Implementation · Tinfoil model identity (Modelwrap)
Evidence & limits
On this page
R3In production for showing clients that the served weights match a committed hash
ReadinessMedium confidence
Tinfoil reports running the chain in its production service, but almost all the evidence comes from Tinfoil, no independent evaluation exists, and the underlying TEEs have open critical flaws.
Assessed use: showing clients that the served weights match a committed hash
Rubric assessment
- R1 met: the design is published 1.
- R2 met: a public working implementation under an MIT license 5 is deployed on realistic hardware, AMD SEV-SNP or Intel TDX with NVIDIA H100, H200 or B200 (provider-reported) 2. Build results are reported for models of up to 554 GB 1.
- R3 met on the provider's own account, as a production service that clients can use. Tinfoil reports serving each model from multiple enclaves in its production deployment, with client SDKs that verify the attestation before sending any data 4. The enclave checks model volumes against Modelwrap commitments at boot 3.
- R4 not met. As of September 2026 no independent audit, red-team or peer-reviewed analysis of Modelwrap or Tinfoil's model-identity chain has been published. Independent research on the underlying TEEs used physical access to forge Intel TDX attestations and, by pairing them with relayed H100 attestations, passed a workload outside TEE protection 6. Other independent research forged AMD SEV-SNP attestations 7 8. Tinfoil's documentation acknowledges physical attacks 2.
Gaps to the next level
- An independent security evaluation of Modelwrap and the attestation chain that leaves no critical flaw open.
- A supported tool for audit-time verification from transparency records.
- A way for third parties to learn something about private models beyond consistency across requests.
Assessed 2026-09-25 against rubric v1.1.
Evidence
- Tinfoil reports that the hash tree adds about 0.8% to storage and that builds take 5 s for a 549 MB model and 13 min 25 s for a 554 GB model. Cold-cache loading takes about 80% longer with verification, but inference runs at full speed once the weights are in GPU memory 1.
- Modelwrap is public under an MIT license, and v0.3.0 was the latest release in September 2026 5.
- Tinfoil reports serving each model from multiple enclaves in its production deployment 4. Its attestation architecture checks model volumes against Modelwrap commitments at boot 3.
Limitations
Tinfoil documents several limitations of enclaves 2:
- an attacker with physical access "can potentially compromise the enclave", with demonstrated attestation forgery for Intel TDX and key extraction for AMD SEV-SNP;
- timing, power and electromagnetic side channels;
- host observation of access patterns and I/O;
- denial of service, supply-chain compromise and rollback.
Other limits:
- Independent researchers report that NVIDIA does not bind the H100 to the identities of specific VMs. By pairing relayed H100 attestations with forged TDX attestations, they made a system running outside TEE protection pass both checks 6. Tinfoil reports that its GPU check runs inside the enclave at boot and is linked to the CPU attestation report 3.
- For private models, clients learn only that the same weights are served each time 1.
- For audit-time checks of its transparency records, Tinfoil "does not provide a supported tool for querying these records", and it notes that rebuilding binaries to check measurements independently is expensive 4.
Known flaws
Blockers
The underlying TEE attestation does not resist attackers with physical access to the host.
No independent evaluation of the model-identity chain has been published.