Mechanism · Whole-workload recomputation (reproducible packets)

Evidence & limits

On this page

R1Proposed for recomputing whole workloads to show a cluster runs only declared inference

The design, its claim and its assumptions are public, but no implementation of whole-workload packets has been built.

Assessed use: recomputing whole workloads to show a cluster runs only declared inference

Rubric assessment

  • R1 met: the AI 2040 verification plan describes the design (discrete, reproducible packets visible to a recomputation server, with random partial recomputation), the claim it serves (correct outputs in an inference-only regime, later R&D verification) and its assumptions (reproducibility, an intact recomputation server, physical security) 1. Amodo gives a comparable written design at the level of single training steps 2. The plan is the only Implementation record for this mechanism (AI 2040 inference-only verification stack, assessed R1).
  • R2 not met: no public implementation or end-to-end result organizes whole workloads into reproducible packets. The nearest demonstrations recompute single inference requests 3 or, in proof-of-learning, selected training steps (Training-transcript verification (proof-of-learning)) 6. The plan's companion page lists a reproducible inference stack and network reproducibility as not started 5, and Amodo rates network reproducibility "not on track" 4.

Confidence is medium. The design is described only at a high level, but the plan's authors and Amodo both list the reproducible inference stack it needs as not started 4 5.

Gaps to the next level
  • A public implementation, or reproducible end-to-end results, of packet-based recomputation beyond single inference requests, under realistic model scale, hardware or a stated adversary.

Assessed 2026-09-25 against rubric v1.1.

Evidence

  • Whole-workload packets. As of September 2026, no implementation or end-to-end result of organizing whole workloads into reproducible packets has been published.
  • Inference recomputation. Amodo reports demonstrations of inference recomputation systems that work around nondeterminism 4, including its own single-request prototype 3.
  • Training-step recomputation. In proof-of-learning, a separate line of work, the verifier reproduces a subset of training updates and accepts each one within a noise threshold 6.
  • Reproducibility status. Amodo rates a reproducible inference stack as not started 4. It rates network reproducibility as not on track, because optimizations throughout the networking stack mean that network packets are not individually reproducible by default 4. It suggests schemes that do not need exact packet replication as a possible alternative 4. The plan's own companion page, updated in July 2026, lists both items as not started 5.

Limitations

  • Reproducibility cost. Making inference reproducible "may involve some cost overhead" 1. For training, writing a checkpoint at every step would cost more than 100% overhead, which Amodo's design avoids by keeping a spare replica 2.
  • Hidden work. The plan notes that a company might try to encode a non-compliant workload inside one that looks compliant 1. Work outside declared packets, including on spare compute, is not covered 1 2.
  • Tolerance. Amodo's training-step design accepts a recomputed step within a calibrated tolerance 2. In proof-of-learning, published spoofs exploit the tolerance that verification must allow for hardware noise 6.
  • Dependencies. The scheme relies on deterministic execution (Deterministic and bit-exact inference), complete traffic capture (Network taps and certifiers) and a secure recomputation server 1.

Known flaws

Blockers

Search

Full search page