The declared model is the one being served
On this page
Mechanisms
- Enables exact-match recomputation checks that the declared model, weights and software setup produced the outputs.
- Core purpose: responses come from the declared weights.
- Checks that sampled recorded outputs are consistent with the declared model, precision and sampling settings.
- Attests the software stack that produced responses, and the model too when paired with a weight commitment (see Model identity attestation).
- Binds audit or capability-evaluation results to the model that is served, without revealing weights 1 4.
- Binds each proven output to committed weights and a public architecture.
- R2Safeguard attestationsupportingProperty and audit attestations bind responses to a measured model 4 5.
- Deployment only to approved flexHEG devices, and verification of evaluation scores 1.
- R1Network taps and certifierssupportingReplaying challenged records with the declared model checks which model produced outputs 1 4.
Implementations
- Assessed use: showing clients that the served weights match a committed hashClients check that the served weights match a committed root hash.
- Assessed use: checking that untrusted providers used the claimed model, prompt and precisionChecks that the provider produced outputs with the claimed model weights, prompt and precision.
- R3Verde and RepOps (Gensyn)primaryAssessed use: reproducing declared-model inference from receipts in Gensyn's information-market serviceA client learns that a delegated inference output came from the declared model and input, if at least one provider is honest 1 2.
- R2Attestable AuditsprimaryAssessed use: showing users that the model answering them is the audited oneUsers can check that the model answering them is the audited one.
- Assessed use: checking that outputs match the declared model, precision and sampling settingsChecks that outputs are consistent with the declared model, precision and sampling configuration.
- Assessed use: proving a language model's output follows from committed weights, against a cheating proverProves an output follows from a committed model. South et al.'s results reach about a million parameters 2.
- Assessed use: attesting declared model operations on a confidential CPU–GPU prototypeInference attestations bind the measured model and tokenizer to queries and outputs 1.
- Assessed use: proving an output came from committed weights, against a prover who cheatsProves an output follows from committed weights and a public architecture.
- Assessed use: proving an output came from committed weightsAttestable reports proving y = F(W, x, r) for committed weights W.
- R3Apple Private Cloud ComputesupportingAssessed use: showing users which software serves their AI requests, not which modelAttests the software release that served a request. Apple reports that model assets share the code's integrity protection 1.
- Assessed use: exact recomputation of served outputs by a verifier, with a cooperating providerMakes exact-match recomputation of served outputs possible when the verifier runs the same model, engine and hardware 6.
- Assessed use: attesting code execution on a GPU that lacks hardware trusted-execution supportAttests that unmodified code executes on the GPU 1.
- Assessed use: showing that retrofitted data centres run only inferenceRecomputation checks sampled packets against the declared model.
- Assessed use: screening challenged records to show declared inference compute is not trainingScreening checks that the model is on an agreed whitelist.
- Assessed use: the operator's own weight security, with no outside verification describedThe compute sanctum checks resident weights against reference measurements before serving.
- R1SASH confidential network loggersupportingAssessed use: telling inference from training on a mutually inspected clusterRecomputation uses another copy of the declared model 1 2.