Implementation · TOPLOC

Evidence & limits

On this page

R3In production for checking that untrusted providers used the claimed model, prompt and precision

Prime Intellect, its developer, has used the public package in production to accept or reject work from untrusted computers, but no independent security audit or red-team has been published.

Assessed use: checking that untrusted providers used the claimed model, prompt and precision

Rubric assessment

  • R1 met: the peer-reviewed paper sets out the design, the claim and the threat 1. The claim is that the provider used the stated model, prompt and precision. The threat is undisclosed changes to any of them.
  • R2 met: a public MIT-licensed implementation exists 2. The paper reports results on A100 and RTX 4090 GPUs across several models, attention implementations and one- and two-GPU tensor parallelism 1.
  • R3 met through the developer's own use: the package is public 2, and Prime Intellect reports using it in production to accept or reject work from untrusted inference workers, in a 32-billion-parameter decentralized training run and a data-generation run on 1,253 GPUs 4 6. The latest documented use is the data-generation run, whose results Prime Intellect released in July 2025 6. No other party is documented relying on TOPLOC for a verification decision.
  • R4 not met: no independent audit, red-team or peer-reviewed security analysis has been published. DiFR's comparison measures detection accuracy against communication cost 7. It is not a security evaluation.

Confidence is low: the production use is the developer's own, and none is documented after July 2025. The package has had no release since April 2025 2.

Gaps to the next level
  • An independent public security evaluation, such as an audit, red-team or peer-reviewed analysis, that tests adaptive attacks like the spoofing and speculative-decoding cases the TOPLOC authors list.

Assessed 2026-09-25 against rubric v1.1.

Evidence

  • The TOPLOC paper reports detecting unauthorized changes to models, prompts or precision with 100% accuracy, and no false positives or negatives in its evaluations 1. The tests used Llama 3.1-8B-Instruct, INTELLECT-1-Instruct and Gemma-2-9B on UltraChat prompts. A model-differentiation test also included Llama 3.1-70B-Instruct 1. Proofs take 258 bytes per 32 new tokens 1.
  • Validation held across A100 and RTX 4090 GPUs, one- and two-GPU tensor parallelism, and three attention implementations 1.
  • Prime Intellect reports using TOPLOC to verify rollouts from untrusted inference workers when training a 32-billion-parameter model 4. Nodes whose files fail validation are "slashed and evicted" 4. Prime Intellect reports that TOPLOC v2 checked the inference workers in SYNTHETIC-2, a distributed data-generation run on 1,253 GPUs, with a false-positive rate of 0.000925% (37 slashes) over 4 million samples 6.
  • The authors of DiFR, a related scheme, report that Activation-DiFR Pareto-dominates TOPLOC (does at least as well on both communication cost and detection accuracy) when detecting FP8 KV-cache quantization in their tests 7.
  • Amodo Design's status page lists TOPLOC among initial recomputation schemes now being tested on relevant hardware and models 10.

Limitations

The TOPLOC paper lists five limitations 1:

  • The margin separating fp8 from bf16 generation is small, and the authors did not test KV-cache compression.
  • The method cannot detect speculative decoding in which a cheaper model does the decoding.
  • Inference consumers could mine for "unstable" prompts that tend to fail validation.
  • An attacker could spoof last-layer activations by pruning intermediate layers or using a smaller model.
  • Subtle modifications are harder to detect than large ones.

The original method checks activations, not token sampling 1. Prime Intellect reports that TOPLOC v2 adds sampling checks, described so far only in its blog posts 5 6.

TOPLOC accepts approximate matches, so it shares the general limit of statistical schemes. It can bound an adversary's covert freedom but cannot eliminate it 9.

No independent red-team or audit has been published. All deployment evidence comes from the developer 4 5 6.

Known flaws

Blockers

  • No independent security evaluation has been published, and Amodo Design rates red-teaming of recomputation schemes as 'not started'.

  • The verifier must run the model itself, which suits the paper's setting of providers serving open-weights models.

Search

Full search page