The declared model is the one being served

On this page

Mechanisms

Implementations

  • Assessed use: showing clients that the served weights match a committed hashClients check that the served weights match a committed root hash.
  • R3TOPLOCprimary
    Assessed use: checking that untrusted providers used the claimed model, prompt and precisionChecks that the provider produced outputs with the claimed model weights, prompt and precision.
  • Assessed use: reproducing declared-model inference from receipts in Gensyn's information-market serviceA client learns that a delegated inference output came from the declared model and input, if at least one provider is honest 1 2.
  • Assessed use: showing users that the model answering them is the audited oneUsers can check that the model answering them is the audited one.
  • Assessed use: checking that outputs match the declared model, precision and sampling settingsChecks that outputs are consistent with the declared model, precision and sampling configuration.
  • R2EZKLprimary
    Assessed use: proving a language model's output follows from committed weights, against a cheating proverProves an output follows from a committed model. South et al.'s results reach about a million parameters 2.
  • R2PAL*Mprimary
    Assessed use: attesting declared model operations on a confidential CPU–GPU prototypeInference attestations bind the measured model and tokenizer to queries and outputs 1.
  • R2zkLLMprimary
    Assessed use: proving an output came from committed weights, against a prover who cheatsProves an output follows from committed weights and a public architecture.
  • Assessed use: proving an output came from committed weightsAttestable reports proving y = F(W, x, r) for committed weights W.
  • Assessed use: showing users which software serves their AI requests, not which modelAttests the software release that served a request. Apple reports that model assets share the code's integrity protection 1.
  • Assessed use: exact recomputation of served outputs by a verifier, with a cooperating providerMakes exact-match recomputation of served outputs possible when the verifier runs the same model, engine and hardware 6.
  • R2SAGEsupporting
    Assessed use: attesting code execution on a GPU that lacks hardware trusted-execution supportAttests that unmodified code executes on the GPU 1.
  • Assessed use: showing that retrofitted data centres run only inferenceRecomputation checks sampled packets against the declared model.
  • Assessed use: screening challenged records to show declared inference compute is not trainingScreening checks that the model is on an agreed whitelist.
  • Assessed use: the operator's own weight security, with no outside verification describedThe compute sanctum checks resident weights against reference measurements before serving.
  • Assessed use: telling inference from training on a mutually inspected clusterRecomputation uses another copy of the declared model 1 2.

Search

Full search page