Mechanism · Safeguard attestation

Components outside the attested boundary

On this page

← All known flaws

SignificantTheoretical argumentOpen

In the proof-of-guardrail experiments, the guardrail model and the agent's backend model were both reached through external APIs, and the authors leave the decision to trust those APIs to the verifier. The measured wrapper must also have no vulnerability that lets the unmeasured agent bypass the guardrail, for example by executing arbitrary commands inside the enclave. The code's README states that the enclave does not currently restrict the agent's arbitrary command execution, which could be used to bypass guardrails.

Sources: [1] · [2]

Search

Full search page