Implementation · Tinfoil model identity (Modelwrap)

Sources

On this page
  1. CTinfoil Team (2026). How Tinfoil Proves Exactly What Model Is Running. Tinfoil. Source recordSupports: Modelwrap design, binding to kernel command line, runtime enforcement, private models, overheads (provider-reported)
  2. BTinfoil (2026). A primer on secure enclaves. Tinfoil documentation. Source recordSupports: supported hardware, trust model, documented limitations (provider-reported) · Supported hardware; Trust model; Limitations
  3. BTinfoil (2026). Backend infrastructure. Tinfoil documentation. Source recordSupports: boot measurement chain, boot-time GPU attestation check linked to the CPU attestation report, Sigstore publication, client verification, closed-source components (provider-reported)
  4. BTinfoil (2026). How verification works in Tinfoil. Tinfoil documentation. Source recordSupports: connection-time vs audit-time verification; production deployment; no supported audit tool (provider-reported) · In-band vs. out-of-band verification
  5. BTinfoil (2026). modelwrap: Reproducible dm-verity read-only image of Huggingface models. GitHub. Source recordSupports: open-source code, MIT license, release v0.3.0, outputs and encryption mode
  6. AJ. Chuang et al. (2026). TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition. 2026 IEEE Symposium on Security and Privacy (SP). Source recordSupports: independent demonstration of Intel TDX attestation forgery, SEV-SNP OpenSSL key recovery and H100 attestation relay · §1.1, §8.3, §10.2
  7. AJ. De Meulemeester et al. (2026). Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing. 47th IEEE Symposium on Security and Privacy (S&P 2026). Source recordSupports: SEV-SNP attestation breach with a DDR4 interposer (Battering RAM) · Abstract; site FAQ
  8. AB. Schlüter & S. Shinde (2025). RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP. 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Source recordSupports: software-only SEV-SNP attestation forgery by a malicious hypervisor (RMPocalypse) · Abstract; site
  9. BAMD (2025). SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020). AMD product security bulletin. Source recordSupports: AMD firmware fixes for RMPocalypse (vendor-reported) · Mitigation tables

Search

Full search page