Mechanism · Model identity attestation

Evidence & limits

On this page

R3In production for showing users that a service runs the declared model weights

Tinfoil reports running the enclave route in a production service, but the independent attacks published so far left flaws open, including a critical flaw in the trusted execution environments that route relies on.

Assessed use: showing users that a service runs the declared model weights

Rubric assessment

  • R1 met: designs and assumptions are published for both routes 1 2 4.
  • R2 met through Tinfoil's Modelwrap chain. Its code is open source 16, it runs on NVIDIA H100, H200 or B200 GPUs with AMD SEV-SNP or Intel TDX (provider-reported) 13, and it has been reported on models of up to 554 GB 1. Rinberg et al. publish code and results on models from 3B to 30B parameters 4.
  • R3 met on the provider's account: Tinfoil reports offering the feature in a production service 14 15.
  • R4 not met, because the independent evaluations that exist left flaws open. TEE.fail used physical access to forge the Intel TDX attestation that the enclave route relies on. By pairing the forgeries with relayed H100 attestations, it made a vLLM proxy running outside TEE protection pass both the TDX and the NVIDIA confidential-computing checks 9. That flaw is critical and open. Kezins, at Delft University of Technology, attacked the exfiltration bound of Rinberg et al.'s recomputation check with chosen prompts. On a 30B mixture-of-experts model this raised leakage from 0.119 to 0.286 bits per token. The attack widens the covert channel and does not target the check that outputs match the declared model 5.
Gaps to the next level
  • Independent security evaluation of a deployed model-identity scheme that leaves no critical flaw open.
  • Resistance of the enclave variant to physical attackers (see TEE remote attestation for AI workloads).
  • Third-party verification for private models beyond consistency across requests.
  • Tooling for audit-time checking of transparency records.

Assessed 2026-09-25 against rubric v1.1.

Mechanism properties

Threat modelSemi-trusted prover
Adversarial evaluationIndependent red-team
Hardware neededExisting features
Prover cooperationRequired
ConfidentialityPartial

Evidence

  • Tinfoil. Modelwrap is published under an MIT license 16. Tinfoil reports a storage overhead of 0.8%, build times of up to 13 min 25 s for a 554 GB model, and slower cold loading but no inference slowdown 1.
  • PAL*M. It reports inference attestation on an H100 across three models of 3.8 to 8 billion parameters. Its added time was 3.8–11.4% of total run time in multi-turn sessions and 45.5–66.4% for single prompts. The authors plan to release the code after peer review 2.
  • Attestable Audits. Its protocol binds inference to the audited model hash. The reported evaluation covers the audit step, for a 4-bit Llama-3.1-8B on CPU-only AWS Nitro Enclaves 3.
  • Rinberg et al. They tested Llama-3.1-8B, Llama-3.2-3B and two Qwen mixture-of-experts models, and publish their code. On the 30B model under benign prompt traffic, the detector cut exfiltratable information to under 0.5% at a false-positive rate under 0.01% 4. An independent study found that prompt control roughly doubles leakage per token 5.
  • Apple Private Cloud Compute. Apple reports that devices send requests only to servers that attest to software in a public transparency log, and that model assets share the code's integrity protection 17.
  • Verde. Gensyn reports that its refereed-delegation system shows a delegated output came from the declared model and data, by re-running disputed operations with bitwise-reproducible kernels 18. The guarantee holds if at least one of the compute providers is honest 19.

Limitations

  • Inherited TEE attacks. Using physical access, TEE.fail forged Intel TDX attestations and, by pairing them with relayed H100 attestations, passed a workload outside TEE protection 9. Battering RAM and RMPocalypse forged AMD SEV-SNP attestations, the second without physical access 10 11. Tinfoil's documentation acknowledges physical-access and side-channel risks 13.
  • Audit-time checking. Tinfoil does not provide a supported tool for querying its transparency records at audit time 15.
  • Recomputation slack. Nondeterminism concentrates at a few token positions, and very slow leaks remain possible 4. An adversary who controls prompts widens the leak 5.
  • Recomputation dependencies. The check depends on complete and trusted logging, and on the verifier holding the weights 4.

Known flaws

Blockers

Search

Full search page