PAL*M
PAL*M is a property-attestation prototype for generative models.
It measures inputs and outputs of training, fine-tuning, evaluation and inference operations inside an Intel TDX confidential virtual machine with an NVIDIA H100. Incremental multiset hashing tracks datasets accessed from untrusted storage in random order. The authors report evaluations on 3.8–8-billion-parameter language models and training on a 124-million-parameter GPT-2.
Evaluation overhead varies with the operation and dataset access strategy. On MMLU, overhead was 0.93–2.46% of total instrumented runtime with in-memory data and 7.69–11.24% with memory-mapped data. The comparison uses the same confidential environment without PAL*M measurements.
The protocol has a symbolic Tamarin analysis. The design trusts Intel and NVIDIA hardware, excludes physical and side-channel attacks, and plans code release after peer review 1.
Published end-to-end experiments specify operations, models, datasets and commercial hardware.
- R1 met: the paper defines measured properties, the attestation protocol and the host adversary 1.
- R2 met through reproducible published results on Intel TDX and an H100, including training, fine-tuning, evaluation and inference. The code is planned for release after peer review 1.
- R3 not met: the paper describes a research prototype and does not document a production service or another party's reliance on its attestations 1.
Assessed use: attesting declared model operations on a confidential CPU–GPU prototype
On this page
What it is
PAL*M is a prototype for attesting properties of generative-model operations, including training, fine-tuning, evaluation and inference 1. It extends TEE remote attestation to measurements of the operation's inputs and outputs. Inference evidence also implements model identity attestation 1.
How it works
An initiator requests an operation and supplies its inputs and an optional freshness challenge. PAL*M loads and measures those inputs inside an Intel TDX confidential virtual machine, runs the operation with an attested NVIDIA H100, and measures its outputs 1. It puts the measurements into the TDX report data and returns a quote for verification against trusted reference values and vendor roots 1.
Datasets can remain in untrusted storage. For memory-mapped data accessed in random order, incremental multiset hashing accumulates measurements without depending on the order of access 1. Evaluation evidence includes the model, tokenizer, test dataset and resulting metric. Inference evidence includes the query and output, and session evidence extends across a sequence of interactions 1.