{
  "schema_version": "1.4.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "I-0022",
    "slug": "palm",
    "title": "PAL*M",
    "aliases": [
      "Property Attestation for Large Generative Models"
    ],
    "status": "draft",
    "last_reviewed": "2026-10-08",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "Attests model, dataset and operation measurements for training, evaluation and inference inside a confidential CPU–GPU environment.",
    "summary": "PAL\\*M is a property-attestation prototype for generative models. It measures inputs and outputs of training, fine-tuning, evaluation and inference operations inside an Intel TDX confidential virtual machine with an NVIDIA H100. Incremental multiset hashing tracks datasets accessed from untrusted storage in random order. The authors report evaluations on 3.8–8-billion-parameter language models and training on a 124-million-parameter GPT-2. Evaluation overhead varies with the operation and dataset access strategy. On MMLU, overhead was 0.93–2.46% of total instrumented runtime with in-memory data and 7.69–11.24% with memory-mapped data. The comparison uses the same confidential environment without PAL\\*M measurements. The protocol has a symbolic Tamarin analysis. The design trusts Intel and NVIDIA hardware, excludes physical and side-channel attacks, and plans code release after peer review [[S-0012]].",
    "category": "on-chip",
    "secondary_categories": [
      "cryptographic-computational"
    ],
    "verifies": [
      {
        "claim": "C-0005",
        "role": "primary",
        "note": "Inference attestations bind the measured model and tokenizer to queries and outputs (S-0012)."
      },
      {
        "claim": "C-0011",
        "role": "primary",
        "note": "Evaluation attestations bind the operation, model, tokenizer, test dataset and reported metric (S-0012)."
      },
      {
        "claim": "C-0007",
        "role": "supporting",
        "note": "Attests declared training and fine-tuning operations and their measured inputs and outputs; it does not account for undeclared training elsewhere (S-0012)."
      }
    ],
    "threat_model": "semi-trusted",
    "adversarial_evaluation": "analysis",
    "hardware_requirement": "existing-features",
    "prover_cooperation": "required",
    "confidentiality": "preserving",
    "depends_on": [
      {
        "target": "M-0008",
        "note": "Intel TDX and NVIDIA H100 attestation and isolation provide the trust root."
      }
    ],
    "readiness": {
      "assessment": true,
      "level": "R2",
      "scope": "attesting declared model operations on a confidential CPU–GPU prototype",
      "rubric_version": "1.1",
      "rationale": "Published end-to-end experiments specify operations, models, datasets and commercial hardware.\n- **R1** met: the paper defines measured properties, the attestation protocol and the host adversary [[S-0012]].\n- **R2** met through reproducible published results on Intel TDX and an H100, including training, fine-tuning, evaluation and inference. The code is planned for release after peer review [[S-0012]].\n- **R3** not met: the paper describes a research prototype and does not document a production service or another party's reliance on its attestations [[S-0012]].",
      "evidence": [
        "S-0012"
      ],
      "next_level_gaps": [
        "A production-grade, available property-attestation implementation, or documented reliance by another party on its attestations."
      ],
      "confidence": "medium",
      "assessed_by": [
        "ai-draft"
      ],
      "assessed_on": "2026-10-08",
      "status": "current",
      "dispute": null
    },
    "flaws": [
      {
        "assessment": true,
        "title": "Physical and side-channel attacks are excluded",
        "kind": "theoretical-argument",
        "severity": "significant",
        "status": "open",
        "description": "The paper's guarantee assumes trusted TDX, CPU and H100 hardware. It treats side-channel defenses as orthogonal and excludes physical attacks, including memory-bus interposition and GPU replacement [[S-0012]]. These adversaries are outside the stated guarantee.",
        "sources": [
          "S-0012"
        ],
        "response": null
      }
    ],
    "blockers": [
      {
        "text": "The paper plans prototype code release after peer review.",
        "theme": "adversarial-validation",
        "blocked_by": null,
        "sources": [
          "S-0012"
        ]
      },
      {
        "text": "Overhead in memory-mapped dataset preprocessing and attribute-distribution experiments accounted for 37.64–42.50% of total instrumented runtime.",
        "theme": "performance-compatibility",
        "blocked_by": null,
        "sources": [
          "S-0012"
        ]
      }
    ],
    "challenge_themes": [
      "evidence-binding",
      "hardware-trust",
      "performance-compatibility"
    ],
    "organizations": [
      "O-0122"
    ],
    "people": [],
    "sources": [
      {
        "source": "S-0012",
        "supports": "protocol; property definitions; assumptions; prototype; measured overhead; code-release plan",
        "locator": "§3.2; §4; §5; §6; Tables 2–6"
      }
    ],
    "concepts": [
      "K-0004",
      "K-0006",
      "K-0024"
    ],
    "kind": "research-prototype",
    "developer": [
      "O-0122"
    ],
    "realises": [
      "M-0008",
      "M-0012"
    ],
    "homepage": "https://arxiv.org/abs/2601.16199",
    "type": "implementation",
    "url": "https://trustbutveri.fyi/implementations/palm/",
    "source_file": "content/implementations/palm.md",
    "flags_all": [],
    "body_markdown": "## What it is\n\nPAL\\*M is a prototype for attesting properties of generative-model operations, including training,\nfine-tuning, evaluation and inference [[S-0012]]. It extends [[M-0008|TEE remote attestation]] to measurements\nof the operation's inputs and outputs. Inference evidence also implements [[M-0012|model identity attestation]]\n[[S-0012]].\n\n## How it works\n\nAn initiator requests an operation and supplies its inputs and an optional freshness challenge. PAL\\*M\nloads and measures those inputs inside an Intel TDX confidential virtual machine, runs the operation with\nan attested NVIDIA H100, and measures its outputs [[S-0012]]. It puts the measurements into the TDX report\ndata and returns a quote for verification against trusted reference values and vendor roots [[S-0012]].\n\nDatasets can remain in untrusted storage. For memory-mapped data accessed in random order, incremental\nmultiset hashing accumulates measurements without depending on the order of access [[S-0012]]. Evaluation\nevidence includes the model, tokenizer, test dataset and resulting metric. Inference evidence includes\nthe query and output, and session evidence extends across a sequence of interactions [[S-0012]].\n\n## Evidence\n\n- The prototype uses Intel TDX and an H100 NVL with confidential computing enabled. Experiments average\n  five runs [[S-0012]].\n- Evaluation and inference experiments use Llama-3.1-8B, Gemma-3-4B and Phi-4-Mini. Training uses the\n  124-million-parameter GPT-2 [[S-0012]].\n- MMLU evaluation overhead was 0.93–2.46% of total instrumented runtime with in-memory data and\n  7.69–11.24% with memory-mapped data. The comparison is with the same TDX environment without PAL\\*M\n  measurement [[S-0012]].\n- The authors model the protocol in Tamarin under their stated adversary assumptions. They plan to release\n  the prototype after peer review [[S-0012]].\n\n## Limitations\n\nThe design trusts the TDX module, CPU and H100 hardware while treating the host software and external\nstorage as hostile. It excludes denial of service, physical attacks and side-channel attacks [[S-0012]].\nCosts vary by operation. Memory-mapped dataset preprocessing and attribute-distribution overhead\naccounted for 37.64–42.50% of total instrumented runtime. Single-prompt inference took 1.8–3 times its baseline\n[[S-0012]].",
    "body_text": "What it is PAL*M is a prototype for attesting properties of generative-model operations, including training, fine-tuning, evaluation and inference [S-0012]. It extends TEE remote attestation to measurements of the operation's inputs and outputs. Inference evidence also implements model identity attestation [S-0012]. How it works An initiator requests an operation and supplies its inputs and an optional freshness challenge. PAL*M loads and measures those inputs inside an Intel TDX confidential virtual machine, runs the operation with an attested NVIDIA H100, and measures its outputs [S-0012]. It puts the measurements into the TDX report data and returns a quote for verification against trusted reference values and vendor roots [S-0012]. Datasets can remain in untrusted storage. For memory-mapped data accessed in random order, incremental multiset hashing accumulates measurements without depending on the order of access [S-0012]. Evaluation evidence includes the model, tokenizer, test dataset and resulting metric. Inference evidence includes the query and output, and session evidence extends across a sequence of interactions [S-0012]. Evidence - The prototype uses Intel TDX and an H100 NVL with confidential computing enabled. Experiments average five runs [S-0012]. - Evaluation and inference experiments use Llama-3.1-8B, Gemma-3-4B and Phi-4-Mini. Training uses the 124-million-parameter GPT-2 [S-0012]. - MMLU evaluation overhead was 0.93–2.46% of total instrumented runtime with in-memory data and 7.69–11.24% with memory-mapped data. The comparison is with the same TDX environment without PAL*M measurement [S-0012]. - The authors model the protocol in Tamarin under their stated adversary assumptions. They plan to release the prototype after peer review [S-0012]. Limitations The design trusts the TDX module, CPU and H100 hardware while treating the host software and external storage as hostile. It excludes denial of service, physical attacks and side-channel attacks [S-0012]. Costs vary by operation. Memory-mapped dataset preprocessing and attribute-distribution overhead accounted for 37.64–42.50% of total instrumented runtime. Single-prompt inference took 1.8–3 times its baseline [S-0012].",
    "referenced_by": [
      {
        "id": "C-0011",
        "title": "The declared evaluation was run",
        "url": "https://trustbutveri.fyi/claims/declared-evaluation-was-run/"
      }
    ]
  }
}