Model weights have not left the facility
On this page
Mechanisms
- Bounds how much weight or other undeclared information can leave in checked outputs; does not close other channels.
- R3Deterministic and bit-exact inferencesupportingRemoves the tolerance margin that steganographic exfiltration could use 1.
- R3Model identity attestation⚠supportingThe recomputation variant limits steganographic weight exfiltration through outputs 4.
- R3Sampled inference recomputationsupportingBounds how much information can be hidden steganographically in checked outputs. It is not a stand-alone defence against weight exfiltration 1.
- A cap on outgoing bandwidth bounds how much weight data can leave a facility in a given time 3.
- R1Network taps and certifierssupportingAims to make covert exfiltration of results through tapped links infeasible 1.
- Supports arguments that weights cannot leave by unmonitored physical routes.
Implementations
- R2DiFR (Divergence From Reference)supportingAssessed use: checking that outputs match the declared model, precision and sampling settingsUsed as the estimator in a weight-exfiltration detection scheme 2.
- Assessed use: the operator's own weight security, with no outside verification describedA security architecture for keeping weights and inference data inside the facility; the report does not describe how an external party would verify this 1.