# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-09. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0022,M-0007&implementations=M-0007:I-0004

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's development status, security evidence and findings. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and findings) and https://trustbutveri.fyi/about/readiness/ (development status).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Overview

One row per mechanism, read from its record. Open failures: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees. Findings are grouped as known failures, scope limitations and open questions. Only known failures count as failures. Counts are an inventory of published findings, not a risk score.

| Mechanism | Development | Security evidence | Prover | Attack testing | Hardware | Open failures | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Side-channel suppression for isolated facilities | Proposed | Published security analysis | Adversarial | Analysis | Retrofit device | 0 / 0 / 0 | not involved | not involved | not involved |
| Proofs of useful work for capacity accounting / Pearl proof-of-useful-work blockchain | Operational use | Published security analysis | Adversarial | Analysis | None | 0 / 0 / 1 | unspecified | unspecified | unspecified |

## Claims

No claims chosen.

## Mechanisms

### Side-channel suppression for isolated facilities

Shielding, filtering, jamming and inspecting an AI facility to limit hidden physical communication around monitored network links. ([Side-channel suppression for isolated facilities](https://trustbutveri.fyi/mechanisms/side-channel-suppression/))

- Assessment: mechanism family.
- Development: Proposed (legacy code R1), assessed for bounding physical covert channels out of a verified enclosure.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: retrofit device. Prover cooperation: partial. Attack testing: analysis. Category: Off-chip devices & sensors.
- What the verifier sees: model weights not involved; inputs and outputs not involved; training data not involved. Shields and filters a facility; it does not handle model data.

### Proofs of useful work for capacity accounting

A blockchain whose mining is designed to be a by-product of GPU matrix multiplications in AI workloads, with public node and miner code. ([Proofs of useful work for capacity accounting](https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/))

- Assessment: selected implementation [Pearl proof-of-useful-work blockchain](https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/).
- Development: Operational use (legacy code R3), assessed for checking matrix-multiplication work proofs for blockchain consensus.
- Security evidence: Published security analysis. Independent evaluation: unassessed. Formal proof: unassessed. Deployment assurance: unassessed.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights unspecified; inputs and outputs unspecified; training data unspecified. This Explorer has no asset-specific exposure assessment for this implementation. Check its source and deployment assumptions.


## Properties

**Operational use**

- Proofs of useful work for capacity accounting: Operational use (legacy code R3), assessed for checking matrix-multiplication work proofs for blockchain consensus

**Built for an adversarial prover**

- Side-channel suppression for isolated facilities
- Proofs of useful work for capacity accounting

**No new hardware needed**

- Proofs of useful work for capacity accounting


## Attack testing

Attack testing records published testing for this use. It does not by itself show independent review, a formal proof or that a deployed system is secure.

**Testing history**

- Side-channel suppression for isolated facilities: Analysis
- Proofs of useful work for capacity accounting / Pearl proof-of-useful-work blockchain: Analysis


## Limits

**Family finding context**

- Context for Pearl proof-of-useful-work blockchain. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Proves that work was done, not that no capacity remains (scope limitation, theoretical argument, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/evidence/flaws/1/) [7]. Proof-of-work accounting bounds unmonitored compute only relative to an estimate of what the actor has. Attestable states that the verifier "needs a credible estimate of the compute available" to the actor, and that a proof "cannot discover a datacenter that was never declared".

  Related mechanism: Chip registries and manufacturing records (R1, not in the proposal). A registry of chips is one basis for the estimate of available compute that the flaw's source says the verifier needs.

  Related mechanism: Remote detection of data centres (R1, not in the proposal). Looks for data centres that were never declared, which a proof cannot discover.
- Context for Pearl proof-of-useful-work blockchain. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Security rests on new hardness assumptions (open question, open question, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/evidence/flaws/2/) [3][5]. Komargodski and Weinstein base security on hardness assumptions about batches of low-rank random linear equations, and list PoUW "from more standard or well-studied assumptions" as an open problem. Pearl's floating-point variant introduces a further "quantized-subspace hardness" assumption.
- Context for Pearl proof-of-useful-work blockchain. Findings from the mechanism family appear here as context. They apply to an implementation only when its own record lists them, under the conditions stated there. Known shortcuts let a miner claim somewhat more work than it did (known failure, theoretical argument, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/evidence/flaws/3/) [3]. Pearl's specification lists known mining speedups: crafted inputs, precision shortcuts, seed grinding, work reuse, and faster kernels or hardware. A policy check caps the summands a miner may skip at one-sixteenth of those in a tile. For capacity bounding, any gap between work proven and work possible leaves spare capacity.

**Open minor failures**

- Known mining speedups reduce work per proof (known failure, theoretical argument, in Pearl proof-of-useful-work blockchain; https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/evidence/flaws/1/) [3]. Pearl lists known speedups: crafted inputs, precision shortcuts, seed or commitment grinding, work reuse, and faster kernels or hardware. Its jackpot policy checks limit crafted inputs, and a policy check caps skippable summands at one-sixteenth of those in a tile. Pearl describes faster honest kernels or hardware as "not an attack on the protocol".

**Scope limitations**

- Openings for airflow, power and optics weaken shielding (scope limitation, theoretical argument, in Side-channel suppression for isolated facilities; https://trustbutveri.fyi/mechanisms/side-channel-suppression/evidence/flaws/2/) [1]. Cankaya notes that keeping attenuation high while passing high-power airflow, cabling and optical links adds complexity beyond existing shielded-enclosure specifications.
- Verification does not check that mined matrices come from AI workloads (scope limitation, theoretical argument, in Pearl proof-of-useful-work blockchain; https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/evidence/flaws/3/) [5][6]. Miners choose their own matrices. Basu reports that Pearl's verification "does not check whether the matrices originate from an AI model", that random matrices pass it, and that Pearl's reference mining code generates uniformly random matrices, with vLLM inference as an option. String analysis suggests that the dominant third-party mining software contains no inference code. Basu also finds that a naive fixed-threshold check of matrix kurtosis is defeated, at negligible cost, by sampling clipped Gaussian matrices. Basu calls the gap "a design property" rather than a vulnerability. It does not affect the claim that work was performed, but it means the "useful" part of the work is not verified.

**Open questions**

- Supply-chain implants may evade inspection (open question, theoretical argument, in Side-channel suppression for isolated facilities; https://trustbutveri.fyi/mechanisms/side-channel-suppression/evidence/flaws/1/) [1]. Cankaya identifies malicious hardware embedded deep in purchased components as a residual risk that visual inspection and disassembly may not catch. He notes that radiographic examination under high-security standards could mitigate it.
- Inspection assumptions may not hold (open question, open question, in Side-channel suppression for isolated facilities; https://trustbutveri.fyi/mechanisms/side-channel-suppression/evidence/flaws/3/) [1]. The design's statistical argument assumes that visual or disassembly inspection catches every flaw that is present in a sampled unit. Cankaya is unsure whether destructive teardowns are defence-dominant or offence-dominant.
- Security rests on a new, informal hardness assumption (open question, open question, in Pearl proof-of-useful-work blockchain; https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/evidence/flaws/2/) [3][5]. The FP8 scheme relies on "Assumption 1 (Informal quantized-subspace hardness)": quantised products of noised matrices are assumed not to be substantially easier than generic ones. The integer construction it extends lists PoUW from more standard assumptions as an open problem.

**Not yet demonstrated**

- Side-channel suppression for isolated facilities: Proposed (legacy code R1), assessed for bounding physical covert channels out of a verified enclosure


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open failure or a dependency. Pointers, not recommendations: each brings its own readiness level and findings, and none is claimed to close a failure.

- **Deterministic and bit-exact inference** (Operational use (legacy code R3), assessed for reproducing open-model inference from receipts in Gensyn's information-market service)
  - Proofs of useful work for capacity accounting depends on it.


## Dependencies

**Missing prerequisites**

- Deterministic and bit-exact inference (Operational use (legacy code R3), assessed for reproducing open-model inference from receipts in Gensyn's information-market service), needed by Proofs of useful work for capacity accounting

**Blockers**

- Side-channel suppression for isolated facilities: No prototype or red-team exists; the design is a first-pass viability study. (adversarial validation) [1]
- Side-channel suppression for isolated facilities: Volume costs of TEMPEST-grade power-line filters are uncertain, because existing products are mostly made to order. (performance & compatibility) [1]
- Proofs of useful work for capacity accounting: Built for consensus rather than capacity bounding; verifying that declared hardware has no spare capacity would also need a credible compute estimate. (capacity bounds) [7]
- Proofs of useful work for capacity accounting: Performance figures are provider-reported, and the benchmark reports no baseline of the certified model without mining. (adversarial validation) [4]
- Proofs of useful work for capacity accounting: Bit-exact verification depends on reproducing GPU arithmetic deterministically. (performance & compatibility) [3]


## What the verifier sees

- Model weights: shown by none; depends on the design for none; hidden by none; not involved in Side-channel suppression for isolated facilities; unspecified for Proofs of useful work for capacity accounting.
- Inputs and outputs: shown by none; depends on the design for none; hidden by none; not involved in Side-channel suppression for isolated facilities; unspecified for Proofs of useful work for capacity accounting.
- Training data: shown by none; depends on the design for none; hidden by none; not involved in Side-channel suppression for isolated facilities; unspecified for Proofs of useful work for capacity accounting.

## Implementations

- Side-channel suppression for isolated facilities: [AI 2040 inference-only verification stack](https://trustbutveri.fyi/implementations/ai-2040-inference-only-verification-plan/) (R1, proposed architecture); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [RAND secure inference data center (SIDC) design](https://trustbutveri.fyi/implementations/rand-secure-inference-data-centers/) (R1, proposed architecture)
- Proofs of useful work for capacity accounting: [Pearl proof-of-useful-work blockchain](https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/) (R3, open-source project)

## Sources

1. Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses, N. Cankaya (2026). https://techgov.intelligence.org/blog/suppressing-side-channels-in-an-untrusted-data-center-via-retrofitted-defenses
2. pearl: Monorepo for the Pearl network, Pearl Research Labs (2026). https://github.com/pearl-research-labs/pearl
3. Pearl Floating Point Scheme Specification, Pearl Research Team (2026). https://pearlresearch.ai/Pearl_Whitepaper.pdf
4. Pearl INT Whitepaper, Pearl Research Labs (2026). https://pearlresearch.ai/research/int-whitepaper
5. Proofs of Useful Work from Arbitrary Matrix Multiplication, I. Komargodski & O. Weinstein (2025). https://arxiv.org/abs/2504.09971
6. The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol, A. Basu (2026). https://arxiv.org/abs/2606.04819
7. Pacing AI Requires Proof, Attestable (2026). https://attestable.com/blog/pacing-ai-requires-proof
