The declared model is the one being served
On this page
Sources
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: Subgoal 1.A (declared uses declared accurately, including inference) and 1.B (required properties; deployed models evaluated at intervals) · §3.2
- BA. Karvonen et al. (2025). DiFR: Inference Verification Despite Nondeterminism. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: need to verify inference; nondeterminism; Token-DiFR detects 4-bit quantization with AUC > 0.999 within 300 tokens · abstract
- CH. He & Thinking Machines Lab (2025). Defeating Nondeterminism in LLM Inference. Thinking Machines Lab: Connectionism. Source recordSupports: batch-size dependence as a cause of inference nondeterminism · batch invariance section
- BN. Cankaya (2026). Bit-Exact AI Inference Verification Without Performance Tradeoffs. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: bit-exact reproduction across GPU variants given recomputation data · abstract
- BB. Harack et al. (2025). Verification for International AI Governance. Oxford Martin AI Governance Initiative. Source recordSupports: model fingerprint attestation; device-model mating with an encrypted model · Appendix K (p. 157); Appendix L.4 (p. 159)
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: whitelisted models for blacklisted uses; attributing forward passes to hardware and time; committed weights in auditing environments; ZKP cost · verification goals; architecture; open problems
- AH. Sun et al. (2024). zkLLM: Zero Knowledge Proofs for Large Language Models. 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024). Source recordSupports: zkLLM proves one 2,048-token forward pass of a 13B-parameter model in under 15 minutes with proofs under 200 kB, keeping parameters private · abstract; §8 Table 1
- BP. Chantasantitam et al. (2026). PAL*M: Property Attestation for Large Generative Models. arXiv. Source recordSupports: property attestation on Intel TDX + NVIDIA H100 with under 11% overhead for common operations · abstract
- CGloria Z (2026). On TEEs for Privacy-Preserving Monitoring in AI Governance. MIRI Technical Governance Team. Source recordSupports: attestation-key holder can produce valid reports; side-channel and physical attacks; measurement coverage · Limitations
- BC. Schnabl et al. (2025). Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments. ICML 2025 Workshop on Technical AI Governance. Source recordSupports: attestation linking model, audit result, prompt and response in a TEE; reported evaluation covers the audit step on CPU-only enclaves with a 4-bit 8B model · abstract; inference protocol; §5
- CTinfoil Team (2026). How Tinfoil Proves Exactly What Model Is Running. Tinfoil. Source recordSupports: public models' hashes can be rebuilt; private models expose only the hash (provider-reported)
- BTinfoil (2026). How verification works in Tinfoil. Tinfoil documentation. Source recordSupports: Modelwrap chain in Tinfoil's production service (provider-reported) · In-band vs. out-of-band verification
- AJ. Chuang et al. (2026). TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition. 2026 IEEE Symposium on Security and Privacy (SP). Source recordSupports: physical memory-bus interposition extracts a per-CPU Intel attestation key and forges TDX attestations · abstract; §1.1
- AJ. De Meulemeester et al. (2026). Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing. 47th IEEE Symposium on Security and Privacy (S&P 2026). Source recordSupports: Battering RAM forges SEV-SNP attestation with a DDR4 interposer
- AB. Schlüter & S. Shinde (2025). RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP. 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Source recordSupports: RMPocalypse forges SEV-SNP attestation from a malicious hypervisor
- AI. Gao et al. (2025). Model Equality Testing: Which Model Is This API Serving?. International Conference on Learning Representations (ICLR 2025). Source recordSupports: model equality testing: median 77.4% power with about 10 samples per prompt; 11 of 31 Llama API endpoints in summer 2024 served distributions different from the reference weights · abstract
- BW. Cai et al. (2025). Are You Getting What You Pay For? Auditing Model Substitution in LLM APIs. arXiv. Source recordSupports: output tests query-intensive and fail against subtle substitutions; log-probability tests defeated by inference nondeterminism · abstract