{
  "schema_version": "1.2",
  "url": "https://trustbutveri.fyi/explorer/?claims=C-0006,C-0005&goal=G-0004",
  "data_generated": "2026-10-08",
  "definitions": {
    "methodology": "https://trustbutveri.fyi/about/methodology/",
    "readiness": "https://trustbutveri.fyi/about/readiness/",
    "filters": [
      {
        "id": "prover",
        "label": "Prover",
        "question": "How far can the party being checked be trusted?",
        "options": [
          {
            "value": "cooperative",
            "label": "Cooperative"
          },
          {
            "value": "semi-trusted",
            "label": "Semi-trusted"
          },
          {
            "value": "adversarial",
            "label": "Adversarial"
          }
        ],
        "rule": "Keeps mechanisms whose threat model holds against at least this prover. Adversarial is the strongest assumption.",
        "about": "The prover is the party being checked. Semi-trusted designs rely on part of its stack: usually the chip vendor's hardware root of trust, its firmware or counters, or its supply-chain records. Adversarial designs aim to hold even if it cheats wherever the checks allow, within their stated assumptions."
      },
      {
        "id": "onsite",
        "label": "Verifier devices on site",
        "question": "May the verifier install its own hardware at the prover's sites?",
        "options": [
          {
            "value": "no",
            "label": "Not allowed"
          }
        ],
        "rule": "\"Not allowed\" removes mechanisms that need a retrofit device, such as a network tap or a sealed sensor.",
        "about": "Some mechanisms need a device the verifier owns or trusts at the prover's facility, such as a network tap, a bandwidth limiter or a sealed sensor. Choose Not allowed when the setting rules that out. Inspectors are not covered."
      },
      {
        "id": "coop",
        "label": "Prover cooperation",
        "question": "How much must the prover take part?",
        "options": [
          {
            "value": "partial",
            "label": "Partial at most"
          },
          {
            "value": "none",
            "label": "Not required"
          }
        ],
        "rule": "\"Partial at most\" removes mechanisms that need the prover's active participation. \"Not required\" keeps only those that work without it.",
        "about": "Required: the prover takes part, for example by logging requests, producing proofs or opening records. Partial: some access, such as installing a device. Not required: works from outside, such as satellite imagery."
      },
      {
        "id": "chips",
        "label": "Chips",
        "question": "May the proposal depend on new chip designs?",
        "options": [
          {
            "value": "existing",
            "label": "Existing chips only"
          }
        ],
        "rule": "\"Existing chips only\" removes mechanisms that need changes to future chip designs.",
        "about": "New chip features take years to reach a deployed fleet and cover only chips made after they ship. Mechanisms that use shipping features, such as trusted execution environments or performance counters, stay."
      },
      {
        "id": "ready",
        "label": "Minimum readiness",
        "question": "How mature must each mechanism be?",
        "options": [
          {
            "value": "R1",
            "label": "R1 Proposed"
          },
          {
            "value": "R2",
            "label": "R2 Demonstrated"
          },
          {
            "value": "R3",
            "label": "R3 In production"
          },
          {
            "value": "R4",
            "label": "R4 Deployment-ready"
          }
        ],
        "rule": "Keeps mechanisms whose readiness level is at least this one.",
        "about": "A level describes the public evidence for a mechanism's stated use, not its cost or feasibility. R3 can still have open critical flaws."
      },
      {
        "id": "tested",
        "label": "Attack testing",
        "question": "How hard has each mechanism been attacked in public?",
        "options": [
          {
            "value": "analysis",
            "label": "Published analysis"
          },
          {
            "value": "red-teamed",
            "label": "Red-teamed"
          },
          {
            "value": "independent-red-team",
            "label": "Independent red-team"
          }
        ],
        "rule": "Keeps mechanisms whose strongest published attack testing is at least this.",
        "about": "The strongest published attempt to break the mechanism for its verification use: a security analysis, red-teaming by its developers or collaborators, or a red team independent of them."
      },
      {
        "id": "hide",
        "label": "Keep hidden from the verifier",
        "question": "What must the verifier never see?",
        "options": [
          {
            "value": "weights",
            "label": "Model weights"
          },
          {
            "value": "io",
            "label": "Inputs and outputs"
          },
          {
            "value": "training",
            "label": "Training data"
          }
        ],
        "rule": "Removes mechanisms that show the asset to the verifier. Conditional or unspecified exposure stays with a note and needs checking against the privacy requirement.",
        "about": "Model weights: the checked model's parameters. Inputs and outputs: the requests a deployed model serves and its responses. Training data: what a model was trained on. Each mechanism's exposure is the editors' reading of its record: shown, depends on the design (kept, with a note), hidden, not involved, or unspecified for a selected implementation. Code and configuration are not covered yet."
      }
    ],
    "exposure": "For model weights, inputs and outputs, and training data. This is the editors' reading of each mechanism's record (its threat model, how it works and its limitations), not a field of the record. Shown: the verifier sees it. Depends: on the design or variant, or the verifier sees only samples. Hidden: the verifier sees only commitments, hashes, proofs or results. Not involved: the record does not handle it. Unspecified: the selected implementation has no asset-specific assessment here.",
    "claim_status": {
      "addressed": "A mechanism in the proposal is aimed at this claim and is not excluded by the filters.",
      "partly-addressed": "Only supporting mechanisms, or mechanisms aimed at it that the filters exclude.",
      "unaddressed": "No mechanism in the proposal addresses this claim."
    },
    "finding_scope": "Evidence scope describes where a finding was demonstrated; it does not establish applicability to every implementation in the mechanism family.",
    "claim_finding_scope": "open_critical_findings names active findings on the assessed records; open_critical_context names conditional family findings whose implementation applicability is unassessed.",
    "legacy_status": "The status field retains covered/partial/none for compatibility. It names claim links, never successful verification. Use claim_status and status_label for presentation."
  },
  "filters": {
    "prover": "",
    "onsite": "",
    "coop": "",
    "chips": "",
    "ready": "",
    "tested": "",
    "hide": []
  },
  "mechanisms_passing_filters": 25,
  "claims": [
    {
      "id": "C-0006",
      "title": "Declared safeguards were applied during inference",
      "url": "https://trustbutveri.fyi/claims/safeguards-were-applied/",
      "n": 1,
      "status": "none",
      "claim_status": "unaddressed",
      "status_label": "Unaddressed",
      "open_critical_findings": [],
      "open_critical_context": [],
      "goal_relevance": "direct",
      "note": "No mechanism in the proposal addresses it.",
      "aimed_at_by": [],
      "supported_by": []
    },
    {
      "id": "C-0005",
      "title": "The declared model is the one being served",
      "url": "https://trustbutveri.fyi/claims/declared-model-is-served/",
      "n": 2,
      "status": "none",
      "claim_status": "unaddressed",
      "status_label": "Unaddressed",
      "open_critical_findings": [],
      "open_critical_context": [],
      "goal_relevance": "supporting",
      "note": "No mechanism in the proposal addresses it.",
      "aimed_at_by": [],
      "supported_by": []
    }
  ],
  "mechanisms": [],
  "strengths": {
    "covered": [],
    "production": [],
    "adversarial": [],
    "noNewHardware": [],
    "mitigated": [],
    "notCounted": []
  },
  "properties": {
    "covered": [],
    "production": [],
    "adversarial": [],
    "noNewHardware": [],
    "mitigated": [],
    "notCounted": []
  },
  "attack_testing": [],
  "selected_implementations": {},
  "weaknesses": {
    "gaps": [
      {
        "id": "C-0006",
        "n": 1,
        "status": "none",
        "note": "No mechanism in the proposal addresses it.",
        "critical": [],
        "criticalContext": [],
        "aimed": [],
        "aimedOk": [],
        "supporting": [],
        "level": "direct"
      },
      {
        "id": "C-0005",
        "n": 2,
        "status": "none",
        "note": "No mechanism in the proposal addresses it.",
        "critical": [],
        "criticalContext": [],
        "aimed": [],
        "aimedOk": [],
        "supporting": [],
        "level": "supporting"
      }
    ],
    "excluded": [],
    "unlinked": [],
    "critical": [],
    "significant": [],
    "criticalMechanisms": [],
    "significantMechanisms": [],
    "familyContext": [],
    "minor": 0,
    "minorFindings": [],
    "minorBy": [],
    "notDemonstrated": [],
    "newChip": []
  },
  "findings": [],
  "possible_additions": [
    {
      "id": "M-0002",
      "title": "Deterministic and bit-exact inference",
      "url": "https://trustbutveri.fyi/mechanisms/deterministic-inference/",
      "readiness": "R3",
      "fits_filters": true,
      "filter_issues": [],
      "reasons": [
        {
          "kind": "gap",
          "claim": "C-0005"
        }
      ]
    },
    {
      "id": "M-0012",
      "title": "Model identity attestation",
      "url": "https://trustbutveri.fyi/mechanisms/model-identity-attestation/",
      "readiness": "R3",
      "fits_filters": true,
      "filter_issues": [],
      "reasons": [
        {
          "kind": "gap",
          "claim": "C-0005"
        }
      ]
    },
    {
      "id": "M-0001",
      "title": "Sampled inference recomputation",
      "url": "https://trustbutveri.fyi/mechanisms/sampled-inference-recomputation/",
      "readiness": "R3",
      "fits_filters": true,
      "filter_issues": [],
      "reasons": [
        {
          "kind": "gap",
          "claim": "C-0005"
        }
      ]
    },
    {
      "id": "M-0008",
      "title": "TEE remote attestation for AI workloads",
      "url": "https://trustbutveri.fyi/mechanisms/tee-remote-attestation/",
      "readiness": "R3",
      "fits_filters": true,
      "filter_issues": [],
      "reasons": [
        {
          "kind": "gap",
          "claim": "C-0005"
        }
      ]
    },
    {
      "id": "M-0025",
      "title": "Confidential multi-party verification",
      "url": "https://trustbutveri.fyi/mechanisms/confidential-multi-party-verification/",
      "readiness": "R2",
      "fits_filters": true,
      "filter_issues": [],
      "reasons": [
        {
          "kind": "gap",
          "claim": "C-0005"
        }
      ]
    },
    {
      "id": "M-0023",
      "title": "Safeguard attestation",
      "url": "https://trustbutveri.fyi/mechanisms/safeguard-attestation/",
      "readiness": "R2",
      "fits_filters": true,
      "filter_issues": [],
      "reasons": [
        {
          "kind": "gap",
          "claim": "C-0006"
        }
      ]
    },
    {
      "id": "M-0004",
      "title": "Zero-knowledge proofs of inference",
      "url": "https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/",
      "readiness": "R2",
      "fits_filters": true,
      "filter_issues": [],
      "reasons": [
        {
          "kind": "gap",
          "claim": "C-0005"
        }
      ]
    }
  ],
  "goal": {
    "id": "G-0004",
    "title": "Prevent catastrophic misuse",
    "url": "https://trustbutveri.fyi/goals/prevent-catastrophic-misuse/",
    "one_liner": "Keep capable AI models from helping anyone carry out catastrophic attacks, such as biological or chemical ones.",
    "claims": [
      {
        "id": "C-0006",
        "title": "Declared safeguards were applied during inference",
        "url": "https://trustbutveri.fyi/claims/safeguards-were-applied/",
        "relevance": "direct",
        "note": "Baker and colleagues give filtering some inputs and running oversight checks on outputs as deployment mitigations. Cankaya's proposed system screens sampled workloads for outputs free of blacklisted use.",
        "sources": [
          "S-0002",
          "S-0018"
        ],
        "editorial": false,
        "in_proposal": true
      },
      {
        "id": "C-0009",
        "title": "Model weights have not left the facility",
        "url": "https://trustbutveri.fyi/claims/weights-have-not-left/",
        "relevance": "direct",
        "note": "Nevo and colleagues write that an attacker who has a model's weights can abuse the model without restrictions or monitoring.",
        "sources": [
          "S-1610"
        ],
        "editorial": false,
        "in_proposal": false
      },
      {
        "id": "C-0005",
        "title": "The declared model is the one being served",
        "url": "https://trustbutveri.fyi/claims/declared-model-is-served/",
        "relevance": "supporting",
        "note": "Safeguards are specified and checked for one model. They say little if a different model serves the requests.",
        "sources": [],
        "editorial": true,
        "in_proposal": true
      },
      {
        "id": "C-0008",
        "title": "Communication between compute groups is bounded",
        "url": "https://trustbutveri.fyi/claims/bandwidth-is-bounded/",
        "relevance": "supporting",
        "note": "A limit on the total data that can leave a facility caps how much of a model's weights can be stolen.",
        "sources": [
          "S-1508"
        ],
        "editorial": false,
        "in_proposal": false
      }
    ],
    "outside": [
      {
        "label": "capability evaluations",
        "text": "Baker and colleagues describe mitigations as proportionate to evaluated risks. They leave improving model evaluations as a separate unsolved problem.",
        "sources": [
          "S-0002"
        ],
        "editorial": false
      },
      {
        "label": "user identity",
        "text": "Cankaya's example rule separates whitelisted users from others. This map has no records for checking who a user is.",
        "sources": [
          "S-0018"
        ],
        "editorial": false
      }
    ]
  },
  "design": null,
  "dependencies": {
    "prerequisites": [],
    "shared": [],
    "blockers": []
  },
  "exposure": {
    "weights": {
      "shown": [],
      "partial": [],
      "hidden": [],
      "none": [],
      "unknown": []
    },
    "io": {
      "shown": [],
      "partial": [],
      "hidden": [],
      "none": [],
      "unknown": []
    },
    "training": {
      "shown": [],
      "partial": [],
      "hidden": [],
      "none": [],
      "unknown": []
    }
  },
  "implementations": [],
  "sources": []
}