# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-09. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0007,M-0009&implementations=M-0007:I-0004

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's development status, security evidence and findings. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and findings) and https://trustbutveri.fyi/about/readiness/ (development status).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Overview

One row per mechanism, read from its record. Open failures: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees. Findings are grouped as known failures, scope limitations and open questions. Only known failures count as failures. Counts are an inventory of published findings, not a risk score.

| Mechanism | Development | Security evidence | Prover | Attack testing | Hardware | Open failures | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Proofs of useful work for capacity accounting / Pearl proof-of-useful-work blockchain | Operational use | Published security analysis | Adversarial | Analysis | None | 0 / 0 / 1 | unspecified | unspecified | unspecified |
| Hardware-enabled guarantees (flexHEG) and guarantee processors | Proposed | Published security analysis | Adversarial | Analysis | New chip design | 0 / 3 / 0 | hidden | hidden | hidden |

## Claims

No claims chosen.

## Mechanisms

### Proofs of useful work for capacity accounting

A blockchain whose mining is designed to be a by-product of GPU matrix multiplications in AI workloads, with public node and miner code. ([Proofs of useful work for capacity accounting](https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/))

- Assessment: selected implementation [Pearl proof-of-useful-work blockchain](https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/).
- Development: Operational use (legacy code R3), assessed for checking matrix-multiplication work proofs for blockchain consensus.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights unspecified; inputs and outputs unspecified; training data unspecified. This Explorer has no asset-specific exposure assessment for this implementation. Check its source and deployment assumptions.

### Hardware-enabled guarantees (flexHEG) and guarantee processors

A proposed add-on for AI chips: an auditable guarantee processor, sealed in a tamper-protected enclosure, that would check and enforce agreed rules on chip use. ([Hardware-enabled guarantees (flexHEG) and guarantee processors](https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/))

- Assessment: mechanism family.
- Development: Proposed (legacy code R1), assessed for checking and enforcing training-compute limits on chips, against adversaries up to states.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: new chip design. Prover cooperation: required. Attack testing: analysis. Category: On-chip & hardware-enabled.
- What the verifier sees: model weights hidden; inputs and outputs hidden; training data hidden. The guarantee processor sees the chip's traffic inside a sealed enclosure and reports only whether rules were kept.


## Properties

**Operational use**

- Proofs of useful work for capacity accounting: Operational use (legacy code R3), assessed for checking matrix-multiplication work proofs for blockchain consensus

**Built for an adversarial prover**

- Proofs of useful work for capacity accounting
- Hardware-enabled guarantees (flexHEG) and guarantee processors

**No new hardware needed**

- Proofs of useful work for capacity accounting


## Attack testing

Attack testing records published testing for this use. It does not by itself show independent review, a formal proof or that a deployed system is secure.

**Testing history**

- Proofs of useful work for capacity accounting / Pearl proof-of-useful-work blockchain: Analysis
- Hardware-enabled guarantees (flexHEG) and guarantee processors: Analysis


## Limits

**Open significant failures**

- State attackers can likely defeat current secure enclosures (known failure, theoretical argument, in Hardware-enabled guarantees (flexHEG) and guarantee processors; https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/evidence/flaws/1/) [8][10]. The flexHEG authors write that "nation-state attackers can likely compromise the best current secure enclosures", and that the marginal cost of circumvention per device is hard to estimate. RAND similarly judges that anti-tamper measures "would not be insurmountable for a determined and well-resourced adversary", although they raise costs and can reveal tampering.
- Firmware-only retrofits rely on Secure Boot, which fault injection can bypass (known failure, theoretical argument, in Hardware-enabled guarantees (flexHEG) and guarantee processors; https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/evidence/flaws/2/) [8]. Part II notes that the most common attack on Secure Boot replaces the firmware and applies a voltage glitch while the signature is being checked. It also notes that sophisticated actors may use microprobing or laser voltage probing to read key registers.
- FLOP accounting can be laundered through external data (known failure, theoretical argument, in Hardware-enabled guarantees (flexHEG) and guarantee processors; https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/evidence/flaws/4/) [8]. Results of earlier or parallel workloads could be hidden in the "external data" fed to a device, which would falsify the total FLOP count unless the inputs are explained or time delays are imposed.

**Family finding context**

- Context for Pearl proof-of-useful-work blockchain. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Proves that work was done, not that no capacity remains (scope limitation, theoretical argument, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/evidence/flaws/1/) [6]. Proof-of-work accounting bounds unmonitored compute only relative to an estimate of what the actor has. Attestable states that the verifier "needs a credible estimate of the compute available" to the actor, and that a proof "cannot discover a datacenter that was never declared".

  Related mechanism: Chip registries and manufacturing records (R1, not in the proposal). A registry of chips is one basis for the estimate of available compute that the flaw's source says the verifier needs.

  Related mechanism: Remote detection of data centres (R1, not in the proposal). Looks for data centres that were never declared, which a proof cannot discover.
- Context for Pearl proof-of-useful-work blockchain. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Security rests on new hardness assumptions (open question, open question, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/evidence/flaws/2/) [2][4]. Komargodski and Weinstein base security on hardness assumptions about batches of low-rank random linear equations, and list PoUW "from more standard or well-studied assumptions" as an open problem. Pearl's floating-point variant introduces a further "quantized-subspace hardness" assumption.
- Context for Pearl proof-of-useful-work blockchain. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Known shortcuts let a miner claim somewhat more work than it did (known failure, theoretical argument, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/evidence/flaws/3/) [2]. Pearl's specification lists known mining speedups: crafted inputs, precision shortcuts, seed grinding, work reuse, and faster kernels or hardware. A policy check caps the summands a miner may skip at one-sixteenth of those in a tile. For capacity bounding, any gap between work proven and work possible leaves spare capacity.

**Open minor failures**

- Known mining speedups reduce work per proof (known failure, theoretical argument, in Pearl proof-of-useful-work blockchain; https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/evidence/flaws/1/) [2]. Pearl lists known speedups: crafted inputs, precision shortcuts, seed or commitment grinding, work reuse, and faster kernels or hardware. Its jackpot policy checks limit crafted inputs, and a policy check caps skippable summands at one-sixteenth of those in a tile. Pearl describes faster honest kernels or hardware as "not an attack on the protocol".

**Scope limitations**

- Verification does not check that mined matrices come from AI workloads (scope limitation, theoretical argument, in Pearl proof-of-useful-work blockchain; https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/evidence/flaws/3/) [4][5]. Miners choose their own matrices. Basu reports that Pearl's verification "does not check whether the matrices originate from an AI model", that random matrices pass it, and that Pearl's reference mining code generates uniformly random matrices, with vLLM inference as an option. String analysis suggests that the dominant third-party mining software contains no inference code. Basu also finds that a naive fixed-threshold check of matrix kurtosis is defeated, at negligible cost, by sampling clipped Gaussian matrices. Basu calls the gap "a design property" rather than a vulnerability. It does not affect the claim that work was performed, but it means the "useful" part of the work is not verified.
- Many important rules cannot be checked on-chip (scope limitation, theoretical argument, in Hardware-enabled guarantees (flexHEG) and guarantee processors; https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/evidence/flaws/3/) [7][9]. Malicious intent "is not a technical property observable on-chip", and misuse depends on what is done with a computation's results. A guarantee processor cannot easily tell whether a network is the whole system or one expert in a mixture-of-experts system. Part III judges that a fully local ruleset "may not be entirely feasible" for the same reason.
- Coverage stops at flexHEG-equipped chips (scope limitation, open question, in Hardware-enabled guarantees (flexHEG) and guarantee processors; https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/evidence/flaws/6/) [7][9]. Motivated actors will always be able to use some compute that is not flexHEG-equipped. Recalling existing consumer GPUs would likely be impractical, and reaching perfect coverage, or conclusively proving that no secret government data centres exist, would be "practically quite difficult".

  Related mechanism: Chip registries and manufacturing records (R1, not in the proposal). Accounts for which chips exist and who holds them.

  Related mechanism: Remote detection of data centres (R1, not in the proposal). Looks for undeclared facilities that hold other chips.

**Open questions**

- Security rests on a new, informal hardness assumption (open question, open question, in Pearl proof-of-useful-work blockchain; https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/evidence/flaws/2/) [2][4]. The FP8 scheme relies on "Assumption 1 (Informal quantized-subspace hardness)": quantised products of noised matrices are assumed not to be substantially easier than generic ones. The integer construction it extends lists PoUW from more standard assumptions as an open problem.
- Supply-chain diversion and hidden backdoors (open question, open question, in Hardware-enabled guarantees (flexHEG) and guarantee processors; https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/evidence/flaws/5/) [8][9]. Components could be diverted before a guarantee processor is added, and backdoors could be introduced during design or manufacturing. Open-source designs and physical scans of randomly selected chips are proposed as countermeasures. Part III proposes international oversight of production and extensive testing of a random sample of finished devices.

  Related mechanism: Chip registries and manufacturing records (R1, not in the proposal). Records each chip's identity and owner from the fab onwards, which bears on diversion before a guarantee processor is fitted. It does not address hidden backdoors.

**Not yet demonstrated**

- Hardware-enabled guarantees (flexHEG) and guarantee processors: Proposed (legacy code R1), assessed for checking and enforcing training-compute limits on chips, against adversaries up to states

**Need new chip designs**

- Hardware-enabled guarantees (flexHEG) and guarantee processors


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open failure or a dependency. Pointers, not recommendations: each brings its own readiness level and findings, and none is claimed to close a failure.

- **Tamper evidence for verifier devices** (Research demonstration (legacy code R2), assessed for detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence)
  - Hardware-enabled guarantees (flexHEG) and guarantee processors waits on it: State-level attackers who hold the hardware can likely compromise the best current secure enclosures.
- **Chip registries and manufacturing records** (Proposed (legacy code R1), assessed for a checkable record of which chips were made and who declared owning them)
  - Hardware-enabled guarantees (flexHEG) and guarantee processors waits on it: Governing all relevant chips depends on knowing where they are, through chip registries and detection of undeclared facilities.
- **Deterministic and bit-exact inference** (Operational use (legacy code R3), assessed for reproducing open-model inference from receipts in Gensyn's information-market service)
  - Proofs of useful work for capacity accounting depends on it.
- **TEE remote attestation for AI workloads** (Operational use (legacy code R3), assessed for showing which software ran to a party that distrusts the operator holding the hardware)
  - Hardware-enabled guarantees (flexHEG) and guarantee processors depends on it.


## Dependencies

**Missing prerequisites**

- Deterministic and bit-exact inference (Operational use (legacy code R3), assessed for reproducing open-model inference from receipts in Gensyn's information-market service), needed by Proofs of useful work for capacity accounting
- TEE remote attestation for AI workloads (Operational use (legacy code R3), assessed for showing which software ran to a party that distrusts the operator holding the hardware), needed by Hardware-enabled guarantees (flexHEG) and guarantee processors
- Chip registries and manufacturing records (Proposed (legacy code R1), assessed for a checkable record of which chips were made and who declared owning them), needed by Hardware-enabled guarantees (flexHEG) and guarantee processors

**Blockers**

- Proofs of useful work for capacity accounting: Built for consensus rather than capacity bounding; verifying that declared hardware has no spare capacity would also need a credible compute estimate. (capacity bounds) [6]
- Proofs of useful work for capacity accounting: Performance figures are provider-reported, and the benchmark reports no baseline of the certified model without mining. (adversarial validation) [3]
- Proofs of useful work for capacity accounting: Bit-exact verification depends on reproducing GPU arithmetic deterministically. (performance & compatibility) [2]
- Hardware-enabled guarantees (flexHEG) and guarantee processors: Integrated flexHEG needs substantial help from the accelerator manufacturer, and the authors estimate 3.7–7.9 years, from when the manufacturer starts work, for such hardware to displace other accelerators in frontier development. (access & governance) [8]
- Hardware-enabled guarantees (flexHEG) and guarantee processors: State-level attackers who hold the hardware can likely compromise the best current secure enclosures. (hardware trust; waits on Tamper evidence for verifier devices) [8][10]
- Hardware-enabled guarantees (flexHEG) and guarantee processors: Rival states would need to trust the design and manufacture of guarantee processors and enclosures, for example through open design, redundant processors from each side or oversight of production. (hardware trust) [7][9]
- Hardware-enabled guarantees (flexHEG) and guarantee processors: Restricting future rule updates would need a formal language for rules, which the authors judge most likely infeasible for early flexHEG versions. (protocol soundness) [7]
- Hardware-enabled guarantees (flexHEG) and guarantee processors: Governing all relevant chips depends on knowing where they are, through chip registries and detection of undeclared facilities. (coverage & hidden compute; waits on Chip registries and manufacturing records) [9]


## What the verifier sees

- Model weights: shown by none; depends on the design for none; hidden by Hardware-enabled guarantees (flexHEG) and guarantee processors; not involved in none; unspecified for Proofs of useful work for capacity accounting.
- Inputs and outputs: shown by none; depends on the design for none; hidden by Hardware-enabled guarantees (flexHEG) and guarantee processors; not involved in none; unspecified for Proofs of useful work for capacity accounting.
- Training data: shown by none; depends on the design for none; hidden by Hardware-enabled guarantees (flexHEG) and guarantee processors; not involved in none; unspecified for Proofs of useful work for capacity accounting.

## Implementations

- Proofs of useful work for capacity accounting: [Pearl proof-of-useful-work blockchain](https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/) (R3, open-source project)
- Hardware-enabled guarantees (flexHEG) and guarantee processors: none on the map

## Sources

1. pearl: Monorepo for the Pearl network, Pearl Research Labs (2026). https://github.com/pearl-research-labs/pearl
2. Pearl Floating Point Scheme Specification, Pearl Research Team (2026). https://pearlresearch.ai/Pearl_Whitepaper.pdf
3. Pearl INT Whitepaper, Pearl Research Labs (2026). https://pearlresearch.ai/research/int-whitepaper
4. Proofs of Useful Work from Arbitrary Matrix Multiplication, I. Komargodski & O. Weinstein (2025). https://arxiv.org/abs/2504.09971
5. The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol, A. Basu (2026). https://arxiv.org/abs/2606.04819
6. Pacing AI Requires Proof, Attestable (2026). https://attestable.com/blog/pacing-ai-requires-proof
7. Flexible Hardware-Enabled Guarantees for AI Compute, J. Petrie et al. (2025). https://arxiv.org/abs/2506.15093
8. Technical Options for Flexible Hardware-Enabled Guarantees, J. Petrie & O. Aarne (2025). https://arxiv.org/abs/2506.03409
9. International Security Applications of Flexible Hardware-Enabled Guarantees, O. Aarne & J. Petrie (2025). https://arxiv.org/abs/2506.15100
10. Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090, G. Kulp et al. (2024). https://www.rand.org/pubs/working_papers/WRA3056-1.html
11. Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing, O. Aarne et al. (2024). https://www.cnas.org/publications/reports/secure-governable-chips
12. Hardware-Enabled Mechanisms for Verifying Responsible AI Development, A. O'Gara et al. (2025). https://arxiv.org/abs/2505.03742
