Implementation · AI 2040 inference-only verification stack

Technical detail

On this page
  • Secure network gateways. The plan names more capable gateways as a possible replacement for the passive taps. Splitters on the input and output paths log data flow into packets, which are randomly sampled and sent to a secure recomputing server. At boot, the gateways would also check that only whitelisted model weights are uploaded to the inference unit 1.
  • Physical security measures. The plan lists tamper-evident enclosures, security cameras, perimeter controls and air-gapping 1.
  • Other options the plan names. Zero-knowledge proofs could preserve privacy and need less hardware retrofit, but are "currently somewhat speculative" for lack of efficient enough algorithms. Memory-challenge verification might also avoid a hardware retrofit, but "seems likely to face some difficulties with verifying completeness". For an initial phase, removing major scale-out interconnect and installing simple sensors might suffice 1.

Search

Full search page