory takes tens of minutes and SSDs take hours.","d":"Performance & compatibility","h":"/mechanisms/timed-challenge-response/#blocker-2","host":"M-0016","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-346,"y":-325},{"id":"M-0016.B3","k":"B","l":"Outside help, such as remote memory, must be excluded…","n":"Outside help, such as remote memory, must be excluded during challenges.","d":"Coverage & hidden compute","h":"/mechanisms/timed-challenge-response/#blocker-3","host":"M-0016","theme":"coverage-hidden-compute","cat":"cryptographic-computational","w":3,"x":-331.9,"y":-318.5},{"id":"M-0016.F1","k":"F","l":"Timing-based software attestation has been broken in practice","n":"Timing-based software attestation has been broken in practice","d":"Castelluccia et al. implemented two generic attacks, one based on a return-oriented rootkit and one on code compression, together with specific attacks on SWATT and ICE-based schemes, on commodity sensor nodes. They conclude that secure time-based attestation…","h":"/mechanisms/timed-challenge-response/#flaw-1","host":"M-0016","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-373,"y":-269.2},{"id":"M-0016.F2","k":"F","l":"Remote memory narrows the timing margin","n":"Remote memory narrows the timing margin","d":"Data-centre remote memory access returns in about 1–2 µs, against about 70–200 ns for local DRAM. The MIRI overview says verification of memory saturation depends on ruling out remote access by latency or physical disconnection. It adds that pre-staging data…","h":"/mechanisms/timed-challenge-response/#flaw-2","host":"M-0016","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-381.9,"y":-281.9},{"id":"M-0016.F3","k":"F","l":"Error rates not quantified","n":"Error rates not quantified","d":"Monfared et al. show separable timing distributions but do not define thresholds or statistical tests, so false-positive and false-negative rates are not quantified.","h":"/mechanisms/timed-challenge-response/#flaw-3","host":"M-0016","cat":"cryptographic-computational","sev":"minor","fk":"Open question","st":"open","w":1,"x":-381.7,"y":-300.5},{"id":"M-0021.B1","k":"B","l":"Software telemetry is trustworthy only if on-chip…","n":"Software telemetry is trustworthy only if on-chip counters are read over a path the operator cannot tamper with.","d":"Hardware trust","h":"/mechanisms/workload-classification-from-telemetry/#blocker-1","host":"M-0021","theme":"hardware-trust","cat":"remote-sensing","w":3,"x":552.6,"y":7.4},{"id":"M-0021.B2","k":"B","l":"No independent red-team or third-party reliance has…","n":"No independent red-team or third-party reliance has been reported.","d":"Adversarial validation","h":"/mechanisms/workload-classification-from-telemetry/#blocker-2","host":"M-0021","theme":"adversarial-validation","cat":"remote-sensing","w":2,"x":545.4,"y":27.5},{"id":"M-0021.B3","k":"B","l":"Results do not yet cover multi-node clusters, other…","n":"Results do not yet cover multi-node clusters, other vendors or multi-tenant serving.","d":"Coverage & hidden compute","h":"/mechanisms/workload-classification-from-telemetry/#blocker-3","host":"M-0021","theme":"coverage-hidden-compute","cat":"remote-sensing","w":2,"x":533.3,"y":36.8},{"id":"M-0021.F1","k":"F","l":"Software-read counters can be forged by a privileged operator","n":"Software-read counters can be forged by a privileged operator","d":"Rahman and Tajdari state that without hardware-enabled guarantees, an adversary with software privilege can return forged counter values. Their results assume a tamper-resistant read path and an authenticated telemetry channel. Gargiulo and Kulp note that…","h":"/mechanisms/workload-classification-from-telemetry/#flaw-1","host":"M-0021","cat":"remote-sensing","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":519,"y":38},{"id":"M-0021.F2","k":"F","l":"Unseen evasion strategies still reduce detection","n":"Unseen evasion strategies still reduce detection","d":"Rahman and Tajdari gave the evader white-box access to the previous round's classifier in their fifth round. After hardening against the other strategies of that round, their classifier detected the held-out white-box strategies only 43–87% of the time,…","h":"/mechanisms/workload-classification-from-telemetry/#flaw-2","host":"M-0021","cat":"remote-sensing","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":524.2,"y":-25.6},{"id":"M-0021.F3","k":"F","l":"The training-inference boundary may blur","n":"The training-inference boundary may blur","d":"Ansari argues that as inference-time compute scaling and fine-tuning become more capable, the training-inference distinction may cease to be a reliable governance boundary.","h":"/mechanisms/workload-classification-from-telemetry/#flaw-3","host":"M-0021","cat":"remote-sensing","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":536.9,"y":-23.1},{"id":"M-0021.F4","k":"F","l":"Limited scale and hardware coverage","n":"Limited scale and hardware coverage","d":"Rahman and Tajdari's experiments are single-node, with up to 8 GPUs, and cover NVIDIA hardware only. Gargiulo and Kulp's corpus was collected on a single H200 NVL, and generalization across devices remains to be established.","h":"/mechanisms/workload-classification-from-telemetry/#flaw-4","host":"M-0021","cat":"remote-sensing","sev":"significant","fk":"Open question","st":"open","w":1,"x":547.4,"y":-12.5},{"id":"M-0004.B1","k":"B","l":"Proving takes about 12 to 13 minutes per 2,048-token…","n":"Proving takes about 12 to 13 minutes per 2,048-token forward pass of a 13B model on one A100, and a verification system design calls the overhead heavy.","d":"Performance & compatibility","h":"/mechanisms/zk-proofs-of-inference/#blocker-1","host":"M-0004","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-479.9,"y":270.7},{"id":"M-0004.B2","k":"B","l":"ZKML and zkLLM prove fixed-point arithmetic, and…","n":"ZKML and zkLLM prove fixed-point arithmetic, and floating-point emulation in ZKPs is described as an open problem.","d":"Performance & compatibility","h":"/mechanisms/zk-proofs-of-inference/#blocker-2","host":"M-0004","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-490.8,"y":235.5},{"id":"M-0004.B3","k":"B","l":"zkLLM's code is unaudited, interactive and archived;…","n":"zkLLM's code is unaudited, interactive and archived; the one audited ZK inference library, ezkl, had high-severity circuit soundness bugs before its fixes.","d":"Adversarial validation","h":"/mechanisms/zk-proofs-of-inference/#blocker-3","host":"M-0004","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-484.6,"y":224},{"id":"M-0004.B4","k":"B","l":"Showing that proven inference was the only work done…","n":"Showing that proven inference was the only work done needs a compute-accounting mechanism such as proof-of-work accounting, which is only proposed.","d":"Coverage & hidden compute","h":"/mechanisms/zk-proofs-of-inference/#blocker-4","host":"M-0004","theme":"coverage-hidden-compute","cat":"cryptographic-computational","w":3,"x":-473.2,"y":217.7},{"id":"M-0004.F1","k":"F","l":"The proof covers a fixed-point approximation, not the…","n":"The proof covers a fixed-point approximation, not the floating-point model","d":"Current ZK inference systems prove a quantised version of the network. zkLLM scales values by 2^16 and reports small perplexity changes. Attestable reports quantising matrix multiplications to 8-bit integers while proving other operations in floating point. A…","h":"/mechanisms/zk-proofs-of-inference/#flaw-1","host":"M-0004","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-441.1,"y":271.5},{"id":"M-0004.F2","k":"F","l":"A proof speaks only for the computations that were proven","n":"A proof speaks only for the computations that were proven","d":"Attestable writes that \"a proof of some computation is not a proof of all computation\", and that a proof cannot discover a datacenter that was never declared. Proofs of inference do not by themselves show that no other workload ran on the same or other…","h":"/mechanisms/zk-proofs-of-inference/#flaw-2","host":"M-0004","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-452.1,"y":278.6},{"id":"M-0004.F3","k":"F","l":"The model architecture is disclosed","n":"The model architecture is disclosed","d":"ZKML \"requires that the model architecture (but not weights) is revealed\", and zkLLM assumes a publicly known model structure. Architecture can be commercially sensitive.","h":"/mechanisms/zk-proofs-of-inference/#flaw-3","host":"M-0004","cat":"cryptographic-computational","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":-465.1,"y":278.7},{"id":"M-0004.F4","k":"F","l":"Proofs do not bind computational effort (Hollow-LLM)","n":"Proofs do not bind computational effort (Hollow-LLM)","d":"Researchers at the University of Southern California show that a proof of inference certifies that an output is consistent with committed weights under the declared architecture, but not how much computation produced it. In their Hollow-LLM attack, a provider…","h":"/mechanisms/zk-proofs-of-inference/#flaw-4","host":"M-0004","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-490.8,"y":252.5},{"id":"M-0005.B1","k":"B","l":"Proving costs minutes per training step even for small…","n":"Proving costs minutes per training step even for small models: 15 minutes per VGG-11 iteration and 47.5 to 328.3 seconds per single-image MobileNet v2 SGD step.","d":"Performance & compatibility","h":"/mechanisms/zk-proofs-of-training-constraints/#blocker-1","host":"M-0005","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-457.7,"y":-130.9},{"id":"M-0005.B2","k":"B","l":"The frontier design is unbuilt and lists 13 open…","n":"The frontier design is unbuilt and lists 13 open problems, including zero-knowledge proofs of backpropagation and deterministic attention backward passes with low overhead.","d":"Protocol soundness","h":"/mechanisms/zk-proofs-of-training-constraints/#blocker-2","host":"M-0005","theme":"protocol-soundness","cat":"cryptographic-computational","w":2,"x":-445.1,"y":-133.7},{"id":"M-0005.B3","k":"B","l":"The frontier design needs deterministic training;…","n":"The frontier design needs deterministic training; current deterministic tensor-parallel all-reduce is reported to lose 64 to 89% of bandwidth.","d":"Performance & compatibility","h":"/mechanisms/zk-proofs-of-training-constraints/#blocker-3","host":"M-0005","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-432.6,"y":-128.8},{"id":"M-0005.B4","k":"B","l":"The frontier design needs an open-hardware network tap…","n":"The frontier design needs an open-hardware network tap at line rate, listed as an open problem.","d":"Hardware trust","h":"/mechanisms/zk-proofs-of-training-constraints/#blocker-4","host":"M-0005","theme":"hardware-trust","cat":"cryptographic-computational","w":3,"x":-446.8,"y":-68},{"id":"M-0005.B5","k":"B","l":"Mixture-of-experts, reinforcement-learning…","n":"Mixture-of-experts, reinforcement-learning post-training and multi-site training are not yet covered.","d":"Coverage & hidden compute","h":"/mechanisms/zk-proofs-of-training-constraints/#blocker-5","host":"M-0005","theme":"coverage-hidden-compute","cat":"cryptographic-computational","w":2,"x":-459.9,"y":-69.3},{"id":"M-0005.F1","k":"F","l":"Sparse challenge-based auditing gives probabilistic detection…","n":"Sparse challenge-based auditing gives probabilistic detection only","d":"In the frontier design, proofs are generated only for training steps the auditor challenges after the hash chain is frozen. The authors describe this as \"detection-grade, not universal\": the verifier \"cannot make universal claims about every step\", but can…","h":"/mechanisms/zk-proofs-of-training-constraints/#flaw-1","host":"M-0005","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-470.4,"y":-77},{"id":"M-0005.F2","k":"F","l":"The network anchor misses traffic inside a server","n":"The network anchor misses traffic inside a server","d":"The frontier design observes traffic between nodes only, so \"intra-node NVLink is invisible\". Its attested-SmartNIC tier is weaker than a physical tap against firmware or supply-chain adversaries.","h":"/mechanisms/zk-proofs-of-training-constraints/#flaw-2","host":"M-0005","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-477.1,"y":-90},{"id":"M-0005.F3","k":"F","l":"Proven training uses fixed-point arithmetic","n":"Proven training uses fixed-point arithmetic","d":"Kaizen and ZkAudit prove training in fixed point. ZkAudit reports accuracy 0.5 to 0.7 points below fp32 on three image datasets. The frontier design proposes native floating-point precompiles, and lists the algebraic reductions needed to verify floating-point…","h":"/mechanisms/zk-proofs-of-training-constraints/#flaw-3","host":"M-0005","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-477.1,"y":-108.5},{"id":"M-0005.F4","k":"F","l":"A proof binds committed data but does not vet it","n":"A proof binds committed data but does not vet it","d":"ZkAudit notes that it does not protect against data poisoning, and that it reveals the model architecture. Whether committed data obeys a rule needs a separate proven audit function.","h":"/mechanisms/zk-proofs-of-training-constraints/#flaw-4","host":"M-0005","cat":"cryptographic-computational","sev":"minor","fk":"Open question","st":"open","w":1,"x":-468.8,"y":-123.5},{"id":"I-0011.B1","k":"B","l":"A fully reproducible inference stack needs substantial…","n":"A fully reproducible inference stack needs substantial software and tooling, and per-packet network reproducibility may need considerable software, firmware and possibly hardware work.","d":"Performance & compatibility","h":"/implementations/ai-2040-inference-only-verification-plan/#blocker-1","host":"I-0011","theme":"performance-compatibility","cat":"isolation-architecture","w":3,"x":182.4,"y":677.7},{"id":"I-0011.B2","k":"B","l":"Passive optical taps work at 400G, but the 800G and…","n":"Passive optical taps work at 400G, but the 800G and 1600G line rates now arriving in data centres are undemonstrated.","d":"Performance & compatibility","h":"/implementations/ai-2040-inference-only-verification-plan/#blocker-2","host":"I-0011","theme":"performance-compatibility","cat":"isolation-architecture","w":3,"x":245.4,"y":657.9},{"id":"I-0011.B3","k":"B","l":"Checking that taps are correctly installed and stay in…","n":"Checking that taps are correctly installed and stay in place at scale is not a solved problem, and hardening the recomputation server inside the prover's facility needs significant research.","d":"Hardware trust","h":"/implementations/ai-2040-inference-only-verification-plan/#blocker-3","host":"I-0011","theme":"hardware-trust","cat":"isolation-architecture","w":3,"x":244.4,"y":670.9},{"id":"I-0011.B4","k":"B","l":"There is no plan yet for quickly scaling side-channel…","n":"There is no plan yet for quickly scaling side-channel defences on a frontier cluster; only early theoretical pieces exist.","d":"Coverage & hidden compute","h":"/implementations/ai-2040-inference-only-verification-plan/#blocker-4","host":"I-0011","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":237.2,"y":682.8},{"id":"I-0011.B5","k":"B","l":"Memory wiping may use existing algorithms, but hardware…","n":"Memory wiping may use existing algorithms, but hardware testing is at an early stage.","d":"Coverage & hidden compute","h":"/implementations/ai-2040-inference-only-verification-plan/#blocker-5","host":"I-0011","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":222.1,"y":692.5},{"id":"I-0011.B6","k":"B","l":"Recomputation red-teaming has not started.","n":"Recomputation red-teaming has not started.","d":"Adversarial validation","h":"/implementations/ai-2040-inference-only-verification-plan/#blocker-6","host":"I-0011","theme":"adversarial-validation","cat":"isolation-architecture","w":2,"x":203.6,"y":693.5},{"id":"I-0011.F1","k":"F","l":"The recomputation server must be trusted","n":"The recomputation server must be trusted","d":"The plan calls the integrity of the recomputation server an extremely important aspect, and its argument that sampling verifies all outputs assumes that the server's computations and outputs can be trusted. The companion page notes that the server sits inside…","h":"/implementations/ai-2040-inference-only-verification-plan/#flaw-1","host":"I-0011","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":190.5,"y":687.9},{"id":"I-0011.F2","k":"F","l":"Spare compute is not verified","n":"Spare compute is not verified","d":"The plan states that it does not verify that spare compute is unused for unapproved workloads, because this seems very challenging. It relies instead on side-channel bounds and memory wipes, so that the only results that persist are verified inference outputs.","h":"/implementations/ai-2040-inference-only-verification-plan/#flaw-2","host":"I-0011","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":180.5,"y":664.8},{"id":"I-0011.F3","k":"F","l":"A recomputation family degrades against prompt-controlling…","n":"A recomputation family degrades against prompt-controlling adversaries","d":"The plan's companion page names DiFR among the recomputation schemes being tested. An independent study found that Gumbel-based inference verification, the family that includes Token-DiFR, leaks roughly twice as many bits per token when the adversary chooses…","h":"/implementations/ai-2040-inference-only-verification-plan/#flaw-3","host":"I-0011","cat":"isolation-architecture","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":239.5,"y":646.1},{"id":"I-0013.B1","k":"B","l":"Published binaries cannot be rebuilt from source and…","n":"Published binaries cannot be rebuilt from source and carry no symbols, so checking what the attested software does needs reverse engineering.","d":"Evidence binding","h":"/implementations/apple-private-cloud-compute/#blocker-1","host":"I-0013","theme":"evidence-binding","cat":"on-chip","w":2,"x":126.9,"y":-692.8},{"id":"I-0013.B2","k":"B","l":"Only Apple's own client software sends requests to PCC,…","n":"Only Apple's own client software sends requests to PCC, and there is no API for third parties.","d":"Access & governance","h":"/implementations/apple-private-cloud-compute/#blocker-2","host":"I-0013","theme":"access-governance","cat":"on-chip","w":2,"x":141.6,"y":-706},{"id":"I-0013.F1","k":"F","l":"Tampered node configuration passed attestation","n":"Tampered node configuration passed attestation","d":"Working in Apple's Virtual Research Environment, an independent researcher used a path traversal in darwin-init, which unpacks software archives when a node boots, to write files as root that survived the node's userspace reboot. The change redirected a…","h":"/implementations/apple-private-cloud-compute/#flaw-1","host":"I-0013","cat":"on-chip","sev":"significant","fk":"Demonstrated attack","st":"mitigated","w":1,"x":177.4,"y":-699.4},{"id":"I-0013.F2","k":"F","l":"Google Cloud deployment relies on TEEs whose attestations have…","n":"Google Cloud deployment relies on TEEs whose attestations have been forged","d":"Apple reports that PCC on Google Cloud uses NVIDIA confidential computing, Intel CPUs with TDX and Google's Titan chip, with attestation rooted in at least two separate roots of trust from independent vendors. With physical access and root privileges,…","h":"/implementations/apple-private-cloud-compute/#flaw-2","host":"I-0013","cat":"on-chip","sev":"significant","fk":"Open question","st":"open","w":1,"x":186.9,"y":-680.5},{"id":"I-0007.B1","k":"B","l":"The prototype needs porting to GPU confidential…","n":"The prototype needs porting to GPU confidential computing to handle larger models; the authors expect an overhead as small as 5 times there.","d":"Performance & compatibility","h":"/implementations/attestable-audits/#blocker-1","host":"I-0007","theme":"performance-compatibility","cat":"on-chip","w":3,"x":-125.9,"y":-653.7},{"id":"I-0007.B2","k":"B","l":"As of September 2026 no code has been released for the…","n":"As of September 2026 no code has been released for the prototype.","d":"Adversarial validation","h":"/implementations/attestable-audits/#blocker-2","host":"I-0007","theme":"adversarial-validation","cat":"on-chip","w":2,"x":-114.1,"y":-640.1},{"id":"I-0007.F1","k":"F","l":"Relies on the TEE vendor and inherits TEE attacks","n":"Relies on the TEE vendor and inherits TEE attacks","d":"The design depends on trusting the TEE vendor, AWS in the prototype. The authors cite memory-aliasing, ciphertext side-channel and malicious-interrupt attacks on confidential VMs (BadRAM, CIPHER-LEAKS, Heckler). Their answer is to revoke vulnerable base…","h":"/implementations/attestable-audits/#flaw-1","host":"I-0007","cat":"on-chip","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-175.4,"y":-624.6},{"id":"I-0007.F2","k":"F","l":"Prompt-based model exfiltration is a residual gap","n":"Prompt-based model exfiltration is a residual gap","d":"The authors state that \"prompt-based model exfiltration during the user interaction step remains a residual gap\".","h":"/implementations/attestable-audits/#flaw-2","host":"I-0007","cat":"on-chip","sev":"significant","fk":"Open question","st":"open","w":1,"x":-172.2,"y":-641.2},{"id":"I-0007.F3","k":"F","l":"CPU-only enclaves force small, quantized models and high cost","n":"CPU-only enclaves force small, quantized models and high cost","d":"Memory limits required 4-bit quantization, which lowered zero-shot MMLU accuracy from 54.6% to 51.4%. CPU inference cost 21.7 times as much per token as GPU inference, and the enclave roughly doubled the CPU cost. The authors wrote that H100 confidential…","h":"/implementations/attestable-audits/#flaw-3","host":"I-0007","cat":"on-chip","sev":"minor","fk":"Open question","st":"open","w":1,"x":-152.8,"y":-656.4},{"id":"I-0005.B1","k":"B","l":"No paper, protocol specification or code is public, so…","n":"No paper, protocol specification or code is public, so the reported results cannot be reproduced.","d":"Adversarial validation","h":"/implementations/attestable-zk-inference/#blocker-1","host":"I-0005","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-655.9,"y":112.9},{"id":"I-0005.B2","k":"B","l":"Attestable reports a context window limited to 16K…","n":"Attestable reports a context window limited to 16K tokens.","d":"Performance & compatibility","h":"/implementations/attestable-zk-inference/#blocker-2","host":"I-0005","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-668.2,"y":87.4},{"id":"I-0005.B3","k":"B","l":"Covering computation that is not proven relies on…","n":"Covering computation that is not proven relies on proof-of-work accounting, which Attestable has only proposed.","d":"Coverage & hidden compute","h":"/implementations/attestable-zk-inference/#blocker-3","host":"I-0005","theme":"coverage-hidden-compute","cat":"cryptographic-computational","w":3,"x":-660.5,"y":64.8},{"id":"I-0005.F1","k":"F","l":"Proves an 8-bit quantised variant of the model","n":"Proves an 8-bit quantised variant of the model","d":"Attestable reports that matrix multiplications are dynamically quantised to 8-bit integers, while non-linear operations are proven in floating point. It reports that its IFEval result \"shows where the current quantization still needs improvement\". The proven…","h":"/implementations/attestable-zk-inference/#flaw-1","host":"I-0005","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-646.1,"y":56.2},{"id":"I-0005.F2","k":"F","l":"A proof covers only the computation it is about","n":"A proof covers only the computation it is about","d":"Attestable states that \"a proof of some computation is not a proof of all computation\" and that a proof \"cannot discover a datacenter that was never declared\".","h":"/implementations/attestable-zk-inference/#flaw-2","host":"I-0005","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-639.2,"y":119},{"id":"I-0016.B1","k":"B","l":"Batch invariance costs throughput: on Qwen3-8B the…","n":"Batch invariance costs throughput: on Qwen3-8B the improved deterministic build took 42 s against 26 s for vLLM's default, and SGLang reports an average slowdown of 34.35% on its FlashInfer and FlashAttention 3 backends.","d":"Performance & compatibility","h":"/implementations/batch-invariant-inference-kernels/#blocker-1","host":"I-0016","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-503.8,"y":427},{"id":"I-0016.B2","k":"B","l":"Outputs are identical only while the model, inference…","n":"Outputs are identical only while the model, inference implementation and device stay fixed, so provider and verifier must run the same stack.","d":"Performance & compatibility","h":"/implementations/batch-invariant-inference-kernels/#blocker-2","host":"I-0016","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-537.5,"y":395.2},{"id":"I-0002.B1","k":"B","l":"The verifier needs the model weights, so outsiders…","n":"The verifier needs the model weights, so outsiders cannot use the method to verify providers of closed-weights models.","d":"Privacy & leakage","h":"/implementations/difr/#blocker-1","host":"I-0002","theme":"privacy-leakage","cat":"cryptographic-computational","w":2,"x":-424.3,"y":586.6},{"id":"I-0002.B2","k":"B","l":"The verifier must know and match the provider's…","n":"The verifier must know and match the provider's sampling procedure, and in one re-implementation a sampling mismatch in a newer vLLM version produced large spurious logit differences.","d":"Performance & compatibility","h":"/implementations/difr/#blocker-2","host":"I-0002","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-445.7,"y":570},{"id":"I-0002.B3","k":"B","l":"No independent red-team of DiFR's consistency check has…","n":"No independent red-team of DiFR's consistency check has been published, Amodo rates recomputation red-teaming 'not started', and the one independent attack study targets an exfiltration detector built on the same statistic.","d":"Adversarial validation","h":"/implementations/difr/#blocker-3","host":"I-0002","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-449.8,"y":552.2},{"id":"I-0002.F1","k":"F","l":"Statistical tolerance leaves a covert channel","n":"Statistical tolerance leaves a covert channel","d":"Statistical schemes can put an upper bound on an adversary's covert bandwidth, but cannot close it. In the companion exfiltration study, the detector cut exfiltratable information to under 0.5% under benign prompt traffic. It did not cut it to zero. An…","h":"/implementations/difr/#flaw-1","host":"I-0002","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-444,"y":538},{"id":"I-0002.F2","k":"F","l":"Mixed hardware widens the honest baseline","n":"Mixed hardware widens the honest baseline","d":"For Qwen3-30B-A3B, benign differences between A100 and H200 deployments broadened the honest score distribution. This made the smallest tested change, a temperature raised by 0.1, harder to separate.","h":"/implementations/difr/#flaw-2","host":"I-0002","cat":"cryptographic-computational","sev":"minor","fk":"Open question","st":"open","w":1,"x":-393.1,"y":576.9},{"id":"I-0002.F3","k":"F","l":"Speculative decoding and multi-model sampling not evaluated","n":"Speculative decoding and multi-model sampling not evaluated","d":"The algorithms and experiments cover sampling from a single LLM. Speculative decoding was not evaluated. The authors sketch an extension to one speculative-decoding algorithm, without experiments. They note that other variants would need modified verification…","h":"/implementations/difr/#flaw-3","host":"I-0002","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-405.5,"y":586.2},{"id":"I-0014.B1","k":"B","l":"Proving cost grows steeply with model size: a…","n":"Proving cost grows steeply with model size: a 250,000-parameter nanoGPT took 2,781 s to prove and needed a 219 GB proving key, which South et al. name as the main limit on model size.","d":"Performance & compatibility","h":"/implementations/ezkl/#blocker-1","host":"I-0014","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-707.8,"y":-62.8},{"id":"I-0014.F1","k":"F","l":"Circuit and contract bugs allowed forged proofs","n":"Circuit and contract bugs allowed forged proofs","d":"Trail of Bits found three high-severity soundness bugs in EZKL's circuits: an unsound shuffle argument for min, max and top-k, a decomposition that did not fix the sign of zero, and missing range checks for division and reciprocals. Each would let a malicious…","h":"/implementations/ezkl/#flaw-1","host":"I-0014","cat":"cryptographic-computational","sev":"critical","fk":"Demonstrated attack","st":"mitigated","w":1,"x":-719.4,"y":-93.1},{"id":"I-0014.F2","k":"F","l":"Quantization can activate a backdoor dormant in the…","n":"Quantization can activate a backdoor dormant in the full-precision model","d":"EZKL quantizes values to represent them in a finite field. Trail of Bits built a ResNet-18 whose backdoor is dormant at full precision and active after EZKL's quantization. Larger models and smaller quantization scales make the attack easier. Whether the…","h":"/implementations/ezkl/#flaw-2","host":"I-0014","cat":"cryptographic-computational","sev":"significant","fk":"Demonstrated attack","st":"open","w":1,"x":-699.6,"y":-118.8},{"id":"I-0012.B1","k":"B","l":"Empirical feasibility of passive optical splitting at…","n":"Empirical feasibility of passive optical splitting at 53–112 GBaud under realistic conditions is an open question.","d":"Performance & compatibility","h":"/implementations/low-trust-compute-verification-system-overview/#blocker-1","host":"I-0012","theme":"performance-compatibility","cat":"isolation-architecture","w":3,"x":17.8,"y":661.6},{"id":"I-0012.B2","k":"B","l":"Exact replay needs complete hardware and software…","n":"Exact replay needs complete hardware and software metadata, and the tolerable slowdown from emulation is an open question.","d":"Performance & compatibility","h":"/implementations/low-trust-compute-verification-system-overview/#blocker-2","host":"I-0012","theme":"performance-compatibility","cat":"isolation-architecture","w":3,"x":-38.1,"y":661.4},{"id":"I-0012.B3","k":"B","l":"Tamper-evident, rapidly mass-manufacturable and…","n":"Tamper-evident, rapidly mass-manufacturable and retrofittable enclosures for side-channel defence are an open research question, and physical security against covert communication in every monitored data centre is challenging.","d":"Hardware trust","h":"/implementations/low-trust-compute-verification-system-overview/#blocker-3","host":"I-0012","theme":"hardware-trust","cat":"isolation-architecture","w":3,"x":21.2,"y":636.8},{"id":"I-0012.B4","k":"B","l":"A mass-manufacturable, good-enough side-channel…","n":"A mass-manufacturable, good-enough side-channel defence, particularly power-line filtering, has not been constructed or red-teamed.","d":"Coverage & hidden compute","h":"/implementations/low-trust-compute-verification-system-overview/#blocker-4","host":"I-0012","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":22.9,"y":649.7},{"id":"I-0012.B5","k":"B","l":"Distinguishing one server's DRAM contents from…","n":"Distinguishing one server's DRAM contents from another's by challenge-response timing, and a general challenge-response protocol for diverse data types, are open.","d":"Coverage & hidden compute","h":"/implementations/low-trust-compute-verification-system-overview/#blocker-5","host":"I-0012","theme":"coverage-hidden-compute","cat":"isolation-architecture","w":3,"x":8.2,"y":670.4},{"id":"I-0012.B6","k":"B","l":"The threat model is under-developed and needs input…","n":"The threat model is under-developed and needs input from cybersecurity and AI threat-modelling experts.","d":"Adversarial validation","h":"/implementations/low-trust-compute-verification-system-overview/#blocker-6","host":"I-0012","theme":"adversarial-validation","cat":"isolation-architecture","w":2,"x":-9.2,"y":675.1},{"id":"I-0012.F1","k":"F","l":"Mismatches cannot be attributed to cheating or error","n":"Mismatches cannot be attributed to cheating or error","d":"A failed hash or replay does not show whether it came from an evasion attempt, a random bit flip or an evaluation error. The author notes that if detected anomalies can plausibly be waved off as malfunctions, deterrence becomes less effective, so the parties…","h":"/implementations/low-trust-compute-verification-system-overview/#flaw-1","host":"I-0012","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-27.1,"y":670.9},{"id":"I-0012.F2","k":"F","l":"Deliberate faults leak a bit each","n":"Deliberate faults leak a bit each","d":"A malicious device can leak one bit by deliberately outputting a wrong result, which blocks a disclosure when the cross-comparison fails. The design therefore needs a pre-agreed budget of tolerated faults.","h":"/implementations/low-trust-compute-verification-system-overview/#flaw-2","host":"I-0012","cat":"isolation-architecture","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":-43.1,"y":649.4},{"id":"I-0012.F3","k":"F","l":"Inspector agents may be manipulable","n":"Inspector agents may be manipulable","d":"Automated compliance screening with LLM-based inspector agents must resist prompt-injection attacks. Adversarially trained systems might hide malicious actions with steganography, which makes backdoor detection an open problem.","h":"/implementations/low-trust-compute-verification-system-overview/#flaw-3","host":"I-0012","cat":"isolation-architecture","sev":"significant","fk":"Open question","st":"open","w":1,"x":-41.2,"y":636.3},{"id":"I-0009.B1","k":"B","l":"The specification is an unfinished draft with no public…","n":"The specification is an unfinished draft with no public implementation or evaluation.","d":"Adversarial validation","h":"/implementations/lucid-location-certificates/#blocker-1","host":"I-0009","theme":"adversarial-validation","cat":"accounting-provenance","w":2,"x":597.5,"y":250.7},{"id":"I-0009.B2","k":"B","l":"It needs a globally distributed, trusted anchor fleet…","n":"It needs a globally distributed, trusted anchor fleet and an endorser to run the anchor directory.","d":"Access & governance","h":"/implementations/lucid-location-certificates/#blocker-2","host":"I-0009","theme":"access-governance","cat":"accounting-provenance","w":2,"x":608.7,"y":262.8},{"id":"I-0009.F1","k":"F","l":"Physical attacks on the trusted hardware are out of scope","n":"Physical attacks on the trusted hardware are out of scope","d":"The specification places the hardware root of trust and the TEE in the trusted computing base. It assumes they resist software attacks, notes that the attacker may have physical access, and leaves sophisticated physical attacks, such as bus probing and…","h":"/implementations/lucid-location-certificates/#flaw-1","host":"I-0009","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":610.1,"y":285.4},{"id":"I-0009.F2","k":"F","l":"On-chip keys may be extractable","n":"On-chip keys may be extractable","d":"Tee and Happel argue that ping-based location protocols backed by keys stored on the chip can be compromised if an adversary with physical access extracts those keys. In this specification, the evidence chain rests on the hardware root of trust's signed…","h":"/implementations/lucid-location-certificates/#flaw-2","host":"I-0009","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":590.8,"y":307.7},{"id":"I-0009.F3","k":"F","l":"General delay and landmark attacks apply","n":"General delay and landmark attacks apply","d":"Attacks on delay-based location verification in general also apply. Brass and Aarne discuss adding delay, using faster paths such as dark fibre, and compromising landmarks. The specification counters anchor impersonation with a signed anchor directory.…","h":"/implementations/lucid-location-certificates/#flaw-3","host":"I-0009","cat":"accounting-provenance","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":572.7,"y":308.9},{"id":"I-0004.B1","k":"B","l":"Built for consensus rather than capacity bounding;…","n":"Built for consensus rather than capacity bounding; verifying that declared hardware has no spare capacity would also need a credible compute estimate.","d":"Capacity bounds","h":"/implementations/pearl-proof-of-useful-work/#blocker-1","host":"I-0004","theme":"capacity-bounds","cat":"cryptographic-computational","w":2,"x":-378.4,"y":-541.8},{"id":"I-0004.B2","k":"B","l":"Performance figures are provider-reported, and the…","n":"Performance figures are provider-reported, and the benchmark reports no baseline of the certified model without mining.","d":"Adversarial validation","h":"/implementations/pearl-proof-of-useful-work/#blocker-2","host":"I-0004","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-365.9,"y":-532.5},{"id":"I-0004.B3","k":"B","l":"Bit-exact verification depends on reproducing GPU…","n":"Bit-exact verification depends on reproducing GPU arithmetic deterministically.","d":"Performance & compatibility","h":"/implementations/pearl-proof-of-useful-work/#blocker-3","host":"I-0004","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-416.6,"y":-493.3},{"id":"I-0004.F1","k":"F","l":"Known mining speedups reduce work per proof","n":"Known mining speedups reduce work per proof","d":"Pearl lists known speedups: crafted inputs, precision shortcuts, seed or commitment grinding, work reuse, and faster kernels or hardware. Its jackpot policy checks limit crafted inputs, and a policy check caps skippable summands at one-sixteenth of those in a…","h":"/implementations/pearl-proof-of-useful-work/#flaw-1","host":"I-0004","cat":"cryptographic-computational","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":-422.5,"y":-507.5},{"id":"I-0004.F2","k":"F","l":"Security rests on a new, informal hardness assumption","n":"Security rests on a new, informal hardness assumption","d":"The FP8 scheme relies on \"Assumption 1 (Informal quantized-subspace hardness)\": quantised products of noised matrices are assumed not to be substantially easier than generic ones. The integer construction it extends lists PoUW from more standard assumptions…","h":"/implementations/pearl-proof-of-useful-work/#flaw-2","host":"I-0004","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-418.4,"y":-525.3},{"id":"I-0004.F3","k":"F","l":"Verification does not check that mined matrices come from AI…","n":"Verification does not check that mined matrices come from AI workloads","d":"Miners choose their own matrices. Basu reports that Pearl's verification \"does not check whether the matrices originate from an AI model\", that random matrices pass it, and that Pearl's reference mining code generates uniformly random matrices, with vLLM…","h":"/implementations/pearl-proof-of-useful-work/#flaw-3","host":"I-0004","cat":"cryptographic-computational","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":-397.2,"y":-542.1},{"id":"I-0010.B1","k":"B","l":"No prototype exists; RAND recommends prototyping key…","n":"No prototype exists; RAND recommends prototyping key security features and integration now.","d":"Adversarial validation","h":"/implementations/rand-secure-inference-data-centers/#blocker-1","host":"I-0010","theme":"adversarial-validation","cat":"isolation-architecture","w":2,"x":388,"y":548.5},{"id":"I-0010.B2","k":"B","l":"The report describes internal integrity checks, audit…","n":"The report describes internal integrity checks, audit logging and accreditation, but no way for a party outside the operator to verify the facility's properties.","d":"Access & governance","h":"/implementations/rand-secure-inference-data-centers/#blocker-2","host":"I-0010","theme":"access-governance","cat":"isolation-architecture","w":2,"x":369.4,"y":547.6},{"id":"I-0010.B3","k":"B","l":"Human review of every prompt and response makes each…","n":"Human review of every prompt and response makes each request take three to five minutes, with the review steps as the rate-limiting factor.","d":"Performance & compatibility","h":"/implementations/rand-secure-inference-data-centers/#blocker-3","host":"I-0010","theme":"performance-compatibility","cat":"isolation-architecture","w":2,"x":357.2,"y":538},{"id":"I-0010.B4","k":"B","l":"Detailed design information is withheld from the public…","n":"Detailed design information is withheld from the public report and is to be evaluated privately with stakeholders, which limits independent public scrutiny.","d":"Access & governance","h":"/implementations/rand-secure-inference-data-centers/#blocker-4","host":"I-0010","theme":"access-governance","cat":"isolation-architecture","w":2,"x":408.8,"y":500},{"id":"I-0010.F1","k":"F","l":"Everything rests on the trusted setup","n":"Everything rests on the trusted setup","d":"Reference measurements for model weights and reference data are established in a trusted setup phase. The report states that the system cannot detect compromise that happened before ingestion if the trusted setup itself is compromised.","h":"/implementations/rand-secure-inference-data-centers/#flaw-1","host":"I-0010","cat":"isolation-architecture","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":414.4,"y":514.5},{"id":"I-0010.F2","k":"F","l":"Security weakens over long operation","n":"Security weakens over long operation","d":"The authors claim that the facility can withstand attacks at the OC5 level for a five-year operational period. They expect its ability to withstand long OC5 campaigns to become less robust the longer the facility remains in operation.","h":"/implementations/rand-secure-inference-data-centers/#flaw-2","host":"I-0010","cat":"isolation-architecture","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":409.7,"y":532.4},{"id":"I-0008.B1","k":"B","l":"The planned FPGA logger has not yet been built.","n":"The planned FPGA logger has not yet been built.","d":"Hardware trust","h":"/implementations/sash-confidential-network-logger/#blocker-1","host":"I-0008","theme":"hardware-trust","cat":"off-chip-devices","w":2,"x":497.7,"y":-451.6},{"id":"I-0008.B2","k":"B","l":"The design has not been scaled to production traffic…","n":"The design has not been scaled to production traffic volumes.","d":"Performance & compatibility","h":"/implementations/sash-confidential-network-logger/#blocker-2","host":"I-0008","theme":"performance-compatibility","cat":"off-chip-devices","w":2,"x":515.1,"y":-431},{"id":"I-0008.B3","k":"B","l":"Exact-match recomputation requires reproducible…","n":"Exact-match recomputation requires reproducible inference.","d":"Evidence binding","h":"/implementations/sash-confidential-network-logger/#blocker-3","host":"I-0008","theme":"evidence-binding","cat":"off-chip-devices","w":3,"x":515.6,"y":-412.6},{"id":"I-0008.F1","k":"F","l":"Recomputation cluster security is not monitored","n":"Recomputation cluster security is not monitored","d":"SASH states that the current prototype has no means to monitor the security of the recomputation cluster, which holds a copy of the model and decides whether an alarm is raised.","h":"/implementations/sash-confidential-network-logger/#flaw-1","host":"I-0008","cat":"off-chip-devices","sev":"significant","fk":"Open question","st":"open","w":1,"x":506.9,"y":-399.8},{"id":"I-0008.F2","k":"F","l":"Side channels not yet addressed","n":"Side channels not yet addressed","d":"SASH lists eliminating a wider range of side-channel vulnerabilities as future work.","h":"/implementations/sash-confidential-network-logger/#flaw-2","host":"I-0008","cat":"off-chip-devices","sev":"significant","fk":"Open question","st":"open","w":1,"x":465.1,"y":-448.4},{"id":"I-0008.F3","k":"F","l":"Logger hardware supply chain","n":"Logger hardware supply chain","d":"The prototype uses a Raspberry Pi 5 as the logger, which SASH says locks the design into Broadcom and Arm supply chains.","h":"/implementations/sash-confidential-network-logger/#flaw-3","host":"I-0008","cat":"off-chip-devices","sev":"minor","fk":"Open question","st":"open","w":1,"x":479.2,"y":-455},{"id":"I-0006.B1","k":"B","l":"The underlying TEE attestation does not resist…","n":"The underlying TEE attestation does not resist attackers with physical access to the host.","d":"Hardware trust","h":"/implementations/tinfoil-model-identity/#blocker-1","host":"I-0006","theme":"hardware-trust","cat":"cryptographic-computational","w":3,"x":-575.6,"y":-402.8},{"id":"I-0006.B2","k":"B","l":"No independent evaluation of the model-identity chain…","n":"No independent evaluation of the model-identity chain has been published.","d":"Adversarial validation","h":"/implementations/tinfoil-model-identity/#blocker-2","host":"I-0006","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-582.7,"y":-419.3},{"id":"I-0006.F1","k":"F","l":"Inherits attacks on the underlying TEEs","n":"Inherits attacks on the underlying TEEs","d":"Tinfoil's documentation states that an attacker with physical access \"can potentially compromise the enclave\". It notes that attestation forgery has been demonstrated for Intel TDX, and that researchers breached confidentiality on AMD SEV-SNP through key…","h":"/implementations/tinfoil-model-identity/#flaw-1","host":"I-0006","cat":"cryptographic-computational","sev":"critical","fk":"Demonstrated attack","st":"open","crit":true,"w":1,"x":-571.9,"y":-446.7},{"id":"I-0006.F2","k":"F","l":"Side channels, I/O leakage and denial of service are outside…","n":"Side channels, I/O leakage and denial of service are outside enclave protection","d":"Tinfoil's documentation lists timing, power and electromagnetic side channels, host observation of access patterns and I/O, denial of service, supply-chain compromise and rollback as limitations.","h":"/implementations/tinfoil-model-identity/#flaw-2","host":"I-0006","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-551,"y":-455.8},{"id":"I-0006.F3","k":"F","l":"Private models can be checked only for consistency","n":"Private models can be checked only for consistency","d":"For unpublished weights, the root hash appears in the attestation without the weights being exposed. Users can then confirm only that they get the same model each time.","h":"/implementations/tinfoil-model-identity/#flaw-3","host":"I-0006","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-535.1,"y":-451.4},{"id":"I-0001.B1","k":"B","l":"No independent security evaluation has been published,…","n":"No independent security evaluation has been published, and Amodo Design rates red-teaming of recomputation schemes as 'not started'.","d":"Adversarial validation","h":"/implementations/toploc/#blocker-1","host":"I-0001","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-209.6,"y":610.3},{"id":"I-0001.B2","k":"B","l":"The verifier must run the model itself, which suits the…","n":"The verifier must run the model itself, which suits the paper's setting of providers serving open-weights models.","d":"Privacy & leakage","h":"/implementations/toploc/#blocker-2","host":"I-0001","theme":"privacy-leakage","cat":"cryptographic-computational","w":2,"x":-218.4,"y":622.7},{"id":"I-0001.F1","k":"F","l":"Speculative decoding goes undetected","n":"Speculative decoding goes undetected","d":"The TOPLOC authors state that it cannot detect speculative decoding. In speculative decoding, a provider decodes with a cheaper model and uses the larger model only for prefill.","h":"/implementations/toploc/#flaw-1","host":"I-0001","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-235.5,"y":628.7},{"id":"I-0001.F2","k":"F","l":"Last-layer activations could be spoofed","n":"Last-layer activations could be spoofed","d":"The TOPLOC authors name spoofing of the last hidden layer's activations as a potential attack. A provider could do this by pruning intermediate layers or by using a smaller model.","h":"/implementations/toploc/#flaw-2","host":"I-0001","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-260.8,"y":619.7},{"id":"I-0001.F3","k":"F","l":"Subtle modifications are harder to detect","n":"Subtle modifications are harder to detect","d":"The TOPLOC authors state that large changes to the model or prompt are straightforward to detect, but subtle modifications are harder. In preliminary experiments, the margin separating fp8 from bf16 generation was small. The authors did not test whether…","h":"/implementations/toploc/#flaw-3","host":"I-0001","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-270.8,"y":603.3},{"id":"I-0001.F4","k":"F","l":"Tolerance leaves covert bandwidth","n":"Tolerance leaves covert bandwidth","d":"TOPLOC accepts approximate matches. A check of this kind can put an upper bound on the covert bandwidth available to an adversary, but it cannot close that bandwidth. The limit applies to all statistical verification schemes.","h":"/implementations/toploc/#flaw-4","host":"I-0001","cat":"cryptographic-computational","sev":"significant","fk":"Theoretical argument","st":"open","w":1,"x":-269.5,"y":587.6},{"id":"I-0015.B1","k":"B","l":"RepOps as published supports only 32-bit floating point…","n":"RepOps as published supports only 32-bit floating point with one GPU per provider, and added 98% to Llama-8B inference time on an A100.","d":"Performance & compatibility","h":"/implementations/gensyn-verde-repops/#blocker-1","host":"I-0015","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-601.3,"y":-276},{"id":"I-0015.B2","k":"B","l":"The providers who re-run a job and the referee need the…","n":"The providers who re-run a job and the referee need the model and data, and the guarantee holds only if at least one provider is honest.","d":"Privacy & leakage","h":"/implementations/gensyn-verde-repops/#blocker-2","host":"I-0015","theme":"privacy-leakage","cat":"cryptographic-computational","w":2,"x":-620.8,"y":-228.9},{"id":"I-0003.B1","k":"B","l":"Proving takes about 12 to 13 minutes of A100 time per…","n":"Proving takes about 12 to 13 minutes of A100 time per 2,048-token forward pass at 13B parameters, plus a one-time weight commitment of 16 to 21 minutes.","d":"Performance & compatibility","h":"/implementations/zkllm/#blocker-1","host":"I-0003","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-633.1,"y":301.5},{"id":"I-0003.B2","k":"B","l":"The repository was archived on 10 July 2025 and the…","n":"The repository was archived on 10 July 2025 and the author states there is no plan for upgrades or maintenance.","d":"Performance & compatibility","h":"/implementations/zkllm/#blocker-2","host":"I-0003","theme":"performance-compatibility","cat":"cryptographic-computational","w":2,"x":-650.3,"y":300.8},{"id":"I-0003.B3","k":"B","l":"No security audit of the code has been carried out.","n":"No security audit of the code has been carried out.","d":"Adversarial validation","h":"/implementations/zkllm/#blocker-3","host":"I-0003","theme":"adversarial-validation","cat":"cryptographic-computational","w":2,"x":-668.8,"y":282.5},{"id":"I-0003.F1","k":"F","l":"Reference code is interactive and runs prover and verifier…","n":"Reference code is interactive and runs prover and verifier together","d":"The README states that prover and verifier work \"are implemented side-by-side\", and that intermediate values written to files are for the prover's reference only. It says an industrial deployment would need to separate the two and apply Fiat–Shamir to make…","h":"/implementations/zkllm/#flaw-1","host":"I-0003","cat":"cryptographic-computational","sev":"significant","fk":"Open question","st":"open","w":1,"x":-669.3,"y":256.3},{"id":"I-0003.F2","k":"F","l":"Proves a fixed-point approximation of a publicly known…","n":"Proves a fixed-point approximation of a publicly known architecture","d":"The prover's model must have a \"publicly known structure\". Tensors are discretised by scaling and rounding. The authors report perplexity changes of 0.008 to 0.09 on C4. The proof covers the quantised computation.","h":"/implementations/zkllm/#flaw-2","host":"I-0003","cat":"cryptographic-computational","sev":"minor","fk":"Theoretical argument","st":"open","w":1,"x":-657.9,"y":243.3}],"edges":[{"s":"M-0014","t":"C-0008","k":"verifies","role":"p","note":"Caps or removes communication between declared groups of accelerators (Dean (2026), Computing (2026))."},{"s":"M-0014","t":"C-0004","k":"verifies","role":"s","note":"Intended to leave inference workable while making large training impractical (Dean (2026), Computing (2026))."},{"s":"M-0014","t":"C-0007","k":"verifies","role":"s","note":"Bounds the size of model that can be trained efficiently across pods (Computing (2026))."},{"s":"M-0014","t":"C-0009","k":"verifies","role":"s","note":"A cap on outgoing bandwidth bounds how much weight data can leave a facility in a given time (Rinberg et al. (2026))."},{"s":"O-0101","t":"M-0014","k":"works_on"},{"s":"O-0180","t":"M-0014","k":"works_on"},{"s":"O-0201","t":"M-0014","k":"works_on"},{"s":"O-0202","t":"M-0014","k":"works_on"},{"s":"M-0014","t":"M-0013","k":"depends_on","note":"Monitored links are needed to show that all traffic leaving a group crosses the capped boundary."},{"s":"M-0014","t":"M-0017","k":"depends_on","note":"Shaping and monitoring devices must resist tampering and bypass."},{"s":"M-0014","t":"M-0005","k":"complements"},{"s":"M-0014","t":"M-0001","k":"complements"},{"s":"M-0014","t":"M-0003","k":"complements"},{"s":"M-0014","t":"M-0015","k":"complements"},{"s":"M-0014","t":"M-0016","k":"complements"},{"s":"M-0014","t":"K-0017","k":"uses_concept"},{"s":"M-0014","t":"K-0021","k":"uses_concept"},{"s":"M-0014","t":"K-0025","k":"uses_concept"},{"s":"M-0014","t":"K-0016","k":"uses_concept"},{"s":"M-0014","t":"K-0018","k":"uses_concept"},{"s":"M-0014","t":"T.capacity-bounds","k":"faces"},{"s":"M-0014","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0014","t":"T.hardware-trust","k":"faces"},{"s":"M-0014","t":"T.adversarial-validation","k":"faces"},{"s":"M-0014","t":"T.performance-compatibility","k":"faces"},{"s":"M-0014","t":"G.isolation-architecture","k":"in_category"},{"s":"M-0014.B1","t":"M-0014","k":"blocks"},{"s":"M-0014.B1","t":"T.adversarial-validation","k":"theme"},{"s":"M-0014.B2","t":"M-0014","k":"blocks"},{"s":"M-0014.B2","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0014.B2","t":"M-0013","k":"waits_on"},{"s":"M-0014.B3","t":"M-0014","k":"blocks"},{"s":"M-0014.B3","t":"T.hardware-trust","k":"theme"},{"s":"M-0014.B3","t":"M-0017","k":"waits_on"},{"s":"M-0014.B4","t":"M-0014","k":"blocks"},{"s":"M-0014.B4","t":"T.capacity-bounds","k":"theme"},{"s":"M-0014.F1","t":"M-0014","k":"weakens"},{"s":"M-0014.F2","t":"M-0014","k":"weakens"},{"s":"M-0014.F3","t":"M-0014","k":"weakens"},{"s":"M-0014.F4","t":"M-0014","k":"weakens"},{"s":"M-0014.F5","t":"M-0014","k":"weakens"},{"s":"M-0024","t":"C-0009","k":"verifies","role":"p","note":"Bounds how much weight or other undeclared information can leave in checked outputs; does not close other channels."},{"s":"M-0024","t":"C-0004","k":"verifies","role":"s","note":"In the compute-agreement framing, outputs must be predictable by policy-compliant computation, which limits what undeclared workloads can export (Petrie & Mühlhäuser (2026))."},{"s":"M-0024","t":"C-0008","k":"verifies","role":"s","note":"Bounds effective unexplained output bandwidth rather than raw link bandwidth."},{"s":"M-0024","t":"M-0001","k":"depends_on","note":"Predictions of honest outputs come from recomputing declared workloads."},{"s":"M-0024","t":"M-0014","k":"depends_on","note":"The bound is meaningful only if outputs through the interlock are the prover's only channel."},{"s":"M-0024","t":"M-0022","k":"depends_on","note":"Physical side channels bypass output checks and must be suppressed separately."},{"s":"M-0024","t":"M-0013","k":"depends_on","note":"An interlock or tap must record commitments to all traffic."},{"s":"M-0024","t":"M-0002","k":"complements"},{"s":"M-0024","t":"M-0015","k":"complements"},{"s":"M-0024","t":"K-0008","k":"uses_concept"},{"s":"M-0024","t":"K-0009","k":"uses_concept"},{"s":"M-0024","t":"K-0013","k":"uses_concept"},{"s":"M-0024","t":"K-0016","k":"uses_concept"},{"s":"M-0024","t":"K-0017","k":"uses_concept"},{"s":"M-0024","t":"K-0020","k":"uses_concept"},{"s":"M-0024","t":"K-0022","k":"uses_concept"},{"s":"M-0024","t":"K-0024","k":"uses_concept"},{"s":"M-0024","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0024","t":"T.protocol-soundness","k":"faces"},{"s":"M-0024","t":"T.privacy-leakage","k":"faces"},{"s":"M-0024","t":"T.adversarial-validation","k":"faces"},{"s":"M-0024","t":"G.isolation-architecture","k":"in_category"},{"s":"M-0024.B1","t":"M-0024","k":"blocks"},{"s":"M-0024.B1","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0024.B1","t":"M-0014","k":"waits_on"},{"s":"M-0024.B2","t":"M-0024","k":"blocks"},{"s":"M-0024.B2","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0024.B2","t":"M-0022","k":"waits_on"},{"s":"M-0024.B3","t":"M-0024","k":"blocks"},{"s":"M-0024.B3","t":"T.protocol-soundness","k":"theme"},{"s":"M-0024.B3","t":"M-0002","k":"waits_on"},{"s":"M-0024.B4","t":"M-0024","k":"blocks"},{"s":"M-0024.B4","t":"T.privacy-leakage","k":"theme"},{"s":"M-0024.B5","t":"M-0024","k":"blocks"},{"s":"M-0024.B5","t":"T.adversarial-validation","k":"theme"},{"s":"M-0024.F1","t":"M-0024","k":"weakens"},{"s":"M-0024.F2","t":"M-0024","k":"weakens"},{"s":"M-0024.F3","t":"M-0024","k":"weakens"},{"s":"M-0024.F4","t":"M-0024","k":"weakens"},{"s":"M-0018","t":"C-0002","k":"verifies","role":"p","note":"Bounds how far a responding chip can be from trusted landmark servers at the time of the check."},{"s":"M-0018","t":"C-0010","k":"verifies","role":"s","note":"Can flag enrolled chips that stop responding or answer from outside declared regions; says nothing about chips outside the scheme."},{"s":"O-0180","t":"M-0018","k":"works_on"},{"s":"O-0204","t":"M-0018","k":"works_on"},{"s":"O-0207","t":"M-0018","k":"works_on"},{"s":"O-0140","t":"M-0018","k":"works_on"},{"s":"M-0018","t":"M-0008","k":"depends_on","note":"Binding a timed reply to one physical chip relies on a per-chip key held in secure hardware, as in remote attestation."},{"s":"M-0018","t":"M-0019","k":"complements"},{"s":"M-0018","t":"M-0017","k":"complements"},{"s":"M-0018","t":"K-0004","k":"uses_concept"},{"s":"M-0018","t":"K-0005","k":"uses_concept"},{"s":"M-0018","t":"K-0006","k":"uses_concept"},{"s":"M-0018","t":"K-0007","k":"uses_concept"},{"s":"M-0018","t":"K-0018","k":"uses_concept"},{"s":"M-0018","t":"T.hardware-trust","k":"faces"},{"s":"M-0018","t":"T.protocol-soundness","k":"faces"},{"s":"M-0018","t":"T.adversarial-validation","k":"faces"},{"s":"M-0018","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0018","t":"T.access-governance","k":"faces"},{"s":"M-0018","t":"G.accounting-provenance","k":"in_category"},{"s":"M-0018.B1","t":"M-0018","k":"blocks"},{"s":"M-0018.B1","t":"T.adversarial-validation","k":"theme"},{"s":"M-0018.B2","t":"M-0018","k":"blocks"},{"s":"M-0018.B2","t":"T.hardware-trust","k":"theme"},{"s":"M-0018.B3","t":"M-0018","k":"blocks"},{"s":"M-0018.B3","t":"T.protocol-soundness","k":"theme"},{"s":"M-0018.B4","t":"M-0018","k":"blocks"},{"s":"M-0018.B4","t":"T.access-governance","k":"theme"},{"s":"M-0018.F1","t":"M-0018","k":"weakens"},{"s":"M-0018.F2","t":"M-0018","k":"weakens"},{"s":"M-0018.F3","t":"M-0018","k":"weakens"},{"s":"M-0018.F4","t":"M-0018","k":"weakens"},{"s":"M-0019","t":"C-0001","k":"verifies","role":"p","note":"Gives a baseline of which chips were made and who declared owning them."},{"s":"M-0019","t":"C-0010","k":"verifies","role":"s","note":"Supports checks that recorded chips have not been assembled into undeclared clusters."},{"s":"M-0019","t":"C-0002","k":"verifies","role":"s","note":"Records declared locations, which inspections or location checks can test."},{"s":"O-0200","t":"M-0019","k":"works_on"},{"s":"O-0201","t":"M-0019","k":"works_on"},{"s":"O-0204","t":"M-0019","k":"works_on"},{"s":"M-0019","t":"M-0020","k":"complements"},{"s":"M-0019","t":"M-0017","k":"complements"},{"s":"M-0019","t":"K-0024","k":"uses_concept"},{"s":"M-0019","t":"K-0016","k":"uses_concept"},{"s":"M-0019","t":"K-0020","k":"uses_concept"},{"s":"M-0019","t":"K-0015","k":"uses_concept"},{"s":"M-0019","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0019","t":"T.hardware-trust","k":"faces"},{"s":"M-0019","t":"T.evidence-binding","k":"faces"},{"s":"M-0019","t":"T.access-governance","k":"faces"},{"s":"M-0019","t":"G.accounting-provenance","k":"in_category"},{"s":"M-0019.B1","t":"M-0019","k":"blocks"},{"s":"M-0019.B1","t":"T.access-governance","k":"theme"},{"s":"M-0019.B2","t":"M-0019","k":"blocks"},{"s":"M-0019.B2","t":"T.hardware-trust","k":"theme"},{"s":"M-0019.B3","t":"M-0019","k":"blocks"},{"s":"M-0019.B3","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0019.F1","t":"M-0019","k":"weakens"},{"s":"M-0019.F2","t":"M-0019","k":"weakens"},{"s":"M-0019.F3","t":"M-0019","k":"weakens"},{"s":"M-0025","t":"C-0005","k":"verifies","role":"p","note":"Binds audit or capability-evaluation results to the model that is served, without revealing weights (Schnabl et al. (2025), Ding et al. (2026))."},{"s":"M-0025","t":"C-0006","k":"verifies","role":"s","note":"Plan-scoped monitoring runs an agreed classifier over private usage records (Penchas et al. (2026))."},{"s":"M-0025","t":"C-0007","k":"verifies","role":"s","note":"Zero-knowledge audits can prove properties of committed training data and weights (Waiwitlikhit et al. (2024))."},{"s":"O-0142","t":"M-0025","k":"works_on"},{"s":"O-0202","t":"M-0025","k":"works_on"},{"s":"M-0025","t":"M-0008","k":"depends_on","note":"TEE-based designs rely on measured launch and remote attestation."},{"s":"M-0025","t":"M-0023","k":"complements"},{"s":"M-0025","t":"M-0012","k":"complements"},{"s":"M-0025","t":"K-0001","k":"uses_concept"},{"s":"M-0025","t":"K-0002","k":"uses_concept"},{"s":"M-0025","t":"K-0004","k":"uses_concept"},{"s":"M-0025","t":"K-0005","k":"uses_concept"},{"s":"M-0025","t":"K-0006","k":"uses_concept"},{"s":"M-0025","t":"K-0010","k":"uses_concept"},{"s":"M-0025","t":"K-0018","k":"uses_concept"},{"s":"M-0025","t":"K-0024","k":"uses_concept"},{"s":"M-0025","t":"T.privacy-leakage","k":"faces"},{"s":"M-0025","t":"T.hardware-trust","k":"faces"},{"s":"M-0025","t":"T.performance-compatibility","k":"faces"},{"s":"M-0025","t":"T.access-governance","k":"faces"},{"s":"M-0025","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0025","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0025.B1","t":"M-0025","k":"blocks"},{"s":"M-0025.B1","t":"T.performance-compatibility","k":"theme"},{"s":"M-0025.B1","t":"M-0008","k":"waits_on"},{"s":"M-0025.B2","t":"M-0025","k":"blocks"},{"s":"M-0025.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0025.B2","t":"M-0004","k":"waits_on"},{"s":"M-0025.B3","t":"M-0025","k":"blocks"},{"s":"M-0025.B3","t":"T.hardware-trust","k":"theme"},{"s":"M-0025.B3","t":"M-0008","k":"waits_on"},{"s":"M-0025.B4","t":"M-0025","k":"blocks"},{"s":"M-0025.B4","t":"T.access-governance","k":"theme"},{"s":"M-0025.B5","t":"M-0025","k":"blocks"},{"s":"M-0025.B5","t":"T.privacy-leakage","k":"theme"},{"s":"M-0025.F1","t":"M-0025","k":"weakens"},{"s":"M-0025.F2","t":"M-0025","k":"weakens"},{"s":"M-0025.F3","t":"M-0025","k":"weakens"},{"s":"M-0025.F4","t":"M-0025","k":"weakens"},{"s":"M-0025.F5","t":"M-0025","k":"weakens"},{"s":"M-0002","t":"C-0005","k":"verifies","role":"p","note":"Enables exact-match recomputation checks that the declared model, weights and software setup produced the outputs."},{"s":"M-0002","t":"C-0004","k":"verifies","role":"s","note":"Bit-exact recomputation of declared inference removes the tolerance an operator could hide other work in (Cankaya (2026))."},{"s":"M-0002","t":"C-0009","k":"verifies","role":"s","note":"Removes the tolerance margin that steganographic exfiltration could use (Cankaya (2026))."},{"s":"M-0002","t":"C-0010","k":"verifies","role":"s","note":"Unreported batch elements alter the numerics, so covert computation inside batches becomes detectable (Cankaya (2026))."},{"s":"M-0002","t":"M-0001","k":"complements"},{"s":"M-0002","t":"M-0003","k":"complements"},{"s":"M-0002","t":"M-0004","k":"complements"},{"s":"M-0002","t":"K-0008","k":"uses_concept"},{"s":"M-0002","t":"K-0009","k":"uses_concept"},{"s":"M-0002","t":"K-0016","k":"uses_concept"},{"s":"M-0002","t":"T.performance-compatibility","k":"faces"},{"s":"M-0002","t":"T.protocol-soundness","k":"faces"},{"s":"M-0002","t":"T.privacy-leakage","k":"faces"},{"s":"M-0002","t":"T.adversarial-validation","k":"faces"},{"s":"M-0002","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0002.B1","t":"M-0002","k":"blocks"},{"s":"M-0002.B1","t":"T.performance-compatibility","k":"theme"},{"s":"M-0002.B2","t":"M-0002","k":"blocks"},{"s":"M-0002.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0002.B3","t":"M-0002","k":"blocks"},{"s":"M-0002.B3","t":"T.performance-compatibility","k":"theme"},{"s":"M-0002.B4","t":"M-0002","k":"blocks"},{"s":"M-0002.B4","t":"T.privacy-leakage","k":"theme"},{"s":"M-0002.F1","t":"M-0002","k":"weakens"},{"s":"M-0002.F2","t":"M-0002","k":"weakens"},{"s":"M-0011","t":"C-0001","k":"verifies","role":"s","note":"A verified performance cap bounds the effective capacity of declared hardware; needs attestation that the cap is active."},{"s":"M-0011","t":"C-0007","k":"verifies","role":"s","note":"Licenses that authorize a fixed amount of work would bound compute per license period (Kulp et al. (2024), O'Gara et al. (2025))."},{"s":"M-0011","t":"C-0003","k":"verifies","role":"s","note":"Unlicensed hardware falls back to reduced capacity or shuts down (O'Gara et al. (2025))."},{"s":"O-0200","t":"M-0011","k":"works_on"},{"s":"O-0207","t":"M-0011","k":"works_on"},{"s":"M-0011","t":"M-0010","k":"depends_on","note":"Licenses denominated in work need secure meters for the licensed quantities (S-0006)."},{"s":"M-0011","t":"M-0008","k":"depends_on","note":"A verifier needs attested configuration to know a cap is in force; licensing relies on secure boot and on-chip authentication (S-0057)."},{"s":"M-0011","t":"M-0009","k":"complements"},{"s":"M-0011","t":"K-0007","k":"uses_concept"},{"s":"M-0011","t":"K-0023","k":"uses_concept"},{"s":"M-0011","t":"K-0005","k":"uses_concept"},{"s":"M-0011","t":"K-0018","k":"uses_concept"},{"s":"M-0011","t":"T.hardware-trust","k":"faces"},{"s":"M-0011","t":"T.protocol-soundness","k":"faces"},{"s":"M-0011","t":"T.adversarial-validation","k":"faces"},{"s":"M-0011","t":"T.access-governance","k":"faces"},{"s":"M-0011","t":"G.on-chip","k":"in_category"},{"s":"M-0011.B1","t":"M-0011","k":"blocks"},{"s":"M-0011.B1","t":"T.access-governance","k":"theme"},{"s":"M-0011.B2","t":"M-0011","k":"blocks"},{"s":"M-0011.B2","t":"T.protocol-soundness","k":"theme"},{"s":"M-0011.B2","t":"M-0009","k":"waits_on"},{"s":"M-0011.B3","t":"M-0011","k":"blocks"},{"s":"M-0011.B3","t":"T.hardware-trust","k":"theme"},{"s":"M-0011.B3","t":"M-0010","k":"waits_on"},{"s":"M-0011.B4","t":"M-0011","k":"blocks"},{"s":"M-0011.B4","t":"T.adversarial-validation","k":"theme"},{"s":"M-0011.F1","t":"M-0011","k":"weakens"},{"s":"M-0011.F2","t":"M-0011","k":"weakens"},{"s":"M-0011.F3","t":"M-0011","k":"weakens"},{"s":"M-0011.F4","t":"M-0011","k":"weakens"},{"s":"M-0009","t":"C-0007","k":"verifies","role":"p","note":"Verifiable claims about total training compute, and enforcement of compute thresholds (Petrie et al. (2025))."},{"s":"M-0009","t":"C-0005","k":"verifies","role":"s","note":"Deployment only to approved flexHEG devices, and verification of evaluation scores (Petrie et al. (2025))."},{"s":"M-0009","t":"C-0002","k":"verifies","role":"s","note":"Automated verification of approximate chip location (Petrie et al. (2025)); see Chip location verification."},{"s":"M-0009","t":"C-0008","k":"verifies","role":"s","note":"Interlocks on NVLink or NICs, and RAND's fixed-set pods, would bound communication (Petrie & Aarne (2025), Kulp et al. (2024))."},{"s":"M-0009","t":"C-0006","k":"verifies","role":"s","note":"Could require deployment-time safeguards on approved devices (Petrie et al. (2025))."},{"s":"O-0200","t":"M-0009","k":"works_on"},{"s":"O-0207","t":"M-0009","k":"works_on"},{"s":"M-0009","t":"M-0008","k":"depends_on","note":"Builds on existing secure boot, device identity and remote attestation; flexHEG would extend confidential-computing attestation (S-0035, S-1204)."},{"s":"M-0009","t":"M-0019","k":"depends_on","note":"Governance through flexHEG assumes a registry of equipped chips; covering non-flexHEG compute is a separate problem (S-1205)."},{"s":"M-0009","t":"M-0010","k":"complements"},{"s":"M-0009","t":"M-0014","k":"complements"},{"s":"M-0009","t":"M-0017","k":"complements"},{"s":"M-0009","t":"M-0018","k":"complements"},{"s":"M-0009","t":"M-0013","k":"alternative"},{"s":"M-0009","t":"K-0007","k":"uses_concept"},{"s":"M-0009","t":"K-0015","k":"uses_concept"},{"s":"M-0009","t":"K-0005","k":"uses_concept"},{"s":"M-0009","t":"K-0004","k":"uses_concept"},{"s":"M-0009","t":"K-0023","k":"uses_concept"},{"s":"M-0009","t":"K-0021","k":"uses_concept"},{"s":"M-0009","t":"K-0016","k":"uses_concept"},{"s":"M-0009","t":"K-0018","k":"uses_concept"},{"s":"M-0009","t":"T.hardware-trust","k":"faces"},{"s":"M-0009","t":"T.access-governance","k":"faces"},{"s":"M-0009","t":"T.protocol-soundness","k":"faces"},{"s":"M-0009","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0009","t":"T.adversarial-validation","k":"faces"},{"s":"M-0009","t":"G.on-chip","k":"in_category"},{"s":"M-0009.B1","t":"M-0009","k":"blocks"},{"s":"M-0009.B1","t":"T.access-governance","k":"theme"},{"s":"M-0009.B2","t":"M-0009","k":"blocks"},{"s":"M-0009.B2","t":"T.hardware-trust","k":"theme"},{"s":"M-0009.B2","t":"M-0017","k":"waits_on"},{"s":"M-0009.B3","t":"M-0009","k":"blocks"},{"s":"M-0009.B3","t":"T.hardware-trust","k":"theme"},{"s":"M-0009.B4","t":"M-0009","k":"blocks"},{"s":"M-0009.B4","t":"T.protocol-soundness","k":"theme"},{"s":"M-0009.B5","t":"M-0009","k":"blocks"},{"s":"M-0009.B5","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0009.B5","t":"M-0019","k":"waits_on"},{"s":"M-0009.F1","t":"M-0009","k":"weakens"},{"s":"M-0009.F2","t":"M-0009","k":"weakens"},{"s":"M-0009.F3","t":"M-0009","k":"weakens"},{"s":"M-0009.F4","t":"M-0009","k":"weakens"},{"s":"M-0009.F5","t":"M-0009","k":"weakens"},{"s":"M-0009.F6","t":"M-0009","k":"weakens"},{"s":"M-0015","t":"C-0004","k":"verifies","role":"s","note":"Periodic wipes are proposed so that only verified inference outputs persist (Dean (2026)); Amodo frames wipes as verifying completeness of declared workloads (Design (2026))."},{"s":"O-0101","t":"M-0015","k":"works_on"},{"s":"O-0201","t":"M-0015","k":"works_on"},{"s":"O-0202","t":"M-0015","k":"works_on"},{"s":"M-0015","t":"M-0016","k":"depends_on","note":"The fill is checked by timed challenges, which must exclude outside help."},{"s":"M-0015","t":"M-0013","k":"depends_on","note":"Monitored links, or physical disconnection, are needed to rule out remote storage during challenges."},{"s":"M-0015","t":"M-0001","k":"complements"},{"s":"M-0015","t":"K-0012","k":"uses_concept"},{"s":"M-0015","t":"K-0016","k":"uses_concept"},{"s":"M-0015","t":"K-0001","k":"uses_concept"},{"s":"M-0015","t":"K-0002","k":"uses_concept"},{"s":"M-0015","t":"K-0018","k":"uses_concept"},{"s":"M-0015","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0015","t":"T.performance-compatibility","k":"faces"},{"s":"M-0015","t":"T.protocol-soundness","k":"faces"},{"s":"M-0015","t":"T.adversarial-validation","k":"faces"},{"s":"M-0015","t":"G.isolation-architecture","k":"in_category"},{"s":"M-0015.B1","t":"M-0015","k":"blocks"},{"s":"M-0015.B1","t":"T.performance-compatibility","k":"theme"},{"s":"M-0015.B2","t":"M-0015","k":"blocks"},{"s":"M-0015.B2","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0015.B2","t":"M-0016","k":"waits_on"},{"s":"M-0015.B3","t":"M-0015","k":"blocks"},{"s":"M-0015.B3","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0015.F1","t":"M-0015","k":"weakens"},{"s":"M-0015.F2","t":"M-0015","k":"weakens"},{"s":"M-0015.F3","t":"M-0015","k":"weakens"},{"s":"M-0012","t":"C-0005","k":"verifies","role":"p","note":"Core purpose: responses come from the declared weights."},{"s":"M-0012","t":"C-0006","k":"verifies","role":"s","note":"Links an attested evaluation to the model later served (Schnabl et al. (2025))."},{"s":"M-0012","t":"C-0009","k":"verifies","role":"s","note":"The recomputation variant limits steganographic weight exfiltration through outputs (Rinberg et al. (2025))."},{"s":"O-0141","t":"M-0012","k":"works_on"},{"s":"O-0142","t":"M-0012","k":"works_on"},{"s":"O-0202","t":"M-0012","k":"works_on"},{"s":"M-0012","t":"M-0008","k":"depends_on","note":"The enclave variant relies on TEE and GPU attestation."},{"s":"M-0012","t":"M-0001","k":"depends_on","note":"The recomputation variant is a form of sampled inference recomputation."},{"s":"M-0012","t":"M-0002","k":"complements"},{"s":"M-0012","t":"M-0023","k":"complements"},{"s":"M-0012","t":"M-0004","k":"alternative"},{"s":"M-0012","t":"K-0024","k":"uses_concept"},{"s":"M-0012","t":"K-0004","k":"uses_concept"},{"s":"M-0012","t":"K-0006","k":"uses_concept"},{"s":"M-0012","t":"K-0009","k":"uses_concept"},{"s":"M-0012","t":"K-0008","k":"uses_concept"},{"s":"M-0012","t":"K-0022","k":"uses_concept"},{"s":"M-0012","t":"K-0019","k":"uses_concept"},{"s":"M-0012","t":"T.evidence-binding","k":"faces"},{"s":"M-0012","t":"T.hardware-trust","k":"faces"},{"s":"M-0012","t":"T.protocol-soundness","k":"faces"},{"s":"M-0012","t":"T.access-governance","k":"faces"},{"s":"M-0012","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0012.B1","t":"M-0012","k":"blocks"},{"s":"M-0012.B1","t":"T.hardware-trust","k":"theme"},{"s":"M-0012.B1","t":"M-0008","k":"waits_on"},{"s":"M-0012.B2","t":"M-0012","k":"blocks"},{"s":"M-0012.B2","t":"T.protocol-soundness","k":"theme"},{"s":"M-0012.B2","t":"M-0002","k":"waits_on"},{"s":"M-0012.B3","t":"M-0012","k":"blocks"},{"s":"M-0012.B3","t":"T.access-governance","k":"theme"},{"s":"M-0012.F1","t":"M-0012","k":"weakens"},{"s":"M-0012.F2","t":"M-0012","k":"weakens"},{"s":"M-0012.F3","t":"M-0012","k":"weakens"},{"s":"M-0012.F4","t":"M-0012","k":"weakens"},{"s":"M-0013","t":"C-0004","k":"verifies","role":"p","note":"Supplies the committed record of cluster I/O that recomputation checks against declared inference (Dean (2026), Cankaya et al. (2026))."},{"s":"M-0013","t":"C-0009","k":"verifies","role":"s","note":"Aims to make covert exfiltration of results through tapped links infeasible (Cankaya et al. (2026))."},{"s":"M-0013","t":"C-0005","k":"verifies","role":"s","note":"Replaying challenged records with the declared model checks which model produced outputs (Cankaya et al. (2026), Dean (2026))."},{"s":"O-0101","t":"M-0013","k":"works_on"},{"s":"O-0160","t":"M-0013","k":"works_on"},{"s":"O-0201","t":"M-0013","k":"works_on"},{"s":"O-0202","t":"M-0013","k":"works_on"},{"s":"O-0209","t":"M-0013","k":"works_on"},{"s":"M-0013","t":"M-0001","k":"depends_on","note":"Challenged records are checked by recomputing them."},{"s":"M-0013","t":"M-0002","k":"depends_on","note":"Bit-exact replay is the main proposed way to remove covert capacity in model outputs."},{"s":"M-0013","t":"M-0017","k":"depends_on","note":"Taps and gateway devices must be physically protected and the facility monitored so all traffic passes through them."},{"s":"M-0013","t":"M-0022","k":"depends_on","note":"Radio, power-line and thermal channels bypass the tapped links."},{"s":"M-0013","t":"M-0003","k":"complements"},{"s":"M-0013","t":"M-0014","k":"complements"},{"s":"M-0013","t":"M-0015","k":"complements"},{"s":"M-0013","t":"M-0016","k":"complements"},{"s":"M-0013","t":"M-0024","k":"complements"},{"s":"M-0013","t":"M-0008","k":"alternative"},{"s":"M-0013","t":"K-0014","k":"uses_concept"},{"s":"M-0013","t":"K-0024","k":"uses_concept"},{"s":"M-0013","t":"K-0009","k":"uses_concept"},{"s":"M-0013","t":"K-0020","k":"uses_concept"},{"s":"M-0013","t":"K-0013","k":"uses_concept"},{"s":"M-0013","t":"K-0022","k":"uses_concept"},{"s":"M-0013","t":"K-0008","k":"uses_concept"},{"s":"M-0013","t":"K-0019","k":"uses_concept"},{"s":"M-0013","t":"K-0001","k":"uses_concept"},{"s":"M-0013","t":"K-0002","k":"uses_concept"},{"s":"M-0013","t":"T.evidence-binding","k":"faces"},{"s":"M-0013","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0013","t":"T.performance-compatibility","k":"faces"},{"s":"M-0013","t":"T.hardware-trust","k":"faces"},{"s":"M-0013","t":"T.privacy-leakage","k":"faces"},{"s":"M-0013","t":"T.adversarial-validation","k":"faces"},{"s":"M-0013","t":"G.off-chip-devices","k":"in_category"},{"s":"M-0013.B1","t":"M-0013","k":"blocks"},{"s":"M-0013.B1","t":"T.performance-compatibility","k":"theme"},{"s":"M-0013.B2","t":"M-0013","k":"blocks"},{"s":"M-0013.B2","t":"T.evidence-binding","k":"theme"},{"s":"M-0013.B2","t":"M-0002","k":"waits_on"},{"s":"M-0013.B3","t":"M-0013","k":"blocks"},{"s":"M-0013.B3","t":"T.hardware-trust","k":"theme"},{"s":"M-0013.B3","t":"M-0017","k":"waits_on"},{"s":"M-0013.B4","t":"M-0013","k":"blocks"},{"s":"M-0013.B4","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0013.B4","t":"M-0022","k":"waits_on"},{"s":"M-0013.B5","t":"M-0013","k":"blocks"},{"s":"M-0013.B5","t":"T.adversarial-validation","k":"theme"},{"s":"M-0013.F1","t":"M-0013","k":"weakens"},{"s":"M-0013.F2","t":"M-0013","k":"weakens"},{"s":"M-0013.F3","t":"M-0013","k":"weakens"},{"s":"M-0013.F4","t":"M-0013","k":"weakens"},{"s":"M-0013.F5","t":"M-0013","k":"weakens"},{"s":"M-0013.F6","t":"M-0013","k":"weakens"},{"s":"M-0010","t":"C-0004","k":"verifies","role":"p","note":"Classifying training versus other workloads from counters (Rahman & Tajdari (2026)) or timing (Monfared et al. (2026))."},{"s":"M-0010","t":"C-0003","k":"verifies","role":"p","note":"Utilization and residency signals indicate whether declared-idle hardware is busy (Monfared et al. (2026))."},{"s":"M-0010","t":"C-0010","k":"verifies","role":"s","note":"Contention from undeclared co-running workloads shifts challenge timing (Monfared et al. (2026)); coverage of other chips needs other mechanisms."},{"s":"M-0010","t":"C-0007","k":"verifies","role":"s","note":"Counters for FLOP, memory and interconnect traffic are proposed as meters for compute accounting (Kulp et al. (2024), O'Gara et al. (2025))."},{"s":"O-0202","t":"M-0010","k":"works_on"},{"s":"M-0010","t":"M-0008","k":"depends_on","note":"A tamper-resistant read path, an authenticated channel and secure boot of the monitoring software are needed for counters to be trustworthy (S-0037)."},{"s":"M-0010","t":"M-0016","k":"complements"},{"s":"M-0010","t":"M-0021","k":"complements"},{"s":"M-0010","t":"M-0022","k":"complements"},{"s":"M-0010","t":"K-0025","k":"uses_concept"},{"s":"M-0010","t":"K-0023","k":"uses_concept"},{"s":"M-0010","t":"K-0013","k":"uses_concept"},{"s":"M-0010","t":"K-0016","k":"uses_concept"},{"s":"M-0010","t":"K-0020","k":"uses_concept"},{"s":"M-0010","t":"K-0007","k":"uses_concept"},{"s":"M-0010","t":"K-0018","k":"uses_concept"},{"s":"M-0010","t":"T.hardware-trust","k":"faces"},{"s":"M-0010","t":"T.privacy-leakage","k":"faces"},{"s":"M-0010","t":"T.adversarial-validation","k":"faces"},{"s":"M-0010","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0010","t":"T.performance-compatibility","k":"faces"},{"s":"M-0010","t":"G.on-chip","k":"in_category"},{"s":"M-0010.B1","t":"M-0010","k":"blocks"},{"s":"M-0010.B1","t":"T.hardware-trust","k":"theme"},{"s":"M-0010.B1","t":"M-0009","k":"waits_on"},{"s":"M-0010.B2","t":"M-0010","k":"blocks"},{"s":"M-0010.B2","t":"T.privacy-leakage","k":"theme"},{"s":"M-0010.B3","t":"M-0010","k":"blocks"},{"s":"M-0010.B3","t":"T.performance-compatibility","k":"theme"},{"s":"M-0010.B4","t":"M-0010","k":"blocks"},{"s":"M-0010.B4","t":"T.adversarial-validation","k":"theme"},{"s":"M-0010.F1","t":"M-0010","k":"weakens"},{"s":"M-0010.F2","t":"M-0010","k":"weakens"},{"s":"M-0010.F3","t":"M-0010","k":"weakens"},{"s":"M-0010.F4","t":"M-0010","k":"weakens"},{"s":"M-0010.F5","t":"M-0010","k":"weakens"},{"s":"M-0006","t":"C-0007","k":"verifies","role":"p","note":"Transcript checks for rules on training compute, data and hyperparameters (Shavit; Choi et al.)."},{"s":"M-0006","t":"M-0005","k":"alternative"},{"s":"M-0006","t":"K-0009","k":"uses_concept"},{"s":"M-0006","t":"K-0008","k":"uses_concept"},{"s":"M-0006","t":"K-0020","k":"uses_concept"},{"s":"M-0006","t":"K-0001","k":"uses_concept"},{"s":"M-0006","t":"K-0002","k":"uses_concept"},{"s":"M-0006","t":"K-0023","k":"uses_concept"},{"s":"M-0006","t":"T.protocol-soundness","k":"faces"},{"s":"M-0006","t":"T.adversarial-validation","k":"faces"},{"s":"M-0006","t":"T.privacy-leakage","k":"faces"},{"s":"M-0006","t":"T.performance-compatibility","k":"faces"},{"s":"M-0006","t":"T.evidence-binding","k":"faces"},{"s":"M-0006","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0006.B1","t":"M-0006","k":"blocks"},{"s":"M-0006.B1","t":"T.privacy-leakage","k":"theme"},{"s":"M-0006.B2","t":"M-0006","k":"blocks"},{"s":"M-0006.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0006.B3","t":"M-0006","k":"blocks"},{"s":"M-0006.B3","t":"T.performance-compatibility","k":"theme"},{"s":"M-0006.B4","t":"M-0006","k":"blocks"},{"s":"M-0006.B4","t":"T.protocol-soundness","k":"theme"},{"s":"M-0006.B5","t":"M-0006","k":"blocks"},{"s":"M-0006.B5","t":"T.evidence-binding","k":"theme"},{"s":"M-0006.F1","t":"M-0006","k":"weakens"},{"s":"M-0006.F2","t":"M-0006","k":"weakens"},{"s":"M-0006.F3","t":"M-0006","k":"weakens"},{"s":"M-0006.F4","t":"M-0006","k":"weakens"},{"s":"M-0006.F5","t":"M-0006","k":"weakens"},{"s":"M-0007","t":"C-0010","k":"verifies","role":"p","note":"On declared hardware only: bounds capacity left for unmonitored work; cannot find undeclared facilities."},{"s":"M-0007","t":"C-0003","k":"verifies","role":"s","note":"Keeping declared hardware provably busy with agreed work, as an alternative to showing it idle."},{"s":"M-0007","t":"C-0004","k":"verifies","role":"s","note":"Attestable's pacing proposal pairs work accounting with ZK inference proofs."},{"s":"O-0120","t":"M-0007","k":"works_on"},{"s":"O-0121","t":"M-0007","k":"works_on"},{"s":"M-0007","t":"M-0004","k":"complements"},{"s":"M-0007","t":"M-0015","k":"complements"},{"s":"M-0007","t":"K-0011","k":"uses_concept"},{"s":"M-0007","t":"K-0012","k":"uses_concept"},{"s":"M-0007","t":"K-0016","k":"uses_concept"},{"s":"M-0007","t":"K-0023","k":"uses_concept"},{"s":"M-0007","t":"K-0025","k":"uses_concept"},{"s":"M-0007","t":"T.capacity-bounds","k":"faces"},{"s":"M-0007","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0007","t":"T.protocol-soundness","k":"faces"},{"s":"M-0007","t":"T.adversarial-validation","k":"faces"},{"s":"M-0007","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0007.B1","t":"M-0007","k":"blocks"},{"s":"M-0007.B1","t":"T.capacity-bounds","k":"theme"},{"s":"M-0007.B2","t":"M-0007","k":"blocks"},{"s":"M-0007.B2","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0007.B3","t":"M-0007","k":"blocks"},{"s":"M-0007.B3","t":"T.adversarial-validation","k":"theme"},{"s":"M-0007.F1","t":"M-0007","k":"weakens"},{"s":"M-0007.F2","t":"M-0007","k":"weakens"},{"s":"M-0007.F3","t":"M-0007","k":"weakens"},{"s":"M-0020","t":"C-0010","k":"verifies","role":"p","note":"Searches for large facilities that have not been declared."},{"s":"M-0020","t":"C-0001","k":"verifies","role":"s","note":"Estimates the power capacity, and so roughly the compute, of observed facilities."},{"s":"O-0102","t":"M-0020","k":"works_on"},{"s":"O-0201","t":"M-0020","k":"works_on"},{"s":"O-0208","t":"M-0020","k":"works_on"},{"s":"M-0020","t":"M-0021","k":"complements"},{"s":"M-0020","t":"M-0018","k":"complements"},{"s":"M-0020","t":"K-0016","k":"uses_concept"},{"s":"M-0020","t":"K-0003","k":"uses_concept"},{"s":"M-0020","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0020","t":"T.adversarial-validation","k":"faces"},{"s":"M-0020","t":"T.capacity-bounds","k":"faces"},{"s":"M-0020","t":"G.remote-sensing","k":"in_category"},{"s":"M-0020.B1","t":"M-0020","k":"blocks"},{"s":"M-0020.B1","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0020.B2","t":"M-0020","k":"blocks"},{"s":"M-0020.B2","t":"T.adversarial-validation","k":"theme"},{"s":"M-0020.B3","t":"M-0020","k":"blocks"},{"s":"M-0020.B3","t":"T.access-governance","k":"theme"},{"s":"M-0020.F1","t":"M-0020","k":"weakens"},{"s":"M-0020.F2","t":"M-0020","k":"weakens"},{"s":"M-0020.F3","t":"M-0020","k":"weakens"},{"s":"M-0003","t":"C-0004","k":"verifies","role":"p","note":"Proposed as the correctness check for an inference-only retrofit (Dean (2026))."},{"s":"M-0003","t":"C-0007","k":"verifies","role":"s","note":"Proposed for later R&D verification by treating training steps as packets (Dean (2026), Design (2026))."},{"s":"O-0101","t":"M-0003","k":"works_on"},{"s":"O-0201","t":"M-0003","k":"works_on"},{"s":"M-0003","t":"M-0002","k":"depends_on","note":"Packets must be reproducible, which needs deterministic execution."},{"s":"M-0003","t":"M-0013","k":"depends_on","note":"Network taps copy traffic to the recomputation server."},{"s":"M-0003","t":"M-0001","k":"complements"},{"s":"M-0003","t":"K-0009","k":"uses_concept"},{"s":"M-0003","t":"K-0014","k":"uses_concept"},{"s":"M-0003","t":"K-0016","k":"uses_concept"},{"s":"M-0003","t":"K-0020","k":"uses_concept"},{"s":"M-0003","t":"K-0025","k":"uses_concept"},{"s":"M-0003","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0003","t":"T.performance-compatibility","k":"faces"},{"s":"M-0003","t":"T.hardware-trust","k":"faces"},{"s":"M-0003","t":"T.protocol-soundness","k":"faces"},{"s":"M-0003","t":"G.isolation-architecture","k":"in_category"},{"s":"M-0003.B1","t":"M-0003","k":"blocks"},{"s":"M-0003.B1","t":"T.performance-compatibility","k":"theme"},{"s":"M-0003.B1","t":"M-0002","k":"waits_on"},{"s":"M-0003.B2","t":"M-0003","k":"blocks"},{"s":"M-0003.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0003.B3","t":"M-0003","k":"blocks"},{"s":"M-0003.B3","t":"T.hardware-trust","k":"theme"},{"s":"M-0003.B3","t":"M-0013","k":"waits_on"},{"s":"M-0003.B4","t":"M-0003","k":"blocks"},{"s":"M-0003.B4","t":"T.performance-compatibility","k":"theme"},{"s":"M-0003.F1","t":"M-0003","k":"weakens"},{"s":"M-0003.F2","t":"M-0003","k":"weakens"},{"s":"M-0023","t":"C-0006","k":"verifies","role":"p","note":"Attests that a measured safeguard program (guardrail, filter, monitor) mediated the attested responses; coverage of all traffic is not established."},{"s":"M-0023","t":"C-0005","k":"verifies","role":"s","note":"Property and audit attestations bind responses to a measured model (Chantasantitam et al. (2026), Schnabl et al. (2025))."},{"s":"O-0142","t":"M-0023","k":"works_on"},{"s":"O-0202","t":"M-0023","k":"works_on"},{"s":"M-0023","t":"M-0008","k":"depends_on","note":"Current designs rely on TEE measurement and remote attestation."},{"s":"M-0023","t":"M-0012","k":"depends_on","note":"Safeguard evidence is meaningful only when bound to the model actually served."},{"s":"M-0023","t":"M-0001","k":"alternative"},{"s":"M-0023","t":"K-0001","k":"uses_concept"},{"s":"M-0023","t":"K-0002","k":"uses_concept"},{"s":"M-0023","t":"K-0004","k":"uses_concept"},{"s":"M-0023","t":"K-0005","k":"uses_concept"},{"s":"M-0023","t":"K-0006","k":"uses_concept"},{"s":"M-0023","t":"K-0009","k":"uses_concept"},{"s":"M-0023","t":"K-0018","k":"uses_concept"},{"s":"M-0023","t":"K-0019","k":"uses_concept"},{"s":"M-0023","t":"K-0024","k":"uses_concept"},{"s":"M-0023","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0023","t":"T.evidence-binding","k":"faces"},{"s":"M-0023","t":"T.hardware-trust","k":"faces"},{"s":"M-0023","t":"T.performance-compatibility","k":"faces"},{"s":"M-0023","t":"T.adversarial-validation","k":"faces"},{"s":"M-0023","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0023.B1","t":"M-0023","k":"blocks"},{"s":"M-0023.B1","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0023.B2","t":"M-0023","k":"blocks"},{"s":"M-0023.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0023.B2","t":"M-0008","k":"waits_on"},{"s":"M-0023.B3","t":"M-0023","k":"blocks"},{"s":"M-0023.B3","t":"T.hardware-trust","k":"theme"},{"s":"M-0023.B3","t":"M-0008","k":"waits_on"},{"s":"M-0023.B4","t":"M-0023","k":"blocks"},{"s":"M-0023.B4","t":"T.evidence-binding","k":"theme"},{"s":"M-0023.B4","t":"M-0012","k":"waits_on"},{"s":"M-0023.B5","t":"M-0023","k":"blocks"},{"s":"M-0023.B5","t":"T.adversarial-validation","k":"theme"},{"s":"M-0023.F1","t":"M-0023","k":"weakens"},{"s":"M-0023.F2","t":"M-0023","k":"weakens"},{"s":"M-0023.F3","t":"M-0023","k":"weakens"},{"s":"M-0023.F4","t":"M-0023","k":"weakens"},{"s":"M-0023.F5","t":"M-0023","k":"weakens"},{"s":"M-0001","t":"C-0005","k":"verifies","role":"p","note":"Checks that sampled recorded outputs are consistent with the declared model, precision and sampling settings."},{"s":"M-0001","t":"C-0009","k":"verifies","role":"s","note":"Bounds how much information can be hidden steganographically in checked outputs. It is not a stand-alone defence against weight exfiltration (Rinberg et al. (2025))."},{"s":"M-0001","t":"C-0004","k":"verifies","role":"s","note":"Proposed as the correctness check in inference-only retrofit plans. Completeness needs other mechanisms (Dean (2026), Design (2026))."},{"s":"O-0100","t":"M-0001","k":"works_on"},{"s":"O-0101","t":"M-0001","k":"works_on"},{"s":"O-0201","t":"M-0001","k":"works_on"},{"s":"O-0202","t":"M-0001","k":"works_on"},{"s":"M-0001","t":"M-0013","k":"depends_on","note":"Network taps or trusted logging supply the recorded inputs and outputs that are sampled."},{"s":"M-0001","t":"M-0012","k":"complements"},{"s":"M-0001","t":"M-0004","k":"alternative"},{"s":"M-0001","t":"K-0001","k":"uses_concept"},{"s":"M-0001","t":"K-0002","k":"uses_concept"},{"s":"M-0001","t":"K-0008","k":"uses_concept"},{"s":"M-0001","t":"K-0009","k":"uses_concept"},{"s":"M-0001","t":"K-0014","k":"uses_concept"},{"s":"M-0001","t":"K-0018","k":"uses_concept"},{"s":"M-0001","t":"K-0020","k":"uses_concept"},{"s":"M-0001","t":"K-0022","k":"uses_concept"},{"s":"M-0001","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0001","t":"T.hardware-trust","k":"faces"},{"s":"M-0001","t":"T.adversarial-validation","k":"faces"},{"s":"M-0001","t":"T.protocol-soundness","k":"faces"},{"s":"M-0001","t":"T.performance-compatibility","k":"faces"},{"s":"M-0001","t":"T.privacy-leakage","k":"faces"},{"s":"M-0001","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0001.B1","t":"M-0001","k":"blocks"},{"s":"M-0001.B1","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0001.B1","t":"M-0013","k":"waits_on"},{"s":"M-0001.B2","t":"M-0001","k":"blocks"},{"s":"M-0001.B2","t":"T.hardware-trust","k":"theme"},{"s":"M-0001.B3","t":"M-0001","k":"blocks"},{"s":"M-0001.B3","t":"T.adversarial-validation","k":"theme"},{"s":"M-0001.B4","t":"M-0001","k":"blocks"},{"s":"M-0001.B4","t":"T.performance-compatibility","k":"theme"},{"s":"M-0001.B5","t":"M-0001","k":"blocks"},{"s":"M-0001.B5","t":"T.privacy-leakage","k":"theme"},{"s":"M-0001.F1","t":"M-0001","k":"weakens"},{"s":"M-0001.F2","t":"M-0001","k":"weakens"},{"s":"M-0001.F3","t":"M-0001","k":"weakens"},{"s":"M-0001.F4","t":"M-0001","k":"weakens"},{"s":"M-0022","t":"C-0008","k":"verifies","role":"p","note":"Bounds the capacity of physical covert channels out of an enclosure, so that monitored links carry all significant traffic."},{"s":"M-0022","t":"C-0009","k":"verifies","role":"s","note":"Supports arguments that weights cannot leave by unmonitored physical routes."},{"s":"M-0022","t":"C-0004","k":"verifies","role":"s","note":"Inference-only designs count on suppressing unmonitored physical channels so that all significant traffic passes the taps (Cankaya (2026))."},{"s":"O-0202","t":"M-0022","k":"works_on"},{"s":"M-0022","t":"M-0013","k":"complements"},{"s":"M-0022","t":"M-0014","k":"complements"},{"s":"M-0022","t":"M-0017","k":"complements"},{"s":"M-0022","t":"M-0024","k":"complements"},{"s":"M-0022","t":"K-0013","k":"uses_concept"},{"s":"M-0022","t":"K-0014","k":"uses_concept"},{"s":"M-0022","t":"K-0017","k":"uses_concept"},{"s":"M-0022","t":"K-0021","k":"uses_concept"},{"s":"M-0022","t":"K-0022","k":"uses_concept"},{"s":"M-0022","t":"T.adversarial-validation","k":"faces"},{"s":"M-0022","t":"T.capacity-bounds","k":"faces"},{"s":"M-0022","t":"T.performance-compatibility","k":"faces"},{"s":"M-0022","t":"T.hardware-trust","k":"faces"},{"s":"M-0022","t":"G.off-chip-devices","k":"in_category"},{"s":"M-0022.B1","t":"M-0022","k":"blocks"},{"s":"M-0022.B1","t":"T.adversarial-validation","k":"theme"},{"s":"M-0022.B2","t":"M-0022","k":"blocks"},{"s":"M-0022.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0022.F1","t":"M-0022","k":"weakens"},{"s":"M-0022.F2","t":"M-0022","k":"weakens"},{"s":"M-0022.F3","t":"M-0022","k":"weakens"},{"s":"M-0017","t":"C-0004","k":"verifies","role":"s","note":"Protects the integrity of taps, gateways and recomputation hardware used for inference-only verification (Cankaya (2026), Dean (2026))."},{"s":"M-0017","t":"C-0008","k":"verifies","role":"s","note":"Protects network devices that enforce or monitor bandwidth boundaries (Cankaya (2026))."},{"s":"M-0017","t":"M-0013","k":"complements"},{"s":"M-0017","t":"M-0014","k":"complements"},{"s":"M-0017","t":"K-0015","k":"uses_concept"},{"s":"M-0017","t":"K-0005","k":"uses_concept"},{"s":"M-0017","t":"K-0018","k":"uses_concept"},{"s":"M-0017","t":"K-0002","k":"uses_concept"},{"s":"M-0017","t":"T.hardware-trust","k":"faces"},{"s":"M-0017","t":"T.adversarial-validation","k":"faces"},{"s":"M-0017","t":"T.access-governance","k":"faces"},{"s":"M-0017","t":"T.performance-compatibility","k":"faces"},{"s":"M-0017","t":"G.off-chip-devices","k":"in_category"},{"s":"M-0017.B1","t":"M-0017","k":"blocks"},{"s":"M-0017.B1","t":"T.hardware-trust","k":"theme"},{"s":"M-0017.B2","t":"M-0017","k":"blocks"},{"s":"M-0017.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0017.B3","t":"M-0017","k":"blocks"},{"s":"M-0017.B3","t":"T.access-governance","k":"theme"},{"s":"M-0017.B4","t":"M-0017","k":"blocks"},{"s":"M-0017.B4","t":"T.adversarial-validation","k":"theme"},{"s":"M-0017.F1","t":"M-0017","k":"weakens"},{"s":"M-0017.F2","t":"M-0017","k":"weakens"},{"s":"M-0017.F3","t":"M-0017","k":"weakens"},{"s":"M-0008","t":"C-0005","k":"verifies","role":"p","note":"Attests the software stack that produced responses, and the model too when paired with a weight commitment (see Model identity attestation)."},{"s":"M-0008","t":"C-0006","k":"verifies","role":"s","note":"Can attest that measured policy software, such as filters and logging, wrapped the model (Z (2026)). The evaluation variant is Attestable Audits."},{"s":"M-0008","t":"C-0004","k":"verifies","role":"s","note":"Attests a declared inference deployment, but not that the same chips ran no other workloads (Z (2026))."},{"s":"M-0008","t":"C-0007","k":"verifies","role":"s","note":"PALM attests single-node training and fine-tuning operations (Chantasantitam et al. (2026)). Distributed training is left open."},{"s":"O-0140","t":"M-0008","k":"works_on"},{"s":"O-0141","t":"M-0008","k":"works_on"},{"s":"O-0142","t":"M-0008","k":"works_on"},{"s":"O-0202","t":"M-0008","k":"works_on"},{"s":"O-0206","t":"M-0008","k":"works_on"},{"s":"M-0008","t":"M-0009","k":"complements"},{"s":"M-0008","t":"M-0010","k":"complements"},{"s":"M-0008","t":"M-0012","k":"complements"},{"s":"M-0008","t":"M-0023","k":"complements"},{"s":"M-0008","t":"M-0025","k":"complements"},{"s":"M-0008","t":"M-0001","k":"alternative"},{"s":"M-0008","t":"M-0004","k":"alternative"},{"s":"M-0008","t":"K-0006","k":"uses_concept"},{"s":"M-0008","t":"K-0004","k":"uses_concept"},{"s":"M-0008","t":"K-0005","k":"uses_concept"},{"s":"M-0008","t":"K-0013","k":"uses_concept"},{"s":"M-0008","t":"K-0015","k":"uses_concept"},{"s":"M-0008","t":"K-0018","k":"uses_concept"},{"s":"M-0008","t":"K-0019","k":"uses_concept"},{"s":"M-0008","t":"K-0024","k":"uses_concept"},{"s":"M-0008","t":"K-0001","k":"uses_concept"},{"s":"M-0008","t":"K-0002","k":"uses_concept"},{"s":"M-0008","t":"T.hardware-trust","k":"faces"},{"s":"M-0008","t":"T.evidence-binding","k":"faces"},{"s":"M-0008","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0008","t":"T.adversarial-validation","k":"faces"},{"s":"M-0008","t":"T.performance-compatibility","k":"faces"},{"s":"M-0008","t":"G.on-chip","k":"in_category"},{"s":"M-0008.B1","t":"M-0008","k":"blocks"},{"s":"M-0008.B1","t":"T.hardware-trust","k":"theme"},{"s":"M-0008.B1","t":"M-0009","k":"waits_on"},{"s":"M-0008.B2","t":"M-0008","k":"blocks"},{"s":"M-0008.B2","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0008.B2","t":"M-0010","k":"waits_on"},{"s":"M-0008.B3","t":"M-0008","k":"blocks"},{"s":"M-0008.B3","t":"T.performance-compatibility","k":"theme"},{"s":"M-0008.B4","t":"M-0008","k":"blocks"},{"s":"M-0008.B4","t":"T.access-governance","k":"theme"},{"s":"M-0008.B5","t":"M-0008","k":"blocks"},{"s":"M-0008.B5","t":"T.performance-compatibility","k":"theme"},{"s":"M-0008.F1","t":"M-0008","k":"weakens"},{"s":"M-0008.F2","t":"M-0008","k":"weakens"},{"s":"M-0008.F3","t":"M-0008","k":"weakens"},{"s":"M-0008.F4","t":"M-0008","k":"weakens"},{"s":"M-0008.F5","t":"M-0008","k":"weakens"},{"s":"M-0008.F6","t":"M-0008","k":"weakens"},{"s":"M-0008.F7","t":"M-0008","k":"weakens"},{"s":"M-0008.F8","t":"M-0008","k":"weakens"},{"s":"M-0016","t":"C-0003","k":"verifies","role":"p","note":"Compute and memory probes can reveal whether a GPU is engaged in other work (Monfared et al. (2026))."},{"s":"M-0016","t":"C-0004","k":"verifies","role":"s","note":"Listed as an alternative inference-verification direction that may not need a hardware retrofit (Dean (2026)); bounds spare memory (Cankaya (2026))."},{"s":"M-0016","t":"C-0002","k":"verifies","role":"s","note":"Speed-of-light bounds on signed challenge round trips underlie delay-based location checks; see Chip location verification."},{"s":"O-0101","t":"M-0016","k":"works_on"},{"s":"O-0202","t":"M-0016","k":"works_on"},{"s":"M-0016","t":"M-0014","k":"depends_on","note":"Excluding remote memory during challenges may need physical disconnection or isolation of the device group."},{"s":"M-0016","t":"M-0015","k":"complements"},{"s":"M-0016","t":"M-0010","k":"alternative"},{"s":"M-0016","t":"K-0012","k":"uses_concept"},{"s":"M-0016","t":"K-0011","k":"uses_concept"},{"s":"M-0016","t":"K-0016","k":"uses_concept"},{"s":"M-0016","t":"K-0001","k":"uses_concept"},{"s":"M-0016","t":"K-0002","k":"uses_concept"},{"s":"M-0016","t":"K-0018","k":"uses_concept"},{"s":"M-0016","t":"K-0020","k":"uses_concept"},{"s":"M-0016","t":"T.capacity-bounds","k":"faces"},{"s":"M-0016","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0016","t":"T.protocol-soundness","k":"faces"},{"s":"M-0016","t":"T.adversarial-validation","k":"faces"},{"s":"M-0016","t":"T.performance-compatibility","k":"faces"},{"s":"M-0016","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0016.B1","t":"M-0016","k":"blocks"},{"s":"M-0016.B1","t":"T.adversarial-validation","k":"theme"},{"s":"M-0016.B2","t":"M-0016","k":"blocks"},{"s":"M-0016.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0016.B3","t":"M-0016","k":"blocks"},{"s":"M-0016.B3","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0016.B3","t":"M-0014","k":"waits_on"},{"s":"M-0016.F1","t":"M-0016","k":"weakens"},{"s":"M-0016.F2","t":"M-0016","k":"weakens"},{"s":"M-0016.F3","t":"M-0016","k":"weakens"},{"s":"M-0021","t":"C-0004","k":"verifies","role":"p","note":"Classifies observed activity as training, inference or non-ML work."},{"s":"M-0021","t":"C-0007","k":"verifies","role":"s","note":"Can flag training on hardware declared for other uses; does not measure training size by itself."},{"s":"O-0101","t":"M-0021","k":"works_on"},{"s":"M-0021","t":"M-0010","k":"depends_on","note":"Classifiers that use software-read counters need a tamper-resistant, authenticated path for on-chip telemetry."},{"s":"M-0021","t":"M-0013","k":"complements"},{"s":"M-0021","t":"K-0025","k":"uses_concept"},{"s":"M-0021","t":"K-0013","k":"uses_concept"},{"s":"M-0021","t":"K-0007","k":"uses_concept"},{"s":"M-0021","t":"K-0018","k":"uses_concept"},{"s":"M-0021","t":"T.hardware-trust","k":"faces"},{"s":"M-0021","t":"T.adversarial-validation","k":"faces"},{"s":"M-0021","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0021","t":"T.evidence-binding","k":"faces"},{"s":"M-0021","t":"G.remote-sensing","k":"in_category"},{"s":"M-0021.B1","t":"M-0021","k":"blocks"},{"s":"M-0021.B1","t":"T.hardware-trust","k":"theme"},{"s":"M-0021.B1","t":"M-0010","k":"waits_on"},{"s":"M-0021.B2","t":"M-0021","k":"blocks"},{"s":"M-0021.B2","t":"T.adversarial-validation","k":"theme"},{"s":"M-0021.B3","t":"M-0021","k":"blocks"},{"s":"M-0021.B3","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0021.F1","t":"M-0021","k":"weakens"},{"s":"M-0021.F2","t":"M-0021","k":"weakens"},{"s":"M-0021.F3","t":"M-0021","k":"weakens"},{"s":"M-0021.F4","t":"M-0021","k":"weakens"},{"s":"M-0004","t":"C-0005","k":"verifies","role":"p","note":"Binds each proven output to committed weights and a public architecture."},{"s":"M-0004","t":"C-0004","k":"verifies","role":"s","note":"Attestable proposes using proofs to show accounted workloads used an approved, unchanged model."},{"s":"M-0004","t":"C-0006","k":"verifies","role":"s","note":"Attestable proposes that a proof could show an agreed input classifier was applied; South et al. prove evaluation results."},{"s":"O-0120","t":"M-0004","k":"works_on"},{"s":"O-0122","t":"M-0004","k":"works_on"},{"s":"M-0004","t":"K-0010","k":"uses_concept"},{"s":"M-0004","t":"K-0024","k":"uses_concept"},{"s":"M-0004","t":"K-0001","k":"uses_concept"},{"s":"M-0004","t":"K-0002","k":"uses_concept"},{"s":"M-0004","t":"K-0020","k":"uses_concept"},{"s":"M-0004","t":"K-0016","k":"uses_concept"},{"s":"M-0004","t":"K-0018","k":"uses_concept"},{"s":"M-0004","t":"T.performance-compatibility","k":"faces"},{"s":"M-0004","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0004","t":"T.evidence-binding","k":"faces"},{"s":"M-0004","t":"T.adversarial-validation","k":"faces"},{"s":"M-0004","t":"T.privacy-leakage","k":"faces"},{"s":"M-0004","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0004.B1","t":"M-0004","k":"blocks"},{"s":"M-0004.B1","t":"T.performance-compatibility","k":"theme"},{"s":"M-0004.B2","t":"M-0004","k":"blocks"},{"s":"M-0004.B2","t":"T.performance-compatibility","k":"theme"},{"s":"M-0004.B3","t":"M-0004","k":"blocks"},{"s":"M-0004.B3","t":"T.adversarial-validation","k":"theme"},{"s":"M-0004.B4","t":"M-0004","k":"blocks"},{"s":"M-0004.B4","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0004.B4","t":"M-0007","k":"waits_on"},{"s":"M-0004.F1","t":"M-0004","k":"weakens"},{"s":"M-0004.F2","t":"M-0004","k":"weakens"},{"s":"M-0004.F3","t":"M-0004","k":"weakens"},{"s":"M-0004.F4","t":"M-0004","k":"weakens"},{"s":"M-0005","t":"C-0007","k":"verifies","role":"p","note":"Proves training followed a committed specification and data; the frontier design adds compute-threshold attestations."},{"s":"M-0005","t":"M-0013","k":"depends_on","note":"The frontier-scale design by Peigné et al. anchors its commitments with an auditor-controlled network tap or an attested SmartNIC."},{"s":"M-0005","t":"K-0010","k":"uses_concept"},{"s":"M-0005","t":"K-0024","k":"uses_concept"},{"s":"M-0005","t":"K-0014","k":"uses_concept"},{"s":"M-0005","t":"K-0020","k":"uses_concept"},{"s":"M-0005","t":"K-0008","k":"uses_concept"},{"s":"M-0005","t":"K-0023","k":"uses_concept"},{"s":"M-0005","t":"T.performance-compatibility","k":"faces"},{"s":"M-0005","t":"T.protocol-soundness","k":"faces"},{"s":"M-0005","t":"T.hardware-trust","k":"faces"},{"s":"M-0005","t":"T.coverage-hidden-compute","k":"faces"},{"s":"M-0005","t":"T.evidence-binding","k":"faces"},{"s":"M-0005","t":"G.cryptographic-computational","k":"in_category"},{"s":"M-0005.B1","t":"M-0005","k":"blocks"},{"s":"M-0005.B1","t":"T.performance-compatibility","k":"theme"},{"s":"M-0005.B2","t":"M-0005","k":"blocks"},{"s":"M-0005.B2","t":"T.protocol-soundness","k":"theme"},{"s":"M-0005.B3","t":"M-0005","k":"blocks"},{"s":"M-0005.B3","t":"T.performance-compatibility","k":"theme"},{"s":"M-0005.B4","t":"M-0005","k":"blocks"},{"s":"M-0005.B4","t":"T.hardware-trust","k":"theme"},{"s":"M-0005.B4","t":"M-0013","k":"waits_on"},{"s":"M-0005.B5","t":"M-0005","k":"blocks"},{"s":"M-0005.B5","t":"T.coverage-hidden-compute","k":"theme"},{"s":"M-0005.F1","t":"M-0005","k":"weakens"},{"s":"M-0005.F2","t":"M-0005","k":"weakens"},{"s":"M-0005.F3","t":"M-0005","k":"weakens"},{"s":"M-0005.F4","t":"M-0005","k":"weakens"},{"s":"I-0011","t":"C-0004","k":"verifies","role":"p","note":"The stack's stated purpose: retrofitted data centres run only inference."},{"s":"I-0011","t":"C-0005","k":"verifies","role":"s","note":"Recomputation checks sampled packets against the declared model."},{"s":"I-0011","t":"C-0008","k":"verifies","role":"s","note":"Removing back-end networking limits communication between inference units."},{"s":"I-0011","t":"M-0013","k":"realises"},{"s":"I-0011","t":"M-0001","k":"realises"},{"s":"I-0011","t":"M-0003","k":"realises"},{"s":"I-0011","t":"M-0014","k":"realises"},{"s":"I-0011","t":"M-0015","k":"realises"},{"s":"I-0011","t":"M-0017","k":"realises"},{"s":"I-0011","t":"M-0022","k":"realises"},{"s":"O-0201","t":"I-0011","k":"develops"},{"s":"O-0101","t":"I-0011","k":"works_on"},{"s":"I-0011","t":"M-0001","k":"depends_on","note":"Correctness rests on sampled recomputation."},{"s":"I-0011","t":"M-0003","k":"depends_on","note":"Workloads must be organized into reproducible packets."},{"s":"I-0011","t":"K-0009","k":"uses_concept"},{"s":"I-0011","t":"K-0014","k":"uses_concept"},{"s":"I-0011","t":"K-0016","k":"uses_concept"},{"s":"I-0011","t":"K-0020","k":"uses_concept"},{"s":"I-0011","t":"K-0021","k":"uses_concept"},{"s":"I-0011","t":"K-0025","k":"uses_concept"},{"s":"I-0011","t":"T.coverage-hidden-compute","k":"faces"},{"s":"I-0011","t":"T.hardware-trust","k":"faces"},{"s":"I-0011","t":"T.performance-compatibility","k":"faces"},{"s":"I-0011","t":"T.adversarial-validation","k":"faces"},{"s":"I-0011","t":"T.protocol-soundness","k":"faces"},{"s":"I-0011","t":"G.isolation-architecture","k":"in_category"},{"s":"I-0011.B1","t":"I-0011","k":"blocks"},{"s":"I-0011.B1","t":"T.performance-compatibility","k":"theme"},{"s":"I-0011.B1","t":"M-0003","k":"waits_on"},{"s":"I-0011.B2","t":"I-0011","k":"blocks"},{"s":"I-0011.B2","t":"T.performance-compatibility","k":"theme"},{"s":"I-0011.B2","t":"M-0013","k":"waits_on"},{"s":"I-0011.B3","t":"I-0011","k":"blocks"},{"s":"I-0011.B3","t":"T.hardware-trust","k":"theme"},{"s":"I-0011.B3","t":"M-0017","k":"waits_on"},{"s":"I-0011.B4","t":"I-0011","k":"blocks"},{"s":"I-0011.B4","t":"T.coverage-hidden-compute","k":"theme"},{"s":"I-0011.B4","t":"M-0022","k":"waits_on"},{"s":"I-0011.B5","t":"I-0011","k":"blocks"},{"s":"I-0011.B5","t":"T.coverage-hidden-compute","k":"theme"},{"s":"I-0011.B5","t":"M-0015","k":"waits_on"},{"s":"I-0011.B6","t":"I-0011","k":"blocks"},{"s":"I-0011.B6","t":"T.adversarial-validation","k":"theme"},{"s":"I-0011.F1","t":"I-0011","k":"weakens"},{"s":"I-0011.F2","t":"I-0011","k":"weakens"},{"s":"I-0011.F3","t":"I-0011","k":"weakens"},{"s":"I-0013","t":"C-0005","k":"verifies","role":"s","note":"Attests the software release that served a request. Apple reports that model assets share the code's integrity protection ((SEAR) (2024))."},{"s":"I-0013","t":"M-0008","k":"realises"},{"s":"I-0013","t":"M-0008","k":"depends_on","note":"Relies on hardware attestation: the Secure Enclave on Apple silicon servers, and Intel TDX, NVIDIA confidential computing and Google's Titan chip on Google Cloud."},{"s":"I-0013","t":"K-0004","k":"uses_concept"},{"s":"I-0013","t":"K-0005","k":"uses_concept"},{"s":"I-0013","t":"K-0006","k":"uses_concept"},{"s":"I-0013","t":"K-0019","k":"uses_concept"},{"s":"I-0013","t":"T.evidence-binding","k":"faces"},{"s":"I-0013","t":"T.hardware-trust","k":"faces"},{"s":"I-0013","t":"T.adversarial-validation","k":"faces"},{"s":"I-0013","t":"G.on-chip","k":"in_category"},{"s":"I-0013.B1","t":"I-0013","k":"blocks"},{"s":"I-0013.B1","t":"T.evidence-binding","k":"theme"},{"s":"I-0013.B2","t":"I-0013","k":"blocks"},{"s":"I-0013.B2","t":"T.access-governance","k":"theme"},{"s":"I-0013.F1","t":"I-0013","k":"weakens"},{"s":"I-0013.F2","t":"I-0013","k":"weakens"},{"s":"I-0007","t":"C-0005","k":"verifies","role":"p","note":"Users can check that the model answering them is the audited one."},{"s":"I-0007","t":"C-0006","k":"verifies","role":"s","note":"Attests that declared safety benchmarks were run on that model and what they scored; it does not attest runtime safeguards."},{"s":"I-0007","t":"M-0008","k":"realises"},{"s":"I-0007","t":"M-0012","k":"realises"},{"s":"O-0142","t":"I-0007","k":"develops"},{"s":"I-0007","t":"M-0008","k":"depends_on","note":"Built on AWS Nitro Enclaves attestation."},{"s":"I-0007","t":"K-0006","k":"uses_concept"},{"s":"I-0007","t":"K-0004","k":"uses_concept"},{"s":"I-0007","t":"K-0024","k":"uses_concept"},{"s":"I-0007","t":"K-0019","k":"uses_concept"},{"s":"I-0007","t":"K-0022","k":"uses_concept"},{"s":"I-0007","t":"T.evidence-binding","k":"faces"},{"s":"I-0007","t":"T.hardware-trust","k":"faces"},{"s":"I-0007","t":"T.performance-compatibility","k":"faces"},{"s":"I-0007","t":"G.on-chip","k":"in_category"},{"s":"I-0007.B1","t":"I-0007","k":"blocks"},{"s":"I-0007.B1","t":"T.performance-compatibility","k":"theme"},{"s":"I-0007.B1","t":"M-0008","k":"waits_on"},{"s":"I-0007.B2","t":"I-0007","k":"blocks"},{"s":"I-0007.B2","t":"T.adversarial-validation","k":"theme"},{"s":"I-0007.F1","t":"I-0007","k":"weakens"},{"s":"I-0007.F2","t":"I-0007","k":"weakens"},{"s":"I-0007.F3","t":"I-0007","k":"weakens"},{"s":"I-0005","t":"C-0005","k":"verifies","role":"p","note":"Attestable reports proving y = F(W, x, r) for committed weights W."},{"s":"I-0005","t":"C-0004","k":"verifies","role":"s","note":"Proposed use: showing an accounted workload used an approved, unchanged model."},{"s":"I-0005","t":"C-0006","k":"verifies","role":"s","note":"Proposed use: showing an agreed input classifier was applied."},{"s":"I-0005","t":"M-0004","k":"realises"},{"s":"O-0120","t":"I-0005","k":"develops"},{"s":"I-0005","t":"K-0010","k":"uses_concept"},{"s":"I-0005","t":"K-0024","k":"uses_concept"},{"s":"I-0005","t":"K-0020","k":"uses_concept"},{"s":"I-0005","t":"T.adversarial-validation","k":"faces"},{"s":"I-0005","t":"T.coverage-hidden-compute","k":"faces"},{"s":"I-0005","t":"T.performance-compatibility","k":"faces"},{"s":"I-0005","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0005.B1","t":"I-0005","k":"blocks"},{"s":"I-0005.B1","t":"T.adversarial-validation","k":"theme"},{"s":"I-0005.B2","t":"I-0005","k":"blocks"},{"s":"I-0005.B2","t":"T.performance-compatibility","k":"theme"},{"s":"I-0005.B3","t":"I-0005","k":"blocks"},{"s":"I-0005.B3","t":"T.coverage-hidden-compute","k":"theme"},{"s":"I-0005.B3","t":"M-0007","k":"waits_on"},{"s":"I-0005.F1","t":"I-0005","k":"weakens"},{"s":"I-0005.F2","t":"I-0005","k":"weakens"},{"s":"I-0016","t":"C-0005","k":"verifies","role":"s","note":"Makes exact-match recomputation of served outputs possible when the verifier runs the same model, engine and hardware (Karvonen et al. (2025))."},{"s":"I-0016","t":"M-0002","k":"realises"},{"s":"I-0016","t":"K-0008","k":"uses_concept"},{"s":"I-0016","t":"K-0009","k":"uses_concept"},{"s":"I-0016","t":"T.performance-compatibility","k":"faces"},{"s":"I-0016","t":"T.adversarial-validation","k":"faces"},{"s":"I-0016","t":"T.privacy-leakage","k":"faces"},{"s":"I-0016","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0016.B1","t":"I-0016","k":"blocks"},{"s":"I-0016.B1","t":"T.performance-compatibility","k":"theme"},{"s":"I-0016.B2","t":"I-0016","k":"blocks"},{"s":"I-0016.B2","t":"T.performance-compatibility","k":"theme"},{"s":"I-0002","t":"C-0005","k":"verifies","role":"p","note":"Checks that outputs are consistent with the declared model, precision and sampling configuration."},{"s":"I-0002","t":"C-0009","k":"verifies","role":"s","note":"Used as the estimator in a weight-exfiltration detection scheme (Rinberg et al. (2025))."},{"s":"I-0002","t":"M-0001","k":"realises"},{"s":"I-0002","t":"K-0008","k":"uses_concept"},{"s":"I-0002","t":"K-0009","k":"uses_concept"},{"s":"I-0002","t":"K-0020","k":"uses_concept"},{"s":"I-0002","t":"T.adversarial-validation","k":"faces"},{"s":"I-0002","t":"T.protocol-soundness","k":"faces"},{"s":"I-0002","t":"T.privacy-leakage","k":"faces"},{"s":"I-0002","t":"T.performance-compatibility","k":"faces"},{"s":"I-0002","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0002.B1","t":"I-0002","k":"blocks"},{"s":"I-0002.B1","t":"T.privacy-leakage","k":"theme"},{"s":"I-0002.B2","t":"I-0002","k":"blocks"},{"s":"I-0002.B2","t":"T.performance-compatibility","k":"theme"},{"s":"I-0002.B3","t":"I-0002","k":"blocks"},{"s":"I-0002.B3","t":"T.adversarial-validation","k":"theme"},{"s":"I-0002.F1","t":"I-0002","k":"weakens"},{"s":"I-0002.F2","t":"I-0002","k":"weakens"},{"s":"I-0002.F3","t":"I-0002","k":"weakens"},{"s":"I-0014","t":"C-0005","k":"verifies","role":"p","note":"Proves an output follows from a committed model. South et al.'s results reach about a million parameters (South et al. (2024))."},{"s":"I-0014","t":"M-0004","k":"realises"},{"s":"I-0014","t":"K-0010","k":"uses_concept"},{"s":"I-0014","t":"K-0024","k":"uses_concept"},{"s":"I-0014","t":"K-0001","k":"uses_concept"},{"s":"I-0014","t":"K-0002","k":"uses_concept"},{"s":"I-0014","t":"T.performance-compatibility","k":"faces"},{"s":"I-0014","t":"T.adversarial-validation","k":"faces"},{"s":"I-0014","t":"T.evidence-binding","k":"faces"},{"s":"I-0014","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0014.B1","t":"I-0014","k":"blocks"},{"s":"I-0014.B1","t":"T.performance-compatibility","k":"theme"},{"s":"I-0014.F1","t":"I-0014","k":"weakens"},{"s":"I-0014.F2","t":"I-0014","k":"weakens"},{"s":"I-0012","t":"C-0004","k":"verifies","role":"p","note":"Challenged records are screened for inference versus training."},{"s":"I-0012","t":"C-0005","k":"verifies","role":"s","note":"Screening checks that the model is on an agreed whitelist."},{"s":"I-0012","t":"C-0006","k":"verifies","role":"s","note":"Screening checks that outputs are free of blacklisted uses, including with inspector agents."},{"s":"I-0012","t":"C-0010","k":"verifies","role":"s","note":"Memory challenges and resource accounting are proposed against hidden workloads."},{"s":"I-0012","t":"M-0013","k":"realises"},{"s":"I-0012","t":"M-0001","k":"realises"},{"s":"I-0012","t":"M-0002","k":"realises"},{"s":"I-0012","t":"M-0004","k":"realises"},{"s":"I-0012","t":"M-0015","k":"realises"},{"s":"I-0012","t":"M-0016","k":"realises"},{"s":"I-0012","t":"M-0022","k":"realises"},{"s":"O-0202","t":"I-0012","k":"develops"},{"s":"I-0012","t":"M-0013","k":"depends_on","note":"Taps are the default evidence-capture mechanism."},{"s":"I-0012","t":"M-0002","k":"depends_on","note":"Plan A evaluation relies on exact replay of declared computation."},{"s":"I-0012","t":"K-0001","k":"uses_concept"},{"s":"I-0012","t":"K-0002","k":"uses_concept"},{"s":"I-0012","t":"K-0009","k":"uses_concept"},{"s":"I-0012","t":"K-0010","k":"uses_concept"},{"s":"I-0012","t":"K-0013","k":"uses_concept"},{"s":"I-0012","t":"K-0014","k":"uses_concept"},{"s":"I-0012","t":"K-0015","k":"uses_concept"},{"s":"I-0012","t":"K-0018","k":"uses_concept"},{"s":"I-0012","t":"K-0020","k":"uses_concept"},{"s":"I-0012","t":"K-0024","k":"uses_concept"},{"s":"I-0012","t":"T.coverage-hidden-compute","k":"faces"},{"s":"I-0012","t":"T.hardware-trust","k":"faces"},{"s":"I-0012","t":"T.protocol-soundness","k":"faces"},{"s":"I-0012","t":"T.performance-compatibility","k":"faces"},{"s":"I-0012","t":"T.adversarial-validation","k":"faces"},{"s":"I-0012","t":"T.privacy-leakage","k":"faces"},{"s":"I-0012","t":"G.isolation-architecture","k":"in_category"},{"s":"I-0012.B1","t":"I-0012","k":"blocks"},{"s":"I-0012.B1","t":"T.performance-compatibility","k":"theme"},{"s":"I-0012.B1","t":"M-0013","k":"waits_on"},{"s":"I-0012.B2","t":"I-0012","k":"blocks"},{"s":"I-0012.B2","t":"T.performance-compatibility","k":"theme"},{"s":"I-0012.B2","t":"M-0002","k":"waits_on"},{"s":"I-0012.B3","t":"I-0012","k":"blocks"},{"s":"I-0012.B3","t":"T.hardware-trust","k":"theme"},{"s":"I-0012.B3","t":"M-0017","k":"waits_on"},{"s":"I-0012.B4","t":"I-0012","k":"blocks"},{"s":"I-0012.B4","t":"T.coverage-hidden-compute","k":"theme"},{"s":"I-0012.B4","t":"M-0022","k":"waits_on"},{"s":"I-0012.B5","t":"I-0012","k":"blocks"},{"s":"I-0012.B5","t":"T.coverage-hidden-compute","k":"theme"},{"s":"I-0012.B5","t":"M-0016","k":"waits_on"},{"s":"I-0012.B6","t":"I-0012","k":"blocks"},{"s":"I-0012.B6","t":"T.adversarial-validation","k":"theme"},{"s":"I-0012.F1","t":"I-0012","k":"weakens"},{"s":"I-0012.F2","t":"I-0012","k":"weakens"},{"s":"I-0012.F3","t":"I-0012","k":"weakens"},{"s":"I-0009","t":"C-0002","k":"verifies","role":"p","note":"Certifies a bounded region in which an attested workload's platform was running at a given time."},{"s":"I-0009","t":"M-0018","k":"realises"},{"s":"O-0180","t":"I-0009","k":"develops"},{"s":"I-0009","t":"M-0008","k":"depends_on","note":"Location evidence is bound to a hardware-rooted TEE attestation quote."},{"s":"I-0009","t":"K-0004","k":"uses_concept"},{"s":"I-0009","t":"K-0005","k":"uses_concept"},{"s":"I-0009","t":"K-0006","k":"uses_concept"},{"s":"I-0009","t":"K-0018","k":"uses_concept"},{"s":"I-0009","t":"T.hardware-trust","k":"faces"},{"s":"I-0009","t":"T.adversarial-validation","k":"faces"},{"s":"I-0009","t":"T.protocol-soundness","k":"faces"},{"s":"I-0009","t":"T.access-governance","k":"faces"},{"s":"I-0009","t":"G.accounting-provenance","k":"in_category"},{"s":"I-0009.B1","t":"I-0009","k":"blocks"},{"s":"I-0009.B1","t":"T.adversarial-validation","k":"theme"},{"s":"I-0009.B2","t":"I-0009","k":"blocks"},{"s":"I-0009.B2","t":"T.access-governance","k":"theme"},{"s":"I-0009.F1","t":"I-0009","k":"weakens"},{"s":"I-0009.F2","t":"I-0009","k":"weakens"},{"s":"I-0009.F3","t":"I-0009","k":"weakens"},{"s":"I-0004","t":"C-0010","k":"verifies","role":"s","note":"Proves matrix-multiplication work for consensus; not applied to bounding the spare capacity of declared hardware."},{"s":"I-0004","t":"M-0007","k":"realises"},{"s":"O-0121","t":"I-0004","k":"develops"},{"s":"I-0004","t":"K-0011","k":"uses_concept"},{"s":"I-0004","t":"K-0024","k":"uses_concept"},{"s":"I-0004","t":"K-0008","k":"uses_concept"},{"s":"I-0004","t":"T.capacity-bounds","k":"faces"},{"s":"I-0004","t":"T.protocol-soundness","k":"faces"},{"s":"I-0004","t":"T.adversarial-validation","k":"faces"},{"s":"I-0004","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0004.B1","t":"I-0004","k":"blocks"},{"s":"I-0004.B1","t":"T.capacity-bounds","k":"theme"},{"s":"I-0004.B2","t":"I-0004","k":"blocks"},{"s":"I-0004.B2","t":"T.adversarial-validation","k":"theme"},{"s":"I-0004.B3","t":"I-0004","k":"blocks"},{"s":"I-0004.B3","t":"T.performance-compatibility","k":"theme"},{"s":"I-0004.F1","t":"I-0004","k":"weakens"},{"s":"I-0004.F2","t":"I-0004","k":"weakens"},{"s":"I-0004.F3","t":"I-0004","k":"weakens"},{"s":"I-0010","t":"C-0009","k":"verifies","role":"p","note":"Designed to keep weights and inference data inside the facility; the report does not describe how an external party would verify this."},{"s":"I-0010","t":"C-0005","k":"verifies","role":"s","note":"The compute sanctum checks resident weights against reference measurements before serving."},{"s":"I-0010","t":"C-0004","k":"verifies","role":"s","note":"Scoped to serving already-trained models."},{"s":"I-0010","t":"M-0014","k":"realises"},{"s":"I-0010","t":"M-0022","k":"realises"},{"s":"O-0200","t":"I-0010","k":"develops"},{"s":"I-0010","t":"M-0012","k":"depends_on","note":"Integrity checks compare loaded weights with reference measurements from a trusted setup."},{"s":"I-0010","t":"K-0005","k":"uses_concept"},{"s":"I-0010","t":"K-0015","k":"uses_concept"},{"s":"I-0010","t":"K-0017","k":"uses_concept"},{"s":"I-0010","t":"K-0018","k":"uses_concept"},{"s":"I-0010","t":"K-0022","k":"uses_concept"},{"s":"I-0010","t":"T.hardware-trust","k":"faces"},{"s":"I-0010","t":"T.evidence-binding","k":"faces"},{"s":"I-0010","t":"T.access-governance","k":"faces"},{"s":"I-0010","t":"T.adversarial-validation","k":"faces"},{"s":"I-0010","t":"T.performance-compatibility","k":"faces"},{"s":"I-0010","t":"G.isolation-architecture","k":"in_category"},{"s":"I-0010.B1","t":"I-0010","k":"blocks"},{"s":"I-0010.B1","t":"T.adversarial-validation","k":"theme"},{"s":"I-0010.B2","t":"I-0010","k":"blocks"},{"s":"I-0010.B2","t":"T.access-governance","k":"theme"},{"s":"I-0010.B3","t":"I-0010","k":"blocks"},{"s":"I-0010.B3","t":"T.performance-compatibility","k":"theme"},{"s":"I-0010.B4","t":"I-0010","k":"blocks"},{"s":"I-0010.B4","t":"T.access-governance","k":"theme"},{"s":"I-0010.F1","t":"I-0010","k":"weakens"},{"s":"I-0010.F2","t":"I-0010","k":"weakens"},{"s":"I-0008","t":"C-0004","k":"verifies","role":"p","note":"SASH describes the aim as distinguishing inference from training in data centres ((SASH) (2026))."},{"s":"I-0008","t":"C-0005","k":"verifies","role":"s","note":"Recomputation uses another copy of the declared model ((SASH) (2026), (SASH) (2026))."},{"s":"I-0008","t":"M-0013","k":"realises"},{"s":"I-0008","t":"M-0001","k":"realises"},{"s":"O-0160","t":"I-0008","k":"develops"},{"s":"O-0206","t":"I-0008","k":"works_on"},{"s":"I-0008","t":"M-0002","k":"depends_on","note":"The recomputation check compares output text exactly."},{"s":"I-0008","t":"M-0017","k":"depends_on","note":"The logger and recomputation cluster must be protected against tampering."},{"s":"I-0008","t":"K-0014","k":"uses_concept"},{"s":"I-0008","t":"K-0009","k":"uses_concept"},{"s":"I-0008","t":"K-0020","k":"uses_concept"},{"s":"I-0008","t":"K-0025","k":"uses_concept"},{"s":"I-0008","t":"T.hardware-trust","k":"faces"},{"s":"I-0008","t":"T.performance-compatibility","k":"faces"},{"s":"I-0008","t":"T.evidence-binding","k":"faces"},{"s":"I-0008","t":"T.adversarial-validation","k":"faces"},{"s":"I-0008","t":"G.off-chip-devices","k":"in_category"},{"s":"I-0008.B1","t":"I-0008","k":"blocks"},{"s":"I-0008.B1","t":"T.hardware-trust","k":"theme"},{"s":"I-0008.B2","t":"I-0008","k":"blocks"},{"s":"I-0008.B2","t":"T.performance-compatibility","k":"theme"},{"s":"I-0008.B3","t":"I-0008","k":"blocks"},{"s":"I-0008.B3","t":"T.evidence-binding","k":"theme"},{"s":"I-0008.B3","t":"M-0002","k":"waits_on"},{"s":"I-0008.F1","t":"I-0008","k":"weakens"},{"s":"I-0008.F2","t":"I-0008","k":"weakens"},{"s":"I-0008.F3","t":"I-0008","k":"weakens"},{"s":"I-0006","t":"C-0005","k":"verifies","role":"p","note":"Clients check that the served weights match a committed root hash."},{"s":"I-0006","t":"M-0012","k":"realises"},{"s":"I-0006","t":"M-0008","k":"realises"},{"s":"O-0141","t":"I-0006","k":"develops"},{"s":"I-0006","t":"M-0008","k":"depends_on","note":"Relies on AMD SEV-SNP or Intel TDX attestation and NVIDIA GPU confidential computing."},{"s":"I-0006","t":"K-0024","k":"uses_concept"},{"s":"I-0006","t":"K-0004","k":"uses_concept"},{"s":"I-0006","t":"K-0006","k":"uses_concept"},{"s":"I-0006","t":"K-0005","k":"uses_concept"},{"s":"I-0006","t":"K-0019","k":"uses_concept"},{"s":"I-0006","t":"T.evidence-binding","k":"faces"},{"s":"I-0006","t":"T.hardware-trust","k":"faces"},{"s":"I-0006","t":"T.adversarial-validation","k":"faces"},{"s":"I-0006","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0006.B1","t":"I-0006","k":"blocks"},{"s":"I-0006.B1","t":"T.hardware-trust","k":"theme"},{"s":"I-0006.B1","t":"M-0008","k":"waits_on"},{"s":"I-0006.B2","t":"I-0006","k":"blocks"},{"s":"I-0006.B2","t":"T.adversarial-validation","k":"theme"},{"s":"I-0006.F1","t":"I-0006","k":"weakens"},{"s":"I-0006.F2","t":"I-0006","k":"weakens"},{"s":"I-0006.F3","t":"I-0006","k":"weakens"},{"s":"I-0001","t":"C-0005","k":"verifies","role":"p","note":"Checks that the provider produced outputs with the claimed model weights, prompt and precision."},{"s":"I-0001","t":"M-0001","k":"realises"},{"s":"O-0100","t":"I-0001","k":"develops"},{"s":"I-0001","t":"K-0008","k":"uses_concept"},{"s":"I-0001","t":"K-0009","k":"uses_concept"},{"s":"I-0001","t":"K-0024","k":"uses_concept"},{"s":"I-0001","t":"T.adversarial-validation","k":"faces"},{"s":"I-0001","t":"T.protocol-soundness","k":"faces"},{"s":"I-0001","t":"T.privacy-leakage","k":"faces"},{"s":"I-0001","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0001.B1","t":"I-0001","k":"blocks"},{"s":"I-0001.B1","t":"T.adversarial-validation","k":"theme"},{"s":"I-0001.B2","t":"I-0001","k":"blocks"},{"s":"I-0001.B2","t":"T.privacy-leakage","k":"theme"},{"s":"I-0001.F1","t":"I-0001","k":"weakens"},{"s":"I-0001.F2","t":"I-0001","k":"weakens"},{"s":"I-0001.F3","t":"I-0001","k":"weakens"},{"s":"I-0001.F4","t":"I-0001","k":"weakens"},{"s":"I-0015","t":"C-0005","k":"verifies","role":"p","note":"A client learns that a delegated inference output came from the declared model and input, if at least one provider is honest (Arun et al. (2025), Ersoy (2025))."},{"s":"I-0015","t":"C-0007","k":"verifies","role":"s","note":"Also covers training and fine-tuning jobs delegated to several providers (Arun et al. (2025))."},{"s":"I-0015","t":"M-0002","k":"realises"},{"s":"I-0015","t":"M-0006","k":"realises"},{"s":"I-0015","t":"K-0008","k":"uses_concept"},{"s":"I-0015","t":"K-0009","k":"uses_concept"},{"s":"I-0015","t":"T.performance-compatibility","k":"faces"},{"s":"I-0015","t":"T.adversarial-validation","k":"faces"},{"s":"I-0015","t":"T.privacy-leakage","k":"faces"},{"s":"I-0015","t":"T.protocol-soundness","k":"faces"},{"s":"I-0015","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0015.B1","t":"I-0015","k":"blocks"},{"s":"I-0015.B1","t":"T.performance-compatibility","k":"theme"},{"s":"I-0015.B2","t":"I-0015","k":"blocks"},{"s":"I-0015.B2","t":"T.privacy-leakage","k":"theme"},{"s":"I-0003","t":"C-0005","k":"verifies","role":"p","note":"Proves an output follows from committed weights and a public architecture."},{"s":"I-0003","t":"M-0004","k":"realises"},{"s":"O-0122","t":"I-0003","k":"develops"},{"s":"I-0003","t":"K-0010","k":"uses_concept"},{"s":"I-0003","t":"K-0024","k":"uses_concept"},{"s":"I-0003","t":"K-0001","k":"uses_concept"},{"s":"I-0003","t":"K-0002","k":"uses_concept"},{"s":"I-0003","t":"T.performance-compatibility","k":"faces"},{"s":"I-0003","t":"T.adversarial-validation","k":"faces"},{"s":"I-0003","t":"T.privacy-leakage","k":"faces"},{"s":"I-0003","t":"G.cryptographic-computational","k":"in_category"},{"s":"I-0003.B1","t":"I-0003","k":"blocks"},{"s":"I-0003.B1","t":"T.performance-compatibility","k":"theme"},{"s":"I-0003.B2","t":"I-0003","k":"blocks"},{"s":"I-0003.B2","t":"T.performance-compatibility","k":"theme"},{"s":"I-0003.B3","t":"I-0003","k":"blocks"},{"s":"I-0003.B3","t":"T.adversarial-validation","k":"theme"},{"s":"I-0003.F1","t":"I-0003","k":"weakens"},{"s":"I-0003.F2","t":"I-0003","k":"weakens"},{"s":"C-0001","t":"K-0016","k":"uses_concept"},{"s":"C-0001","t":"K-0023","k":"uses_concept"},{"s":"C-0001","t":"K-0003","k":"uses_concept"},{"s":"C-0001","t":"K-0020","k":"uses_concept"},{"s":"C-0002","t":"K-0004","k":"uses_concept"},{"s":"C-0002","t":"K-0019","k":"uses_concept"},{"s":"C-0002","t":"K-0005","k":"uses_concept"},{"s":"C-0002","t":"K-0015","k":"uses_concept"},{"s":"C-0003","t":"K-0003","k":"uses_concept"},{"s":"C-0003","t":"K-0007","k":"uses_concept"},{"s":"C-0003","t":"K-0013","k":"uses_concept"},{"s":"C-0003","t":"K-0025","k":"uses_concept"},{"s":"C-0004","t":"K-0025","k":"uses_concept"},{"s":"C-0004","t":"K-0009","k":"uses_concept"},{"s":"C-0004","t":"K-0008","k":"uses_concept"},{"s":"C-0004","t":"K-0014","k":"uses_concept"},{"s":"C-0004","t":"K-0021","k":"uses_concept"},{"s":"C-0004","t":"K-0017","k":"uses_concept"},{"s":"C-0004","t":"K-0013","k":"uses_concept"},{"s":"C-0005","t":"K-0009","k":"uses_concept"},{"s":"C-0005","t":"K-0008","k":"uses_concept"},{"s":"C-0005","t":"K-0004","k":"uses_concept"},{"s":"C-0005","t":"K-0006","k":"uses_concept"},{"s":"C-0005","t":"K-0010","k":"uses_concept"},{"s":"C-0005","t":"K-0019","k":"uses_concept"},{"s":"C-0006","t":"K-0006","k":"uses_concept"},{"s":"C-0006","t":"K-0004","k":"uses_concept"},{"s":"C-0006","t":"K-0019","k":"uses_concept"},{"s":"C-0006","t":"K-0005","k":"uses_concept"},{"s":"C-0007","t":"K-0023","k":"uses_concept"},{"s":"C-0007","t":"K-0009","k":"uses_concept"},{"s":"C-0007","t":"K-0020","k":"uses_concept"},{"s":"C-0007","t":"K-0010","k":"uses_concept"},{"s":"C-0007","t":"K-0024","k":"uses_concept"},{"s":"C-0007","t":"K-0008","k":"uses_concept"},{"s":"C-0008","t":"K-0021","k":"uses_concept"},{"s":"C-0008","t":"K-0017","k":"uses_concept"},{"s":"C-0008","t":"K-0014","k":"uses_concept"},{"s":"C-0008","t":"K-0013","k":"uses_concept"},{"s":"C-0009","t":"K-0022","k":"uses_concept"},{"s":"C-0009","t":"K-0013","k":"uses_concept"},{"s":"C-0009","t":"K-0021","k":"uses_concept"},{"s":"C-0009","t":"K-0014","k":"uses_concept"},{"s":"C-0009","t":"K-0012","k":"uses_concept"},{"s":"C-0010","t":"K-0016","k":"uses_concept"},{"s":"C-0010","t":"K-0003","k":"uses_concept"},{"s":"C-0010","t":"K-0020","k":"uses_concept"},{"s":"C-0010","t":"K-0023","k":"uses_concept"},{"s":"K-0017","t":"K-0021","k":"related"},{"s":"K-0017","t":"K-0025","k":"related"},{"s":"K-0017","t":"K-0013","k":"related"},{"s":"K-0024","t":"K-0010","k":"related"},{"s":"K-0024","t":"K-0019","k":"related"},{"s":"K-0024","t":"K-0014","k":"related"},{"s":"K-0024","t":"K-0020","k":"related"},{"s":"K-0019","t":"K-0004","k":"related"},{"s":"K-0019","t":"K-0005","k":"related"},{"s":"K-0023","t":"K-0025","k":"related"},{"s":"K-0023","t":"K-0016","k":"related"},{"s":"K-0007","t":"K-0005","k":"related"},{"s":"K-0007","t":"K-0004","k":"related"},{"s":"K-0007","t":"K-0015","k":"related"},{"s":"K-0007","t":"K-0017","k":"related"},{"s":"K-0025","t":"K-0021","k":"related"},{"s":"K-0021","t":"K-0014","k":"related"},{"s":"K-0014","t":"K-0019","k":"related"},{"s":"K-0008","t":"K-0009","k":"related"},{"s":"K-0003","t":"K-0016","k":"related"},{"s":"K-0003","t":"K-0020","k":"related"},{"s":"K-0003","t":"C-0005","k":"related"},{"s":"K-0003","t":"C-0004","k":"related"},{"s":"K-0011","t":"K-0012","k":"related"},{"s":"K-0011","t":"K-0016","k":"related"},{"s":"K-0012","t":"K-0024","k":"related"},{"s":"K-0012","t":"K-0016","k":"related"},{"s":"K-0001","t":"K-0002","k":"related"},{"s":"K-0001","t":"K-0004","k":"related"},{"s":"K-0001","t":"K-0018","k":"related"},{"s":"K-0001","t":"K-0003","k":"related"},{"s":"K-0009","t":"K-0020","k":"related"},{"s":"K-0009","t":"K-0024","k":"related"},{"s":"K-0004","t":"K-0005","k":"related"},{"s":"K-0004","t":"K-0006","k":"related"},{"s":"K-0005","t":"K-0006","k":"related"},{"s":"K-0005","t":"K-0015","k":"related"},{"s":"K-0020","t":"K-0018","k":"related"},{"s":"K-0013","t":"K-0015","k":"related"},{"s":"K-0013","t":"K-0022","k":"related"},{"s":"K-0013","t":"K-0006","k":"related"},{"s":"K-0018","t":"K-0002","k":"related"},{"s":"K-0018","t":"K-0005","k":"related"},{"s":"K-0016","t":"K-0020","k":"related"},{"s":"K-0002","t":"K-0004","k":"related"},{"s":"K-0002","t":"K-0020","k":"related"},{"s":"K-0022","t":"K-0014","k":"related"},{"s":"K-0022","t":"K-0021","k":"related"},{"s":"K-0010","t":"K-0001","k":"related"},{"s":"K-0010","t":"K-0002","k":"related"},{"s":"M-0014","t":"S-0067","k":"cites"},{"s":"M-0014","t":"S-1301","k":"cites"},{"s":"M-0014","t":"S-1508","k":"cites"},{"s":"M-0014","t":"S-0018","k":"cites"},{"s":"M-0014","t":"S-1313","k":"cites"},{"s":"M-0014","t":"S-1314","k":"cites"},{"s":"M-0014","t":"S-0060","k":"cites"},{"s":"M-0024","t":"S-0019","k":"cites"},{"s":"M-0024","t":"S-0015","k":"cites"},{"s":"M-0024","t":"S-1507","k":"cites"},{"s":"M-0024","t":"S-1508","k":"cites"},{"s":"M-0024","t":"S-1509","k":"cites"},{"s":"M-0024","t":"S-0018","k":"cites"},{"s":"M-0018","t":"S-1400","k":"cites"},{"s":"M-0018","t":"S-1401","k":"cites"},{"s":"M-0018","t":"S-1402","k":"cites"},{"s":"M-0018","t":"S-1413","k":"cites"},{"s":"M-0018","t":"S-0056","k":"cites"},{"s":"M-0018","t":"S-0007","k":"cites"},{"s":"M-0018","t":"S-1403","k":"cites"},{"s":"M-0018","t":"S-1404","k":"cites"},{"s":"M-0019","t":"S-0002","k":"cites"},{"s":"M-0019","t":"S-1402","k":"cites"},{"s":"M-0019","t":"S-1408","k":"cites"},{"s":"M-0019","t":"S-0056","k":"cites"},{"s":"M-0019","t":"S-0007","k":"cites"},{"s":"M-0019","t":"S-1410","k":"cites"},{"s":"M-0019","t":"S-1400","k":"cites"},{"s":"M-0025","t":"S-0011","k":"cites"},{"s":"M-0025","t":"S-1505","k":"cites"},{"s":"M-0025","t":"S-0022","k":"cites"},{"s":"M-0025","t":"S-0009","k":"cites"},{"s":"M-0025","t":"S-1503","k":"cites"},{"s":"M-0025","t":"S-1504","k":"cites"},{"s":"M-0025","t":"S-1506","k":"cites"},{"s":"M-0025","t":"S-0014","k":"cites"},{"s":"M-0025","t":"S-1202","k":"cites"},{"s":"M-0025","t":"S-1210","k":"cites"},{"s":"M-0025","t":"S-1212","k":"cites"},{"s":"M-0025","t":"S-1213","k":"cites"},{"s":"M-0002","t":"S-0020","k":"cites"},{"s":"M-0002","t":"S-0015","k":"cites"},{"s":"M-0002","t":"S-0018","k":"cites"},{"s":"M-0002","t":"S-0016","k":"cites"},{"s":"M-0002","t":"S-0017","k":"cites"},{"s":"M-0002","t":"S-0067","k":"cites"},{"s":"M-0002","t":"S-1008","k":"cites"},{"s":"M-0002","t":"S-1009","k":"cites"},{"s":"M-0002","t":"S-1010","k":"cites"},{"s":"M-0002","t":"S-1011","k":"cites"},{"s":"M-0002","t":"S-1012","k":"cites"},{"s":"M-0002","t":"S-1013","k":"cites"},{"s":"M-0002","t":"S-1014","k":"cites"},{"s":"M-0002","t":"S-1813","k":"cites"},{"s":"M-0002","t":"S-1814","k":"cites"},{"s":"M-0002","t":"S-1809","k":"cites"},{"s":"M-0002","t":"S-1810","k":"cites"},{"s":"M-0009","t":"S-0035","k":"cites"},{"s":"M-0009","t":"S-1204","k":"cites"},{"s":"M-0009","t":"S-1611","k":"cites"},{"s":"M-0009","t":"S-1205","k":"cites"},{"s":"M-0009","t":"S-0057","k":"cites"},{"s":"M-0009","t":"S-0056","k":"cites"},{"s":"M-0009","t":"S-0006","k":"cites"},{"s":"M-0011","t":"S-0036","k":"cites"},{"s":"M-0011","t":"S-0057","k":"cites"},{"s":"M-0011","t":"S-0006","k":"cites"},{"s":"M-0011","t":"S-0056","k":"cites"},{"s":"M-0011","t":"S-0035","k":"cites"},{"s":"M-0011","t":"S-1204","k":"cites"},{"s":"M-0015","t":"S-0067","k":"cites"},{"s":"M-0015","t":"S-1304","k":"cites"},{"s":"M-0015","t":"S-0032","k":"cites"},{"s":"M-0015","t":"S-0018","k":"cites"},{"s":"M-0015","t":"S-1302","k":"cites"},{"s":"M-0015","t":"S-1303","k":"cites"},{"s":"M-0015","t":"S-1321","k":"cites"},{"s":"M-0012","t":"S-0013","k":"cites"},{"s":"M-0012","t":"S-0012","k":"cites"},{"s":"M-0012","t":"S-0009","k":"cites"},{"s":"M-0012","t":"S-0015","k":"cites"},{"s":"M-0012","t":"S-1507","k":"cites"},{"s":"M-0012","t":"S-0014","k":"cites"},{"s":"M-0012","t":"S-1202","k":"cites"},{"s":"M-0012","t":"S-1210","k":"cites"},{"s":"M-0012","t":"S-1212","k":"cites"},{"s":"M-0012","t":"S-1213","k":"cites"},{"s":"M-0012","t":"S-1206","k":"cites"},{"s":"M-0012","t":"S-1207","k":"cites"},{"s":"M-0012","t":"S-1208","k":"cites"},{"s":"M-0012","t":"S-1209","k":"cites"},{"s":"M-0012","t":"S-1800","k":"cites"},{"s":"M-0012","t":"S-1810","k":"cites"},{"s":"M-0013","t":"S-1300","k":"cites"},{"s":"M-0013","t":"S-0031","k":"cites"},{"s":"M-0013","t":"S-0018","k":"cites"},{"s":"M-0013","t":"S-0067","k":"cites"},{"s":"M-0013","t":"S-1309","k":"cites"},{"s":"M-0013","t":"S-1310","k":"cites"},{"s":"M-0013","t":"S-1311","k":"cites"},{"s":"M-0013","t":"S-1312","k":"cites"},{"s":"M-0013","t":"S-1319","k":"cites"},{"s":"M-0013","t":"S-1320","k":"cites"},{"s":"M-0013","t":"S-1507","k":"cites"},{"s":"M-0010","t":"S-0033","k":"cites"},{"s":"M-0010","t":"S-0034","k":"cites"},{"s":"M-0010","t":"S-0037","k":"cites"},{"s":"M-0010","t":"S-0057","k":"cites"},{"s":"M-0010","t":"S-0006","k":"cites"},{"s":"M-0010","t":"S-0014","k":"cites"},{"s":"M-0010","t":"S-1200","k":"cites"},{"s":"M-0010","t":"S-0073","k":"cites"},{"s":"M-0006","t":"S-0028","k":"cites"},{"s":"M-0006","t":"S-1111","k":"cites"},{"s":"M-0006","t":"S-1109","k":"cites"},{"s":"M-0006","t":"S-0027","k":"cites"},{"s":"M-0006","t":"S-0029","k":"cites"},{"s":"M-0006","t":"S-0030","k":"cites"},{"s":"M-0006","t":"S-0022","k":"cites"},{"s":"M-0007","t":"S-1609","k":"cites"},{"s":"M-0007","t":"S-1105","k":"cites"},{"s":"M-0007","t":"S-1106","k":"cites"},{"s":"M-0007","t":"S-1107","k":"cites"},{"s":"M-0007","t":"S-0071","k":"cites"},{"s":"M-0007","t":"S-1102","k":"cites"},{"s":"M-0007","t":"S-1608","k":"cites"},{"s":"M-0007","t":"S-0005","k":"cites"},{"s":"M-0007","t":"S-0018","k":"cites"},{"s":"M-0007","t":"S-1607","k":"cites"},{"s":"M-0020","t":"S-1409","k":"cites"},{"s":"M-0020","t":"S-1411","k":"cites"},{"s":"M-0020","t":"S-1410","k":"cites"},{"s":"M-0020","t":"S-0002","k":"cites"},{"s":"M-0020","t":"S-0007","k":"cites"},{"s":"M-0003","t":"S-0067","k":"cites"},{"s":"M-0003","t":"S-0017","k":"cites"},{"s":"M-0003","t":"S-1006","k":"cites"},{"s":"M-0003","t":"S-1008","k":"cites"},{"s":"M-0023","t":"S-1500","k":"cites"},{"s":"M-0023","t":"S-1501","k":"cites"},{"s":"M-0023","t":"S-0012","k":"cites"},{"s":"M-0023","t":"S-0009","k":"cites"},{"s":"M-0023","t":"S-1503","k":"cites"},{"s":"M-0023","t":"S-1504","k":"cites"},{"s":"M-0023","t":"S-0014","k":"cites"},{"s":"M-0023","t":"S-0003","k":"cites"},{"s":"M-0023","t":"S-0018","k":"cites"},{"s":"M-0023","t":"S-1502","k":"cites"},{"s":"M-0023","t":"S-1202","k":"cites"},{"s":"M-0023","t":"S-1210","k":"cites"},{"s":"M-0023","t":"S-1212","k":"cites"},{"s":"M-0023","t":"S-1213","k":"cites"},{"s":"M-0023","t":"S-0013","k":"cites"},{"s":"M-0001","t":"S-0015","k":"cites"},{"s":"M-0001","t":"S-0016","k":"cites"},{"s":"M-0001","t":"S-0017","k":"cites"},{"s":"M-0001","t":"S-0018","k":"cites"},{"s":"M-0001","t":"S-0020","k":"cites"},{"s":"M-0001","t":"S-0067","k":"cites"},{"s":"M-0001","t":"S-1000","k":"cites"},{"s":"M-0001","t":"S-1001","k":"cites"},{"s":"M-0001","t":"S-1003","k":"cites"},{"s":"M-0001","t":"S-1005","k":"cites"},{"s":"M-0001","t":"S-1006","k":"cites"},{"s":"M-0001","t":"S-1007","k":"cites"},{"s":"M-0001","t":"S-1008","k":"cites"},{"s":"M-0001","t":"S-1507","k":"cites"},{"s":"M-0022","t":"S-0038","k":"cites"},{"s":"M-0022","t":"S-0018","k":"cites"},{"s":"M-0022","t":"S-0043","k":"cites"},{"s":"M-0022","t":"S-0044","k":"cites"},{"s":"M-0022","t":"S-0046","k":"cites"},{"s":"M-0022","t":"S-0007","k":"cites"},{"s":"M-0017","t":"S-0050","k":"cites"},{"s":"M-0017","t":"S-0049","k":"cites"},{"s":"M-0017","t":"S-1315","k":"cites"},{"s":"M-0017","t":"S-0052","k":"cites"},{"s":"M-0017","t":"S-0051","k":"cites"},{"s":"M-0017","t":"S-1316","k":"cites"},{"s":"M-0017","t":"S-1317","k":"cites"},{"s":"M-0017","t":"S-1318","k":"cites"},{"s":"M-0017","t":"S-0018","k":"cites"},{"s":"M-0017","t":"S-0067","k":"cites"},{"s":"M-0017","t":"S-0035","k":"cites"},{"s":"M-0008","t":"S-1200","k":"cites"},{"s":"M-0008","t":"S-1201","k":"cites"},{"s":"M-0008","t":"S-1202","k":"cites"},{"s":"M-0008","t":"S-1210","k":"cites"},{"s":"M-0008","t":"S-1211","k":"cites"},{"s":"M-0008","t":"S-1212","k":"cites"},{"s":"M-0008","t":"S-1213","k":"cites"},{"s":"M-0008","t":"S-0009","k":"cites"},{"s":"M-0008","t":"S-0012","k":"cites"},{"s":"M-0008","t":"S-0013","k":"cites"},{"s":"M-0008","t":"S-0014","k":"cites"},{"s":"M-0008","t":"S-0010","k":"cites"},{"s":"M-0008","t":"S-0006","k":"cites"},{"s":"M-0008","t":"S-0056","k":"cites"},{"s":"M-0008","t":"S-0057","k":"cites"},{"s":"M-0008","t":"S-1203","k":"cites"},{"s":"M-0008","t":"S-1204","k":"cites"},{"s":"M-0008","t":"S-1206","k":"cites"},{"s":"M-0008","t":"S-1207","k":"cites"},{"s":"M-0008","t":"S-1208","k":"cites"},{"s":"M-0008","t":"S-1209","k":"cites"},{"s":"M-0008","t":"S-1815","k":"cites"},{"s":"M-0008","t":"S-1816","k":"cites"},{"s":"M-0008","t":"S-1800","k":"cites"},{"s":"M-0008","t":"S-1802","k":"cites"},{"s":"M-0008","t":"S-1804","k":"cites"},{"s":"M-0008","t":"S-1817","k":"cites"},{"s":"M-0016","t":"S-0018","k":"cites"},{"s":"M-0016","t":"S-0067","k":"cites"},{"s":"M-0016","t":"S-0033","k":"cites"},{"s":"M-0016","t":"S-1306","k":"cites"},{"s":"M-0016","t":"S-1307","k":"cites"},{"s":"M-0016","t":"S-1308","k":"cites"},{"s":"M-0016","t":"S-1607","k":"cites"},{"s":"M-0016","t":"S-0032","k":"cites"},{"s":"M-0016","t":"S-1302","k":"cites"},{"s":"M-0016","t":"S-1304","k":"cites"},{"s":"M-0021","t":"S-0037","k":"cites"},{"s":"M-0021","t":"S-1412","k":"cites"},{"s":"M-0021","t":"S-0007","k":"cites"},{"s":"M-0021","t":"S-0048","k":"cites"},{"s":"M-0021","t":"S-0041","k":"cites"},{"s":"M-0021","t":"S-0042","k":"cites"},{"s":"M-0021","t":"S-0040","k":"cites"},{"s":"M-0021","t":"S-0039","k":"cites"},{"s":"M-0021","t":"S-0046","k":"cites"},{"s":"M-0021","t":"S-0073","k":"cites"},{"s":"M-0004","t":"S-0023","k":"cites"},{"s":"M-0004","t":"S-1108","k":"cites"},{"s":"M-0004","t":"S-0021","k":"cites"},{"s":"M-0004","t":"S-0068","k":"cites"},{"s":"M-0004","t":"S-0024","k":"cites"},{"s":"M-0004","t":"S-0070","k":"cites"},{"s":"M-0004","t":"S-1100","k":"cites"},{"s":"M-0004","t":"S-1101","k":"cites"},{"s":"M-0004","t":"S-1102","k":"cites"},{"s":"M-0004","t":"S-1103","k":"cites"},{"s":"M-0004","t":"S-0018","k":"cites"},{"s":"M-0004","t":"S-1112","k":"cites"},{"s":"M-0004","t":"S-1807","k":"cites"},{"s":"M-0004","t":"S-1808","k":"cites"},{"s":"M-0005","t":"S-1110","k":"cites"},{"s":"M-0005","t":"S-0022","k":"cites"},{"s":"M-0005","t":"S-0025","k":"cites"},{"s":"M-0005","t":"S-1100","k":"cites"},{"s":"M-0005","t":"S-0023","k":"cites"},{"s":"I-0011","t":"S-0067","k":"cites"},{"s":"I-0011","t":"S-1511","k":"cites"},{"s":"I-0011","t":"S-1512","k":"cites"},{"s":"I-0011","t":"S-1008","k":"cites"},{"s":"I-0011","t":"S-0015","k":"cites"},{"s":"I-0011","t":"S-1507","k":"cites"},{"s":"I-0013","t":"S-1800","k":"cites"},{"s":"I-0013","t":"S-1801","k":"cites"},{"s":"I-0013","t":"S-1802","k":"cites"},{"s":"I-0013","t":"S-1803","k":"cites"},{"s":"I-0013","t":"S-1804","k":"cites"},{"s":"I-0013","t":"S-1805","k":"cites"},{"s":"I-0013","t":"S-1202","k":"cites"},{"s":"I-0007","t":"S-0009","k":"cites"},{"s":"I-0007","t":"S-1200","k":"cites"},{"s":"I-0005","t":"S-1101","k":"cites"},{"s":"I-0005","t":"S-1102","k":"cites"},{"s":"I-0005","t":"S-1103","k":"cites"},{"s":"I-0016","t":"S-1009","k":"cites"},{"s":"I-0016","t":"S-1813","k":"cites"},{"s":"I-0016","t":"S-1012","k":"cites"},{"s":"I-0016","t":"S-1013","k":"cites"},{"s":"I-0016","t":"S-1814","k":"cites"},{"s":"I-0016","t":"S-0016","k":"cites"},{"s":"I-0002","t":"S-0016","k":"cites"},{"s":"I-0002","t":"S-0015","k":"cites"},{"s":"I-0002","t":"S-1005","k":"cites"},{"s":"I-0002","t":"S-1006","k":"cites"},{"s":"I-0002","t":"S-1007","k":"cites"},{"s":"I-0002","t":"S-0020","k":"cites"},{"s":"I-0002","t":"S-1008","k":"cites"},{"s":"I-0002","t":"S-1507","k":"cites"},{"s":"I-0014","t":"S-1806","k":"cites"},{"s":"I-0014","t":"S-0024","k":"cites"},{"s":"I-0014","t":"S-0070","k":"cites"},{"s":"I-0015","t":"S-1809","k":"cites"},{"s":"I-0015","t":"S-1810","k":"cites"},{"s":"I-0015","t":"S-1811","k":"cites"},{"s":"I-0015","t":"S-1812","k":"cites"},{"s":"I-0015","t":"S-1003","k":"cites"},{"s":"I-0012","t":"S-0018","k":"cites"},{"s":"I-0012","t":"S-1300","k":"cites"},{"s":"I-0009","t":"S-1404","k":"cites"},{"s":"I-0009","t":"S-1405","k":"cites"},{"s":"I-0009","t":"S-1406","k":"cites"},{"s":"I-0009","t":"S-1407","k":"cites"},{"s":"I-0009","t":"S-1403","k":"cites"},{"s":"I-0009","t":"S-1400","k":"cites"},{"s":"I-0004","t":"S-1105","k":"cites"},{"s":"I-0004","t":"S-1106","k":"cites"},{"s":"I-0004","t":"S-1107","k":"cites"},{"s":"I-0004","t":"S-1609","k":"cites"},{"s":"I-0004","t":"S-0071","k":"cites"},{"s":"I-0004","t":"S-1102","k":"cites"},{"s":"I-0010","t":"S-1510","k":"cites"},{"s":"I-0010","t":"S-1706","k":"cites"},{"s":"I-0010","t":"S-1707","k":"cites"},{"s":"I-0008","t":"S-1320","k":"cites"},{"s":"I-0008","t":"S-1319","k":"cites"},{"s":"I-0006","t":"S-0013","k":"cites"},{"s":"I-0006","t":"S-1206","k":"cites"},{"s":"I-0006","t":"S-1207","k":"cites"},{"s":"I-0006","t":"S-1208","k":"cites"},{"s":"I-0006","t":"S-1209","k":"cites"},{"s":"I-0006","t":"S-1202","k":"cites"},{"s":"I-0006","t":"S-1210","k":"cites"},{"s":"I-0006","t":"S-1212","k":"cites"},{"s":"I-0006","t":"S-1213","k":"cites"},{"s":"I-0001","t":"S-1000","k":"cites"},{"s":"I-0001","t":"S-1001","k":"cites"},{"s":"I-0001","t":"S-1002","k":"cites"},{"s":"I-0001","t":"S-1003","k":"cites"},{"s":"I-0001","t":"S-1004","k":"cites"},{"s":"I-0001","t":"S-0016","k":"cites"},{"s":"I-0001","t":"S-0017","k":"cites"},{"s":"I-0001","t":"S-0020","k":"cites"},{"s":"I-0001","t":"S-1008","k":"cites"},{"s":"I-0003","t":"S-0023","k":"cites"},{"s":"I-0003","t":"S-1108","k":"cites"},{"s":"I-0003","t":"S-0018","k":"cites"},{"s":"I-0003","t":"S-1112","k":"cites"},{"s":"C-0008","t":"S-0005","k":"cites"},{"s":"C-0008","t":"S-0053","k":"cites"},{"s":"C-0008","t":"S-1314","k":"cites"},{"s":"C-0008","t":"S-0057","k":"cites"},{"s":"C-0008","t":"S-0018","k":"cites"},{"s":"C-0008","t":"S-0031","k":"cites"},{"s":"C-0008","t":"S-0038","k":"cites"},{"s":"C-0008","t":"S-0029","k":"cites"},{"s":"C-0008","t":"S-0002","k":"cites"},{"s":"C-0008","t":"S-0067","k":"cites"},{"s":"C-0008","t":"S-1301","k":"cites"},{"s":"C-0008","t":"S-1313","k":"cites"},{"s":"C-0008","t":"S-1508","k":"cites"},{"s":"C-0002","t":"S-0001","k":"cites"},{"s":"C-0002","t":"S-0005","k":"cites"},{"s":"C-0002","t":"S-0062","k":"cites"},{"s":"C-0002","t":"S-0063","k":"cites"},{"s":"C-0002","t":"S-0029","k":"cites"},{"s":"C-0002","t":"S-1400","k":"cites"},{"s":"C-0002","t":"S-1401","k":"cites"},{"s":"C-0002","t":"S-1402","k":"cites"},{"s":"C-0002","t":"S-1413","k":"cites"},{"s":"C-0002","t":"S-1404","k":"cites"},{"s":"C-0002","t":"S-0035","k":"cites"},{"s":"C-0001","t":"S-0029","k":"cites"},{"s":"C-0001","t":"S-0053","k":"cites"},{"s":"C-0001","t":"S-0063","k":"cites"},{"s":"C-0001","t":"S-0005","k":"cites"},{"s":"C-0001","t":"S-0062","k":"cites"},{"s":"C-0001","t":"S-0002","k":"cites"},{"s":"C-0001","t":"S-1411","k":"cites"},{"s":"C-0001","t":"S-0057","k":"cites"},{"s":"C-0003","t":"S-0005","k":"cites"},{"s":"C-0003","t":"S-0062","k":"cites"},{"s":"C-0003","t":"S-0067","k":"cites"},{"s":"C-0003","t":"S-0002","k":"cites"},{"s":"C-0003","t":"S-0057","k":"cites"},{"s":"C-0003","t":"S-0037","k":"cites"},{"s":"C-0003","t":"S-0033","k":"cites"},{"s":"C-0003","t":"S-1102","k":"cites"},{"s":"C-0005","t":"S-0002","k":"cites"},{"s":"C-0005","t":"S-0016","k":"cites"},{"s":"C-0005","t":"S-1009","k":"cites"},{"s":"C-0005","t":"S-0020","k":"cites"},{"s":"C-0005","t":"S-0004","k":"cites"},{"s":"C-0005","t":"S-0018","k":"cites"},{"s":"C-0005","t":"S-0023","k":"cites"},{"s":"C-0005","t":"S-0012","k":"cites"},{"s":"C-0005","t":"S-0014","k":"cites"},{"s":"C-0005","t":"S-0009","k":"cites"},{"s":"C-0005","t":"S-1202","k":"cites"},{"s":"C-0005","t":"S-1210","k":"cites"},{"s":"C-0005","t":"S-1212","k":"cites"},{"s":"C-0004","t":"S-0063","k":"cites"},{"s":"C-0004","t":"S-0067","k":"cites"},{"s":"C-0004","t":"S-0053","k":"cites"},{"s":"C-0004","t":"S-0002","k":"cites"},{"s":"C-0004","t":"S-0018","k":"cites"},{"s":"C-0004","t":"S-0005","k":"cites"},{"s":"C-0004","t":"S-0029","k":"cites"},{"s":"C-0004","t":"S-0037","k":"cites"},{"s":"C-0004","t":"S-0001","k":"cites"},{"s":"C-0004","t":"S-0031","k":"cites"},{"s":"C-0004","t":"S-0016","k":"cites"},{"s":"C-0004","t":"S-0020","k":"cites"},{"s":"C-0004","t":"S-1512","k":"cites"},{"s":"C-0004","t":"S-0033","k":"cites"},{"s":"C-0010","t":"S-0002","k":"cites"},{"s":"C-0010","t":"S-0004","k":"cites"},{"s":"C-0010","t":"S-0029","k":"cites"},{"s":"C-0010","t":"S-0005","k":"cites"},{"s":"C-0010","t":"S-0062","k":"cites"},{"s":"C-0010","t":"S-0063","k":"cites"},{"s":"C-0010","t":"S-0053","k":"cites"},{"s":"C-0010","t":"S-0014","k":"cites"},{"s":"C-0010","t":"S-1409","k":"cites"},{"s":"C-0010","t":"S-1102","k":"cites"},{"s":"C-0006","t":"S-0002","k":"cites"},{"s":"C-0006","t":"S-0062","k":"cites"},{"s":"C-0006","t":"S-0003","k":"cites"},{"s":"C-0006","t":"S-0014","k":"cites"},{"s":"C-0006","t":"S-0009","k":"cites"},{"s":"C-0006","t":"S-0012","k":"cites"},{"s":"C-0006","t":"S-0018","k":"cites"},{"s":"C-0006","t":"S-1500","k":"cites"},{"s":"C-0006","t":"S-1503","k":"cites"},{"s":"C-0006","t":"S-1504","k":"cites"},{"s":"C-0007","t":"S-0029","k":"cites"},{"s":"C-0007","t":"S-0053","k":"cites"},{"s":"C-0007","t":"S-0069","k":"cites"},{"s":"C-0007","t":"S-0063","k":"cites"},{"s":"C-0007","t":"S-0062","k":"cites"},{"s":"C-0007","t":"S-0002","k":"cites"},{"s":"C-0007","t":"S-0025","k":"cites"},{"s":"C-0007","t":"S-0027","k":"cites"},{"s":"C-0007","t":"S-0018","k":"cites"},{"s":"C-0007","t":"S-0035","k":"cites"},{"s":"C-0007","t":"S-0057","k":"cites"},{"s":"C-0007","t":"S-0030","k":"cites"},{"s":"C-0007","t":"S-1110","k":"cites"},{"s":"C-0009","t":"S-1610","k":"cites"},{"s":"C-0009","t":"S-0015","k":"cites"},{"s":"C-0009","t":"S-1507","k":"cites"},{"s":"C-0009","t":"S-0005","k":"cites"},{"s":"C-0009","t":"S-0018","k":"cites"},{"s":"C-0009","t":"S-0038","k":"cites"},{"s":"C-0009","t":"S-0002","k":"cites"},{"s":"C-0009","t":"S-0031","k":"cites"},{"s":"C-0009","t":"S-1508","k":"cites"},{"s":"C-0009","t":"S-0020","k":"cites"},{"s":"C-0009","t":"S-1510","k":"cites"},{"s":"K-0017","t":"S-0005","k":"cites"},{"s":"K-0017","t":"S-0057","k":"cites"},{"s":"K-0017","t":"S-0053","k":"cites"},{"s":"K-0017","t":"S-0018","k":"cites"},{"s":"K-0017","t":"S-0002","k":"cites"},{"s":"K-0017","t":"S-0038","k":"cites"},{"s":"K-0024","t":"S-1606","k":"cites"},{"s":"K-0024","t":"S-1607","k":"cites"},{"s":"K-0024","t":"S-1600","k":"cites"},{"s":"K-0024","t":"S-0004","k":"cites"},{"s":"K-0024","t":"S-0018","k":"cites"},{"s":"K-0024","t":"S-0023","k":"cites"},{"s":"K-0024","t":"S-0025","k":"cites"},{"s":"K-0024","t":"S-0017","k":"cites"},{"s":"K-0019","t":"S-1603","k":"cites"},{"s":"K-0019","t":"S-0018","k":"cites"},{"s":"K-0019","t":"S-0005","k":"cites"},{"s":"K-0019","t":"S-0031","k":"cites"},{"s":"K-0019","t":"S-0029","k":"cites"},{"s":"K-0019","t":"S-0012","k":"cites"},{"s":"K-0019","t":"S-0017","k":"cites"},{"s":"K-0023","t":"S-0029","k":"cites"},{"s":"K-0023","t":"S-0053","k":"cites"},{"s":"K-0023","t":"S-0063","k":"cites"},{"s":"K-0023","t":"S-0062","k":"cites"},{"s":"K-0023","t":"S-0002","k":"cites"},{"s":"K-0023","t":"S-0057","k":"cites"},{"s":"K-0023","t":"S-0018","k":"cites"},{"s":"K-0023","t":"S-0069","k":"cites"},{"s":"K-0007","t":"S-0057","k":"cites"},{"s":"K-0007","t":"S-0006","k":"cites"},{"s":"K-0007","t":"S-0056","k":"cites"},{"s":"K-0007","t":"S-0035","k":"cites"},{"s":"K-0025","t":"S-0029","k":"cites"},{"s":"K-0025","t":"S-0018","k":"cites"},{"s":"K-0025","t":"S-0002","k":"cites"},{"s":"K-0025","t":"S-0053","k":"cites"},{"s":"K-0025","t":"S-0005","k":"cites"},{"s":"K-0025","t":"S-0037","k":"cites"},{"s":"K-0021","t":"S-0053","k":"cites"},{"s":"K-0021","t":"S-0005","k":"cites"},{"s":"K-0021","t":"S-0018","k":"cites"},{"s":"K-0014","t":"S-0031","k":"cites"},{"s":"K-0014","t":"S-0002","k":"cites"},{"s":"K-0014","t":"S-0018","k":"cites"},{"s":"K-0008","t":"S-1010","k":"cites"},{"s":"K-0008","t":"S-0016","k":"cites"},{"s":"K-0008","t":"S-1009","k":"cites"},{"s":"K-0008","t":"S-0018","k":"cites"},{"s":"K-0008","t":"S-0029","k":"cites"},{"s":"K-0008","t":"S-0020","k":"cites"},{"s":"K-0003","t":"S-0004","k":"cites"},{"s":"K-0003","t":"S-0002","k":"cites"},{"s":"K-0003","t":"S-0018","k":"cites"},{"s":"K-0003","t":"S-0005","k":"cites"},{"s":"K-0003","t":"S-0029","k":"cites"},{"s":"K-0012","t":"S-1607","k":"cites"},{"s":"K-0012","t":"S-0032","k":"cites"},{"s":"K-0012","t":"S-0018","k":"cites"},{"s":"K-0011","t":"S-1607","k":"cites"},{"s":"K-0011","t":"S-0005","k":"cites"},{"s":"K-0011","t":"S-1608","k":"cites"},{"s":"K-0011","t":"S-1609","k":"cites"},{"s":"K-0011","t":"S-1105","k":"cites"},{"s":"K-0011","t":"S-1102","k":"cites"},{"s":"K-0001","t":"S-1606","k":"cites"},{"s":"K-0001","t":"S-0004","k":"cites"},{"s":"K-0001","t":"S-0029","k":"cites"},{"s":"K-0001","t":"S-0002","k":"cites"},{"s":"K-0001","t":"S-1603","k":"cites"},{"s":"K-0001","t":"S-0023","k":"cites"},{"s":"K-0009","t":"S-0029","k":"cites"},{"s":"K-0009","t":"S-0016","k":"cites"},{"s":"K-0009","t":"S-0015","k":"cites"},{"s":"K-0009","t":"S-0017","k":"cites"},{"s":"K-0009","t":"S-0018","k":"cites"},{"s":"K-0004","t":"S-1603","k":"cites"},{"s":"K-0004","t":"S-1600","k":"cites"},{"s":"K-0004","t":"S-1602","k":"cites"},{"s":"K-0004","t":"S-1604","k":"cites"},{"s":"K-0004","t":"S-0005","k":"cites"},{"s":"K-0005","t":"S-1601","k":"cites"},{"s":"K-0005","t":"S-1600","k":"cites"},{"s":"K-0005","t":"S-1602","k":"cites"},{"s":"K-0005","t":"S-0029","k":"cites"},{"s":"K-0005","t":"S-0014","k":"cites"},{"s":"K-0020","t":"S-0029","k":"cites"},{"s":"K-0020","t":"S-0017","k":"cites"},{"s":"K-0020","t":"S-0067","k":"cites"},{"s":"K-0020","t":"S-0018","k":"cites"},{"s":"K-0013","t":"S-1600","k":"cites"},{"s":"K-0013","t":"S-0043","k":"cites"},{"s":"K-0013","t":"S-0014","k":"cites"},{"s":"K-0013","t":"S-0038","k":"cites"},{"s":"K-0013","t":"S-0018","k":"cites"},{"s":"K-0013","t":"S-0005","k":"cites"},{"s":"K-0015","t":"S-1605","k":"cites"},{"s":"K-0015","t":"S-1600","k":"cites"},{"s":"K-0015","t":"S-0029","k":"cites"},{"s":"K-0015","t":"S-0035","k":"cites"},{"s":"K-0015","t":"S-0067","k":"cites"},{"s":"K-0015","t":"S-1317","k":"cites"},{"s":"K-0018","t":"S-0072","k":"cites"},{"s":"K-0018","t":"S-1600","k":"cites"},{"s":"K-0018","t":"S-0029","k":"cites"},{"s":"K-0018","t":"S-0004","k":"cites"},{"s":"K-0018","t":"S-0018","k":"cites"},{"s":"K-0006","t":"S-1600","k":"cites"},{"s":"K-0006","t":"S-1604","k":"cites"},{"s":"K-0006","t":"S-0012","k":"cites"},{"s":"K-0006","t":"S-0009","k":"cites"},{"s":"K-0006","t":"S-0014","k":"cites"},{"s":"K-0016","t":"S-0002","k":"cites"},{"s":"K-0016","t":"S-0029","k":"cites"},{"s":"K-0016","t":"S-0005","k":"cites"},{"s":"K-0016","t":"S-0053","k":"cites"},{"s":"K-0016","t":"S-0062","k":"cites"},{"s":"K-0016","t":"S-0018","k":"cites"},{"s":"K-0002","t":"S-0004","k":"cites"},{"s":"K-0002","t":"S-1603","k":"cites"},{"s":"K-0002","t":"S-0002","k":"cites"},{"s":"K-0002","t":"S-1606","k":"cites"},{"s":"K-0002","t":"S-0029","k":"cites"},{"s":"K-0002","t":"S-0018","k":"cites"},{"s":"K-0022","t":"S-1610","k":"cites"},{"s":"K-0022","t":"S-0015","k":"cites"},{"s":"K-0022","t":"S-0038","k":"cites"},{"s":"K-0022","t":"S-0018","k":"cites"},{"s":"K-0010","t":"S-1600","k":"cites"},{"s":"K-0010","t":"S-1606","k":"cites"},{"s":"K-0010","t":"S-0023","k":"cites"},{"s":"K-0010","t":"S-0025","k":"cites"},{"s":"O-0201","t":"S-0067","k":"cites"},{"s":"O-0201","t":"S-1511","k":"cites"},{"s":"O-0201","t":"S-1410","k":"cites"},{"s":"O-0101","t":"S-0017","k":"cites"},{"s":"O-0101","t":"S-1006","k":"cites"},{"s":"O-0101","t":"S-1007","k":"cites"},{"s":"O-0101","t":"S-1309","k":"cites"},{"s":"O-0101","t":"S-1310","k":"cites"},{"s":"O-0101","t":"S-1311","k":"cites"},{"s":"O-0101","t":"S-1312","k":"cites"},{"s":"O-0101","t":"S-1313","k":"cites"},{"s":"O-0101","t":"S-1302","k":"cites"},{"s":"O-0101","t":"S-1303","k":"cites"},{"s":"O-0101","t":"S-1321","k":"cites"},{"s":"O-0101","t":"S-0048","k":"cites"},{"s":"O-0101","t":"S-1511","k":"cites"},{"s":"O-0101","t":"S-1008","k":"cites"},{"s":"O-0101","t":"S-1512","k":"cites"},{"s":"O-0120","t":"S-1101","k":"cites"},{"s":"O-0120","t":"S-1102","k":"cites"},{"s":"O-0120","t":"S-1103","k":"cites"},{"s":"O-0207","t":"S-0056","k":"cites"},{"s":"O-0211","t":"S-1818","k":"cites"},{"s":"O-0211","t":"S-0053","k":"cites"},{"s":"O-0211","t":"S-0061","k":"cites"},{"s":"O-0208","t":"S-1411","k":"cites"},{"s":"O-0208","t":"S-1409","k":"cites"},{"s":"O-0208","t":"S-1410","k":"cites"},{"s":"O-0206","t":"S-1203","k":"cites"},{"s":"O-0206","t":"S-1511","k":"cites"},{"s":"O-0206","t":"S-1320","k":"cites"},{"s":"O-0204","t":"S-1400","k":"cites"},{"s":"O-0204","t":"S-1401","k":"cites"},{"s":"O-0204","t":"S-1402","k":"cites"},{"s":"O-0210","t":"S-1706","k":"cites"},{"s":"O-0210","t":"S-1707","k":"cites"},{"s":"O-0210","t":"S-1510","k":"cites"},{"s":"O-0180","t":"S-1406","k":"cites"},{"s":"O-0180","t":"S-1404","k":"cites"},{"s":"O-0180","t":"S-1407","k":"cites"},{"s":"O-0180","t":"S-1301","k":"cites"},{"s":"O-0180","t":"S-1701","k":"cites"},{"s":"O-0180","t":"S-1702","k":"cites"},{"s":"O-0202","t":"S-0018","k":"cites"},{"s":"O-0202","t":"S-0038","k":"cites"},{"s":"O-0202","t":"S-0014","k":"cites"},{"s":"O-0202","t":"S-0005","k":"cites"},{"s":"O-0202","t":"S-0063","k":"cites"},{"s":"O-0140","t":"S-1200","k":"cites"},{"s":"O-0140","t":"S-1201","k":"cites"},{"s":"O-0140","t":"S-1206","k":"cites"},{"s":"O-0209","t":"S-1703","k":"cites"},{"s":"O-0209","t":"S-1300","k":"cites"},{"s":"O-0209","t":"S-1704","k":"cites"},{"s":"O-0205","t":"S-1705","k":"cites"},{"s":"O-0205","t":"S-0004","k":"cites"},{"s":"O-0205","t":"S-0058","k":"cites"},{"s":"O-0205","t":"S-1703","k":"cites"},{"s":"O-0205","t":"S-1320","k":"cites"},{"s":"O-0121","t":"S-1105","k":"cites"},{"s":"O-0121","t":"S-1106","k":"cites"},{"s":"O-0121","t":"S-1107","k":"cites"},{"s":"O-0102","t":"S-1700","k":"cites"},{"s":"O-0102","t":"S-1409","k":"cites"},{"s":"O-0100","t":"S-1000","k":"cites"},{"s":"O-0100","t":"S-1001","k":"cites"},{"s":"O-0100","t":"S-1002","k":"cites"},{"s":"O-0100","t":"S-1003","k":"cites"},{"s":"O-0100","t":"S-1004","k":"cites"},{"s":"O-0200","t":"S-0002","k":"cites"},{"s":"O-0200","t":"S-0057","k":"cites"},{"s":"O-0200","t":"S-1510","k":"cites"},{"s":"O-0200","t":"S-1610","k":"cites"},{"s":"O-0200","t":"S-1511","k":"cites"},{"s":"O-0160","t":"S-1320","k":"cites"},{"s":"O-0160","t":"S-1319","k":"cites"},{"s":"O-0160","t":"S-1511","k":"cites"},{"s":"O-0141","t":"S-0013","k":"cites"},{"s":"O-0141","t":"S-1209","k":"cites"},{"s":"O-0141","t":"S-1207","k":"cites"},{"s":"O-0141","t":"S-1208","k":"cites"},{"s":"O-0141","t":"S-1206","k":"cites"},{"s":"O-0142","t":"S-0009","k":"cites"},{"s":"O-0122","t":"S-0023","k":"cites"},{"s":"O-0122","t":"S-1108","k":"cites"},{"s":"O-0203","t":"S-1701","k":"cites"},{"s":"O-0203","t":"S-1702","k":"cites"},{"s":"O-0203","t":"S-1406","k":"cites"},{"s":"O-0141","t":"S-1206","k":"published"},{"s":"O-0202","t":"S-0018","k":"published"},{"s":"O-0211","t":"S-1818","k":"published"},{"s":"O-0205","t":"S-1705","k":"published"},{"s":"O-0101","t":"S-1008","k":"published"},{"s":"O-0101","t":"S-1007","k":"published"},{"s":"O-0101","t":"S-1321","k":"published"},{"s":"O-0202","t":"S-0063","k":"published"},{"s":"O-0142","t":"S-0009","k":"published"},{"s":"O-0141","t":"S-1207","k":"published"},{"s":"O-0140","t":"S-1611","k":"published"},{"s":"O-0205","t":"S-0053","k":"published"},{"s":"O-0211","t":"S-0053","k":"published"},{"s":"O-0140","t":"S-1201","k":"published"},{"s":"O-0201","t":"S-1410","k":"published"},{"s":"O-0101","t":"S-0017","k":"published"},{"s":"O-0180","t":"S-1702","k":"published"},{"s":"O-0206","t":"S-1203","k":"published"},{"s":"O-0209","t":"S-1300","k":"published"},{"s":"O-0101","t":"S-1312","k":"published"},{"s":"O-0120","t":"S-1103","k":"published"},{"s":"O-0201","t":"S-1511","k":"published"},{"s":"O-0205","t":"S-0058","k":"published"},{"s":"O-0209","t":"S-1703","k":"published"},{"s":"O-0200","t":"S-0057","k":"published"},{"s":"O-0200","t":"S-1510","k":"published"},{"s":"O-0141","t":"S-0013","k":"published"},{"s":"O-0141","t":"S-1208","k":"published"},{"s":"O-0101","t":"S-1303","k":"published"},{"s":"O-0160","t":"S-1319","k":"published"},{"s":"O-0100","t":"S-1003","k":"published"},{"s":"O-0210","t":"S-1706","k":"published"},{"s":"O-0205","t":"S-0061","k":"published"},{"s":"O-0211","t":"S-0061","k":"published"},{"s":"O-0160","t":"S-1320","k":"published"},{"s":"O-0208","t":"S-1411","k":"published"},{"s":"O-0204","t":"S-1400","k":"published"},{"s":"O-0204","t":"S-1401","k":"published"},{"s":"O-0180","t":"S-1406","k":"published"},{"s":"O-0180","t":"S-1407","k":"published"},{"s":"O-0180","t":"S-1701","k":"published"},{"s":"O-0202","t":"S-0005","k":"published"},{"s":"O-0101","t":"S-1302","k":"published"},{"s":"O-0141","t":"S-1209","k":"published"},{"s":"O-0204","t":"S-1402","k":"published"},{"s":"O-0101","t":"S-1310","k":"published"},{"s":"O-0101","t":"S-1309","k":"published"},{"s":"O-0101","t":"S-1311","k":"published"},{"s":"O-0140","t":"S-1815","k":"published"},{"s":"O-0140","t":"S-1200","k":"published"},{"s":"O-0202","t":"S-0014","k":"published"},{"s":"O-0140","t":"S-1413","k":"published"},{"s":"O-0210","t":"S-1707","k":"published"},{"s":"O-0120","t":"S-1102","k":"published"},{"s":"O-0121","t":"S-1105","k":"published"},{"s":"O-0121","t":"S-1106","k":"published"},{"s":"O-0121","t":"S-1107","k":"published"},{"s":"O-0102","t":"S-1700","k":"published"},{"s":"O-0100","t":"S-1001","k":"published"},{"s":"O-0120","t":"S-1101","k":"published"},{"s":"O-0101","t":"S-1006","k":"published"},{"s":"O-0207","t":"S-0056","k":"published"},{"s":"O-0200","t":"S-1610","k":"published"},{"s":"O-0180","t":"S-1404","k":"published"},{"s":"O-0202","t":"S-0038","k":"published"},{"s":"O-0100","t":"S-1004","k":"published"},{"s":"O-0101","t":"S-1313","k":"published"},{"s":"O-0100","t":"S-1000","k":"published"},{"s":"O-0100","t":"S-1002","k":"published"},{"s":"O-0180","t":"S-1301","k":"published"},{"s":"O-0101","t":"S-0048","k":"published"},{"s":"O-0209","t":"S-1704","k":"published"},{"s":"O-0205","t":"S-1704","k":"published"},{"s":"O-0205","t":"S-0004","k":"published"},{"s":"O-0201","t":"S-0067","k":"published"},{"s":"O-0200","t":"S-0002","k":"published"},{"s":"O-0101","t":"S-1512","k":"published"},{"s":"O-0122","t":"S-1108","k":"published"},{"s":"O-0122","t":"S-0023","k":"published"},{"s":"O-0101","t":"C-0008","k":"works_toward","role":"p","via":["M-0014","I-0011"]},{"s":"O-0101","t":"C-0004","k":"works_toward","role":"p","via":["M-0014","M-0015","M-0013","M-0003","M-0001","M-0016","M-0021","I-0011"]},{"s":"O-0101","t":"C-0007","k":"works_toward","role":"s","via":["M-0014","M-0003","M-0021"]},{"s":"O-0101","t":"C-0009","k":"works_toward","role":"s","via":["M-0014","M-0013","M-0001"]},{"s":"O-0180","t":"C-0008","k":"works_toward","role":"p","via":["M-0014"]},{"s":"O-0180","t":"C-0004","k":"works_toward","role":"s","via":["M-0014"]},{"s":"O-0180","t":"C-0007","k":"works_toward","role":"s","via":["M-0014"]},{"s":"O-0180","t":"C-0009","k":"works_toward","role":"s","via":["M-0014"]},{"s":"O-0201","t":"C-0008","k":"works_toward","role":"p","via":["M-0014","I-0011"]},{"s":"O-0201","t":"C-0004","k":"works_toward","role":"p","via":["M-0014","M-0015","M-0013","M-0003","M-0001","I-0011"]},{"s":"O-0201","t":"C-0007","k":"works_toward","role":"s","via":["M-0014","M-0003"]},{"s":"O-0201","t":"C-0009","k":"works_toward","role":"s","via":["M-0014","M-0013","M-0001"]},{"s":"O-0202","t":"C-0008","k":"works_toward","role":"p","via":["M-0014","M-0022"]},{"s":"O-0202","t":"C-0004","k":"works_toward","role":"p","via":["M-0014","M-0015","M-0013","M-0010","M-0001","M-0022","M-0008","M-0016","I-0012"]},{"s":"O-0202","t":"C-0007","k":"works_toward","role":"s","via":["M-0014","M-0025","M-0010","M-0008"]},{"s":"O-0202","t":"C-0009","k":"works_toward","role":"s","via":["M-0014","M-0012","M-0013","M-0001","M-0022"]},{"s":"O-0180","t":"C-0002","k":"works_toward","role":"p","via":["M-0018","I-0009"]},{"s":"O-0180","t":"C-0010","k":"works_toward","role":"s","via":["M-0018"]},{"s":"O-0204","t":"C-0002","k":"works_toward","role":"p","via":["M-0018","M-0019"]},{"s":"O-0204","t":"C-0010","k":"works_toward","role":"s","via":["M-0018","M-0019"]},{"s":"O-0207","t":"C-0002","k":"works_toward","role":"p","via":["M-0018","M-0009"]},{"s":"O-0207","t":"C-0010","k":"works_toward","role":"s","via":["M-0018"]},{"s":"O-0140","t":"C-0002","k":"works_toward","role":"p","via":["M-0018"]},{"s":"O-0140","t":"C-0010","k":"works_toward","role":"s","via":["M-0018"]},{"s":"O-0200","t":"C-0001","k":"works_toward","role":"p","via":["M-0019","M-0011"]},{"s":"O-0200","t":"C-0010","k":"works_toward","role":"s","via":["M-0019"]},{"s":"O-0200","t":"C-0002","k":"works_toward","role":"s","via":["M-0019","M-0009"]},{"s":"O-0201","t":"C-0001","k":"works_toward","role":"p","via":["M-0019","M-0020"]},{"s":"O-0201","t":"C-0010","k":"works_toward","role":"p","via":["M-0019","M-0020"]},{"s":"O-0201","t":"C-0002","k":"works_toward","role":"s","via":["M-0019"]},{"s":"O-0204","t":"C-0001","k":"works_toward","role":"p","via":["M-0019"]},{"s":"O-0142","t":"C-0005","k":"works_toward","role":"p","via":["M-0025","M-0012","M-0023","M-0008","I-0007"]},{"s":"O-0142","t":"C-0006","k":"works_toward","role":"p","via":["M-0025","M-0012","M-0023","M-0008","I-0007"]},{"s":"O-0142","t":"C-0007","k":"works_toward","role":"s","via":["M-0025","M-0008"]},{"s":"O-0202","t":"C-0005","k":"works_toward","role":"p","via":["M-0025","M-0012","M-0013","M-0023","M-0001","M-0008","I-0012"]},{"s":"O-0202","t":"C-0006","k":"works_toward","role":"p","via":["M-0025","M-0012","M-0023","M-0008","I-0012"]},{"s":"O-0200","t":"C-0007","k":"works_toward","role":"p","via":["M-0011","M-0009"]},{"s":"O-0200","t":"C-0003","k":"works_toward","role":"s","via":["M-0011"]},{"s":"O-0207","t":"C-0001","k":"works_toward","role":"s","via":["M-0011"]},{"s":"O-0207","t":"C-0007","k":"works_toward","role":"p","via":["M-0011","M-0009"]},{"s":"O-0207","t":"C-0003","k":"works_toward","role":"s","via":["M-0011"]},{"s":"O-0200","t":"C-0005","k":"works_toward","role":"s","via":["M-0009","I-0010"]},{"s":"O-0200","t":"C-0008","k":"works_toward","role":"s","via":["M-0009"]},{"s":"O-0200","t":"C-0006","k":"works_toward","role":"s","via":["M-0009"]},{"s":"O-0207","t":"C-0005","k":"works_toward","role":"s","via":["M-0009"]},{"s":"O-0207","t":"C-0008","k":"works_toward","role":"s","via":["M-0009"]},{"s":"O-0207","t":"C-0006","k":"works_toward","role":"s","via":["M-0009"]},{"s":"O-0141","t":"C-0005","k":"works_toward","role":"p","via":["M-0012","M-0008","I-0006"]},{"s":"O-0141","t":"C-0006","k":"works_toward","role":"s","via":["M-0012","M-0008"]},{"s":"O-0141","t":"C-0009","k":"works_toward","role":"s","via":["M-0012"]},{"s":"O-0142","t":"C-0009","k":"works_toward","role":"s","via":["M-0012"]},{"s":"O-0101","t":"C-0005","k":"works_toward","role":"p","via":["M-0013","M-0001","I-0011"]},{"s":"O-0160","t":"C-0004","k":"works_toward","role":"p","via":["M-0013","I-0008"]},{"s":"O-0160","t":"C-0009","k":"works_toward","role":"s","via":["M-0013"]},{"s":"O-0160","t":"C-0005","k":"works_toward","role":"s","via":["M-0013","I-0008"]},{"s":"O-0201","t":"C-0005","k":"works_toward","role":"p","via":["M-0013","M-0001","I-0011"]},{"s":"O-0209","t":"C-0004","k":"works_toward","role":"p","via":["M-0013"]},{"s":"O-0209","t":"C-0009","k":"works_toward","role":"s","via":["M-0013"]},{"s":"O-0209","t":"C-0005","k":"works_toward","role":"s","via":["M-0013"]},{"s":"O-0202","t":"C-0003","k":"works_toward","role":"p","via":["M-0010","M-0016"]},{"s":"O-0202","t":"C-0010","k":"works_toward","role":"s","via":["M-0010","I-0012"]},{"s":"O-0120","t":"C-0010","k":"works_toward","role":"p","via":["M-0007"]},{"s":"O-0120","t":"C-0003","k":"works_toward","role":"s","via":["M-0007"]},{"s":"O-0120","t":"C-0004","k":"works_toward","role":"s","via":["M-0007","M-0004","I-0005"]},{"s":"O-0121","t":"C-0010","k":"works_toward","role":"p","via":["M-0007","I-0004"]},{"s":"O-0121","t":"C-0003","k":"works_toward","role":"s","via":["M-0007"]},{"s":"O-0121","t":"C-0004","k":"works_toward","role":"s","via":["M-0007"]},{"s":"O-0102","t":"C-0010","k":"works_toward","role":"p","via":["M-0020"]},{"s":"O-0102","t":"C-0001","k":"works_toward","role":"s","via":["M-0020"]},{"s":"O-0208","t":"C-0010","k":"works_toward","role":"p","via":["M-0020"]},{"s":"O-0208","t":"C-0001","k":"works_toward","role":"s","via":["M-0020"]},{"s":"O-0100","t":"C-0005","k":"works_toward","role":"p","via":["M-0001","I-0001"]},{"s":"O-0100","t":"C-0009","k":"works_toward","role":"s","via":["M-0001"]},{"s":"O-0100","t":"C-0004","k":"works_toward","role":"s","via":["M-0001"]},{"s":"O-0140","t":"C-0005","k":"works_toward","role":"p","via":["M-0008"]},{"s":"O-0140","t":"C-0006","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0140","t":"C-0004","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0140","t":"C-0007","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0141","t":"C-0004","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0141","t":"C-0007","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0142","t":"C-0004","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0206","t":"C-0005","k":"works_toward","role":"p","via":["M-0008","I-0008"]},{"s":"O-0206","t":"C-0006","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0206","t":"C-0004","k":"works_toward","role":"p","via":["M-0008","I-0008"]},{"s":"O-0206","t":"C-0007","k":"works_toward","role":"s","via":["M-0008"]},{"s":"O-0101","t":"C-0003","k":"works_toward","role":"p","via":["M-0016"]},{"s":"O-0101","t":"C-0002","k":"works_toward","role":"s","via":["M-0016"]},{"s":"O-0202","t":"C-0002","k":"works_toward","role":"s","via":["M-0016"]},{"s":"O-0120","t":"C-0005","k":"works_toward","role":"p","via":["M-0004","I-0005"]},{"s":"O-0120","t":"C-0006","k":"works_toward","role":"s","via":["M-0004","I-0005"]},{"s":"O-0122","t":"C-0005","k":"works_toward","role":"p","via":["M-0004","I-0003"]},{"s":"O-0122","t":"C-0004","k":"works_toward","role":"s","via":["M-0004"]},{"s":"O-0122","t":"C-0006","k":"works_toward","role":"s","via":["M-0004"]},{"s":"O-0200","t":"C-0009","k":"works_toward","role":"p","via":["I-0010"]},{"s":"O-0200","t":"C-0004","k":"works_toward","role":"s","via":["I-0010"]},{"s":"K-0003","t":"M-0014","k":"mentions"},{"s":"I-0011","t":"M-0024","k":"mentions"},{"s":"I-0002","t":"M-0024","k":"mentions"},{"s":"O-0207","t":"M-0019","k":"mentions"},{"s":"K-0003","t":"M-0015","k":"mentions"},{"s":"O-0203","t":"M-0013","k":"mentions"},{"s":"O-0140","t":"M-0010","k":"mentions"},{"s":"O-0200","t":"M-0010","k":"mentions"},{"s":"I-0005","t":"M-0007","k":"mentions"},{"s":"O-0200","t":"M-0020","k":"mentions"},{"s":"I-0016","t":"M-0001","k":"mentions"},{"s":"O-0160","t":"M-0001","k":"mentions"},{"s":"O-0207","t":"M-0008","k":"mentions"},{"s":"O-0203","t":"M-0008","k":"mentions"},{"s":"M-0018","t":"M-0016","k":"mentions"},{"s":"M-0008","t":"M-0021","k":"mentions"},{"s":"O-0203","t":"M-0021","k":"mentions"},{"s":"O-0122","t":"M-0005","k":"mentions"},{"s":"M-0012","t":"I-0013","k":"mentions"},{"s":"M-0025","t":"I-0007","k":"mentions"},{"s":"M-0023","t":"I-0007","k":"mentions"},{"s":"I-0001","t":"I-0002","k":"mentions"},{"s":"O-0101","t":"I-0002","k":"mentions"},{"s":"M-0012","t":"I-0015","k":"mentions"},{"s":"M-0023","t":"I-0012","k":"mentions"},{"s":"O-0209","t":"I-0012","k":"mentions"},{"s":"O-0210","t":"I-0010","k":"mentions"},{"s":"O-0205","t":"I-0008","k":"mentions"},{"s":"O-0140","t":"I-0006","k":"mentions"},{"s":"I-0002","t":"I-0001","k":"mentions"},{"s":"I-0015","t":"I-0001","k":"mentions"},{"s":"C-0009","t":"C-0008","k":"mentions"},{"s":"O-0211","t":"C-0008","k":"mentions"},{"s":"C-0001","t":"C-0002","k":"mentions"},{"s":"C-0003","t":"C-0002","k":"mentions"},{"s":"C-0007","t":"C-0001","k":"mentions"},{"s":"O-0211","t":"C-0001","k":"mentions"},{"s":"O-0202","t":"C-0001","k":"mentions"},{"s":"C-0002","t":"C-0003","k":"mentions"},{"s":"C-0010","t":"C-0003","k":"mentions"},{"s":"C-0006","t":"C-0005","k":"mentions"},{"s":"C-0002","t":"C-0004","k":"mentions"},{"s":"C-0003","t":"C-0004","k":"mentions"},{"s":"C-0010","t":"C-0004","k":"mentions"},{"s":"O-0211","t":"C-0004","k":"mentions"},{"s":"O-0205","t":"C-0004","k":"mentions"},{"s":"C-0001","t":"C-0010","k":"mentions"},{"s":"C-0007","t":"C-0010","k":"mentions"},{"s":"C-0003","t":"C-0007","k":"mentions"},{"s":"C-0008","t":"C-0009","k":"mentions"},{"s":"O-0210","t":"C-0009","k":"mentions"},{"s":"K-0017","t":"K-0014","k":"mentions"},{"s":"K-0012","t":"K-0001","k":"mentions"},{"s":"K-0011","t":"K-0001","k":"mentions"},{"s":"K-0016","t":"K-0001","k":"mentions"},{"s":"O-0205","t":"K-0001","k":"mentions"},{"s":"K-0009","t":"K-0002","k":"mentions"},{"s":"O-0205","t":"K-0002","k":"mentions"},{"s":"I-0002","t":"O-0101","k":"mentions"},{"s":"O-0160","t":"O-0206","k":"mentions"},{"s":"I-0010","t":"O-0210","k":"mentions"},{"s":"O-0203","t":"O-0180","k":"mentions"},{"s":"O-0205","t":"O-0209","k":"mentions"},{"s":"O-0209","t":"O-0205","k":"mentions"},{"s":"O-0160","t":"O-0205","k":"mentions"},{"s":"O-0180","t":"O-0203","k":"mentions"}]}