PySyft double-blind evaluations

R2DemonstratedProvider-reported

OpenMined's PySyft coordinates evaluations in which a model owner keeps its weights from the evaluator and the evaluator keeps its prompts from the model owner.

Both parties check an enclave's attestation, submit code and assets, and approve the code before it runs. In 2026, AVERI evaluated Gemini 2.5 Flash Lite on private MLCommons prompts in Google Cloud Confidential Space using PySyft v0.10.x on an NVIDIA H100 with Intel TDX. Singapore AISI ran a separate private-prompt evaluation.

The participants report end-to-end operation, but not all model code could be inspected or allowlisted. The guest operating system's builds were not independently reproducible, and Google's services signed and verified the attestation. The participant report contains no independent security evaluation of this workflow.

Readinessmedium confidence

A participant report describes an end-to-end evaluation with private assets on commercial GPU hardware; PySyft's double-blind workflow has not been shown as a generally available service.

  • R1 met: the report states the mutual-confidentiality claim, the enclave trust assumptions and the submission and approval procedure 1.
  • R2 met: AVERI evaluated Gemini 2.5 Flash Lite with private MLCommons prompts on an H100 with Intel TDX and PySyft v0.10.x. The report gives the stack and workflow, and states that Singapore AISI ran a separate evaluation with private prompts 1.
  • R3 not met for this implementation: OpenMined documents a pilot with real private assets, but not an available production service or reliance on its result for a verification decision 1 2.
  • R4 not met: the participant report includes no independent public security evaluation of the workflow. Confidence is medium. The demonstration and its limits come from the participants' own report 1.
Rubric assessment

Assessed use: evaluating a private model on private prompts, neither party seeing the other's inputs

Gaps to the next level
  • A generally available production workflow, or documented reliance by another party on its result for a verification decision.
  • An independent public security evaluation that leaves no critical flaw open.

Assessed 2026-09-25 against rubric v1.1.

On this page

What it is

PySyft is OpenMined's software for running approved jobs across private assets 2. In its double-blind evaluation workflow, a model owner and an evaluator submit their assets to a confidential GPU enclave after checking its attestation 1. Neither party receives the other's weights or prompts 1.

How it works

Each party first checks a signed measurement of the enclave software 1. The model owner uploads weights and inference code; the evaluator uploads private prompts and evaluation code. Both review and approve the code before the enclave runs it. PySyft coordinates the submissions and approvals 1.

Evidence

  • In the 2026 pilot, AVERI evaluated Gemini 2.5 Flash Lite on private MLCommons AILuminate prompts in Google Cloud Confidential Space. The instance used one NVIDIA H100 with Intel TDX and PySyft v0.10.x. AVERI staff decrypted and scored the outputs 1.
  • The same report states that Singapore AISI ran a separate evaluation with a private prompt set focused on harmful content in Singapore's context 1.

Limitations

  • The pilot's authors could not inspect or allowlist all model code. AVERI accepted that condition 1.
  • The guest operating system builds were not independently reproducible, and Google's services signed and verified the attestation 1.
  • The published evaluation used one H100. The authors name many-node confidential GPU clusters as a next step 1.

Blockers

Sources

  1. BA. Trask et al. (2026). Double Blind Evals: Resolving the Dual Confidentiality Dilemma in AI Safety Auditing. Google DeepMind. Source recordSupports: procedure, trust boundary, participants, model, private prompts, hardware, results and limits · §2.5; §3; §4
  2. COpenMined Team (2026). PySyft used for first double-blind evaluation of a proprietary, frontier-class AI model. OpenMined. Source recordSupports: OpenMined's description of PySyft and the two 2026 evaluations · Executive Summary

Search

Full search page