Mechanism · Confidential multi-party verification

Sources

On this page
  1. BS. Ding et al. (2026). Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: problem statement; framework; three applications; open-source implementation on Intel TDX via dstack · abstract (read via the ICML 2026 virtual poster page; the OpenReview PDF was not reachable)
  2. Bcovehub (2026). Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance (reference implementation). GitHub. Source recordSupports: object model; lifecycle; certificates; trust boundary; residual risks · README; docs/internal/architecture.md; docs/internal/security_model.md
  3. AS. Waiwitlikhit et al. (2024). Trustless Audits without Revealing Data or Models. 41st International Conference on Machine Learning (ICML 2024). Source recordSupports: ZkAudit protocol; models and datasets; accuracy; costs; assumptions; architecture disclosure; data poisoning · abstract; §5; Tables 1-4; limitations
  4. BC. Schnabl et al. (2025). Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments. ICML 2025 Workshop on Technical AI Governance. Source recordSupports: multi-party enclave audit protocol; transparency log; prototype and throughput; CPU versus GPU cost and slowdown; vendor trust · §3; §4; §5; Table 2
  5. BB. Penchas et al. (2026). Enabling Verifiably-Scoped Monitoring through Large Language Models and Trusted Compute. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: plan-scoped monitoring protocol · abstract
  6. CR. Rinberg & B. Penchas (2026). Auditor-in-a-Box: Tools for Third-Party Auditing. LessWrong. Source recordSupports: plan definition; reference implementation; process problems; limitations · whole post
  7. BS. Abdelghafar & G. Kulp (2026). Privacy-Preserving AI Verification via Minimal Information Disclosure. arXiv. Source recordSupports: minimal information disclosure framework; one-bit leakage findings; Groth16 variant; limitations · abstract; introduction; Appendix A; Figure 5; limitations
  8. CGloria Z (2026). On TEEs for Privacy-Preserving Monitoring in AI Governance. MIRI Technical Governance Team. Source recordSupports: completeness and second-CVM gap; vendor root of trust; GPU TEE maturity; multi-GPU inference; treaty threat model · resource accounting; hardware auditability; physical attack surface
  9. BA. Trask et al. (2026). Double Blind Evals: Resolving the Dual Confidentiality Dilemma in AI Safety Auditing. Google DeepMind. Source recordSupports: double-blind evaluation pilot: participants, model, benchmark, GCP Confidential Space on H100 with Intel TDX, PySyft, mutual attestation checks, overhead figure cited from NVIDIA, uninspected model code, Google in the verification path, scaling to many-node clusters · abstract; architecture; limitations; future work
  10. CA. Tlaie Boria (2026). Confidential computing can enable better frontier AI auditing. Pour Demain. Source recordSupports: Pour Demain's interpretability evaluations of GLM-5.1 on Tinfoil (Intel TDX, eight H200 GPUs): enclave-bound tensors, bounded signed exports, overheads, single-session governance · whole post
  11. BGoogle Cloud (2026). Confidential Space overview. Google Cloud documentation. Source recordSupports: Confidential Space: multi-party roles; data released only to attested workloads; operator has no access; supported TEEs · overview
  12. BGoogle Cloud (2026). Confidential Space release notes. Google Cloud documentation. Source recordSupports: Confidential Space generally available, including on H100 GPUs from 2026-04-29 · release notes, 2023-03-28 and 2026-04-29
  13. AJ. De Meulemeester et al. (2026). DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes. 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26). Source recordSupports: DDRop forges attestation reports on an up-to-date Intel TDX platform with an active DDR5 interposer · site summary
  14. AJ. Chuang et al. (2026). TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition. 2026 IEEE Symposium on Security and Privacy (SP). Source recordSupports: physical extraction of Intel attestation keys and SEV-SNP signing keys; forged attestations against NVIDIA GPU confidential computing; vendor acknowledgement and positions · project site summary; paper abstract and disclosure
  15. AJ. De Meulemeester et al. (2026). Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing. 47th IEEE Symposium on Security and Privacy (S&P 2026). Source recordSupports: Battering RAM forges SEV-SNP attestation with a DDR4 interposer
  16. AB. Schlüter & S. Shinde (2025). RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP. 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Source recordSupports: RMPocalypse forges SEV-SNP attestation from a malicious hypervisor
  17. BAMD (2025). SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020). AMD product security bulletin. Source recordSupports: AMD firmware fixes for RMPocalypse (CVE-2025-0033)

Search

Full search page