This compute runs inference, not training
On this page
Mechanisms
- Classifying training versus other workloads from counters 3 or timing 1.
- Classifies observed activity as training, inference or non-ML work.
- Supplies the committed record of cluster I/O that recomputation checks against declared inference 1 4.
- Bounds the spare capacity of declared hardware that could run unauthorised training; Attestable pairs work accounting with ZK inference proofs.
- Proposed as the correctness check for an inference-only retrofit 1.
- R3Deterministic and bit-exact inferencesupportingBit-exact recomputation of declared inference removes the tolerance an operator could hide other work in 1.
- R3Sampled inference recomputationsupportingProposed as the correctness check in inference-only retrofit plans. Completeness needs other mechanisms 3 6.
- Attests a declared inference deployment, but not that the same chips ran no other workloads 11.
- Intended to leave inference workable while making large training impractical 1 2.
- In the compute-agreement framing, outputs must be predictable by policy-compliant computation, which limits what undeclared workloads can export 1.
- R2Tamper evidence for verifier devicessupportingProtects the integrity of taps, gateways and recomputation hardware used for inference-only verification 12 13.
- Listed as an alternative inference-verification direction that may not need a hardware retrofit 2; bounds spare memory 1.
- R2Zero-knowledge proofs of inferencesupportingAttestable proposes using proofs to show accounted workloads used an approved, unchanged model.
- Periodic wipes are proposed so that only verified inference outputs persist 1; Amodo frames wipes as verifying completeness of declared workloads 5.
- Inference-only designs count on suppressing unmonitored physical channels so that all significant traffic passes the taps 2.
Implementations
- Assessed use: showing that retrofitted data centres run only inferenceThe stack's stated purpose: retrofitted data centres run only inference.
- Assessed use: confirming data presence and bounding free memory across data-centre serversA capacity-filling challenge bounds the free memory a hidden workload would need 1.
- Assessed use: screening challenged records to show declared inference compute is not trainingChallenged records are screened for inference versus training.
- Assessed use: telling inference from training on a mutually inspected clusterSASH describes the aim as distinguishing inference from training in data centres 1.
- R3Pearl proof-of-useful-work blockchainsupportingAssessed use: checking matrix-multiplication work proofs for blockchain consensusDemonstrates matrix-multiplication work proofs, a component proposed for capacity accounting 8; Pearl has not demonstrated that use.
- Assessed use: proving an output came from committed weightsProposed use: showing an accounted workload used an approved, unchanged model.