Mechanism · Model identity attestation
Sources
On this page
- CTinfoil Team (2026). How Tinfoil Proves Exactly What Model Is Running. Tinfoil. Source recordSupports: Modelwrap design, launch-state problem, signing comparison, private models, overheads (provider-reported) · sections on the challenge, the three phases, performance, private models
- BP. Chantasantitam et al. (2026). PAL*M: Property Attestation for Large Generative Models. arXiv. Source recordSupports: inference attestation binding hashes to TDX report; overheads · §4, Table 6
- BC. Schnabl et al. (2025). Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments. ICML 2025 Workshop on Technical AI Governance. Source recordSupports: audit-to-inference model-hash binding; prototype evaluation of the audit step · §3, Algorithms 1-3, §5
- BR. Rinberg et al. (2025). Verifying LLM Inference to Detect Model Weight Exfiltration. arXiv. Source recordSupports: recomputation-based verification, assumptions, results, limitations, code · Abstract; §1, §3.3-3.4, §4.2, §5-§7
- BN. Kezins (2026). Adversarial Entropy Inflation Against Gumbel-Based Inference Verification. arXiv. Source recordSupports: independent prompt-control attack that widens the exfiltration bound; 0.119 to 0.286 bits per token on the 30B MoE model · Abstract; Table 1
- CGloria Z (2026). On TEEs for Privacy-Preserving Monitoring in AI Governance. MIRI Technical Governance Team. Source recordSupports: measurement incompleteness; hashing-scheme warning
- CTrail of Bits (2026). What we learned about TEE security from auditing WhatsApp's Private Inference. Trail of Bits blog. Source recordSupports: Trail of Bits audit of WhatsApp Private Processing: environment variables loaded after the measurement (TOB-WAPI-13) and Meta's fix
- BTrail of Bits (2025). Meta WhatsApp Private Processing (security review). Trail of Bits publications library. Source recordSupports: the review's finding that CVMs could be compromised through environment-variable injection
- AJ. Chuang et al. (2026). TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition. 2026 IEEE Symposium on Security and Privacy (SP). Source recordSupports: Intel TDX attestation forgery and H100 attestation relay to a vLLM proxy outside TEE protection · Abstract; §1.1, §8.3
- AJ. De Meulemeester et al. (2026). Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing. 47th IEEE Symposium on Security and Privacy (S&P 2026). Source recordSupports: SEV-SNP attestation breach with a DDR4 interposer (Battering RAM) · Abstract; site FAQ
- AB. Schlüter & S. Shinde (2025). RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP. 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Source recordSupports: software-only SEV-SNP attestation forgery by a malicious hypervisor (RMPocalypse) · Abstract; site
- BAMD (2025). SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020). AMD product security bulletin. Source recordSupports: AMD firmware fixes for RMPocalypse (vendor-reported) · Mitigation tables
- BTinfoil (2026). A primer on secure enclaves. Tinfoil documentation. Source recordSupports: Tinfoil hardware, trust model and documented limitations (provider-reported)
- BTinfoil (2026). Backend infrastructure. Tinfoil documentation. Source recordSupports: measured boot chain, Sigstore publication, production model volumes (provider-reported)
- BTinfoil (2026). How verification works in Tinfoil. Tinfoil documentation. Source recordSupports: production deployment; no supported audit-time tool (provider-reported) · In-band vs. out-of-band verification
- BTinfoil (2026). modelwrap: Reproducible dm-verity read-only image of Huggingface models. GitHub. Source recordSupports: open-source implementation, release v0.3.0
- CApple Security Engineering and Architecture (SEAR) (2024). Private Cloud Compute: A new frontier for AI privacy in the cloud. Apple Security Research blog. Source recordSupports: Apple PCC: integrity protection of code and model assets; attestation against a public transparency log (provider-reported)
- CO. Ersoy (2025). Verde Verification System In Production. Gensyn research blog. Source recordSupports: Gensyn's statement that Verde shows outputs came from the declared model and data (provider-reported)
- BA. Arun et al. (2025). Verde: Verification via Refereed Delegation for Machine Learning Programs. arXiv. Source recordSupports: Verde's guarantee holds if at least one compute provider is honest · Abstract