Bibliography
Sources
The bibliography: 182 public sources, 171 of them cited by at least one record. Tier A is peer-reviewed work, standards and government publications; tier B is preprints, reports, documentation and code; tier C is expert blogs and talks. See the citation policy.
Seeded from Will Hodgkins' AI Workload Verification Papers bibliography (CC BY 4.0), which builds on earlier reading lists by Mauricio Baker and James Petrie.
| Title | Year | Tier | Type | Cited by |
|---|---|---|---|---|
| A primer on secure enclaves Tinfoil · Tinfoil documentation | 2026 | B | Documentation | 5 |
| A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning Z. Peng et al. · Artificial Intelligence Review, vol. 59, no. 7, article 157 | 2026 | A | Peer-reviewed | 2 |
| A System Overview for Near-Term, Low-Trust AI Compute Verification N. Cankaya · Machine Intelligence Research Institute | 2026 | B | Technical report | 38 |
| About: Oxford Martin AIGI · Oxford Martin AI Governance Initiative | 2026 | B | Documentation | 1 |
| Adversarial Entropy Inflation Against Gumbel-Based Inference Verification N. Kezins · arXiv | 2026 | B | Preprint | 7 |
| AI 2040 Plan A — Verification SITREP Amodo Design · Amodo Design | 2026 | C | Blog / article | 7 |
| Amodo-Design/Inference-Recomputation-Prototype (GitHub repository) Amodo Design · GitHub | 2026 | B | Code | 3 |
| Amodo-Design/PoSE-Memory-Wiping (GitHub repository) Amodo Design · GitHub | 2026 | B | Code | 2 |
| Auditor-in-a-Box: Tools for Third-Party Auditing R. Rinberg & B. Penchas · LessWrong | 2026 | C | Blog / article | 3 |
| Backend infrastructure Tinfoil · Tinfoil documentation | 2026 | B | Documentation | 4 |
| Batch Invariance (vLLM documentation) vLLM project · vLLM documentation (GitHub, docs/features/batch_invariance.md) | 2026 | B | Documentation | 1 |
| Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing J. De Meulemeester et al. · 47th IEEE Symposium on Security and Privacy (S&P 2026) | 2026 | A | Peer-reviewed | 6 |
| Bit-Exact AI Inference Verification Without Performance Tradeoffs N. Cankaya · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 8 |
| Components of a Frontier AI Slowdown A. Chan · A Strange Attractor | 2026 | C | Blog / article | — |
| Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance S. Ding et al. · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 1 |
| Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance (reference implementation) covehub · GitHub | 2026 | B | Code | 1 |
| Covert AI Projects B. Halstead & T. Larsen · AI 2040 | 2026 | C | Blog / article | 4 |
| DeepSeek-V4: Towards Highly Efficient Million-Token Context Intelligence DeepSeek-AI · arXiv | 2026 | B | Technical report | 1 |
| Detecting Compute Structuring in AI Governance Is Likely Feasible E. Seferis & T. Fist · Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment) | 2026 | A | Peer-reviewed | — |
| Detecting Hidden ML Training With Zero-Overhead Telemetry R. Rahman & S. Tajdari · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 5 |
| Does Distributed Training Undermine Compute Governance? R. Rahman · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 1 |
| Enabling Verifiably-Scoped Monitoring through Large Language Models and Trusted Compute B. Penchas et al. · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 3 |
| Example Schemes for Verifying High-Stakes AI Agreements Amodo Design · Amodo Design | 2026 | C | Blog / article | 9 |
| Experiments: Lucid Labs · Lucid Computing | 2026 | B | Documentation | 2 |
| Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors N. Cankaya et al. · arXiv | 2026 | B | Preprint | 3 |
| Fitting a Network TAP to our Inference Verification Prototype Amodo Design · Amodo Design | 2026 | C | Blog / article | 2 |
| From Verifiability to Model-Weight Security Attestable · Attestable blog | 2026 | C | Blog / article | 3 |
| Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies M. Brundage et al. · arXiv | 2026 | B | Preprint | 2 |
| Get Involved in Verification AI Futures Project · AI 2040 | 2026 | C | Blog / article | 6 |
| GPU Fingerprinting for Location Verification W. Tee & J. Happel · arXiv | 2026 | B | Preprint | 2 |
| Haiku to Opus in Just 10 bits: LLMs Unlock Large Compression Gains R. Rinberg et al. · arXiv | 2026 | B | Preprint | 4 |
| Hardware AI Governance Lab · Oxford Martin AI Governance Initiative | 2026 | B | Documentation | 2 |
| Hardware Mechanisms to Dynamically Throttle AI Performance H. Ma et al. · arXiv | 2026 | B | Preprint | 1 |
| Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification S. Ansari · arXiv | 2026 | B | Preprint | 5 |
| Hawkeye: Reproducing GPU-Level Non-Determinism E. Badash et al. · Proceedings of Machine Learning and Systems 8 (MLSys 2026) | 2026 | A | Peer-reviewed | 2 |
| Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering S. F. Comer et al. · RAND Corporation (Research Report RR-A4827-1) | 2026 | B | Technical report | 4 |
| Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference C. Gong et al. · arXiv | 2026 | B | Preprint | 2 |
| How Tinfoil Proves Exactly What Model Is Running Tinfoil Team · Tinfoil | 2026 | C | Blog / article | 5 |
| How verification works in Tinfoil Tinfoil · Tinfoil documentation | 2026 | B | Documentation | 4 |
| Improving Disk Wiping Speed for Memory Wipes Amodo Design · Amodo Design | 2026 | C | Blog / article | 2 |
| inference-verification: Inference Verification Prototype Singapore AI Safety Hub (SASH) · GitHub | 2026 | B | Code | 3 |
| Intelligence Security Laboratories: Building secure infrastructure for transformative AI · Intelligence Security Laboratories | 2026 | B | Documentation | 2 |
| Internationalising AI Verification Singapore AI Safety Hub (SASH) · SASH blog | 2026 | C | Blog / article | 5 |
| Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field P. Horvath et al. · IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026) | 2026 | A | Peer-reviewed | 1 |
| LLM-42: Enabling Determinism in LLM Inference with Verified Speculation R. Gond et al. · arXiv | 2026 | B | Preprint | 1 |
| Lucid Computing: Verifiable AI. Proven in hardware. · Lucid Computing | 2026 | B | Documentation | 3 |
| Lucid Developer Platform documentation · Lucid Computing | 2026 | B | Documentation | 2 |
| Lucid Labs: the verification flywheel · Lucid Computing | 2026 | B | Documentation | 2 |
| Memory Wipes - Performance Analysis Amodo Design · Amodo Design | 2026 | C | Blog / article | 3 |
| modelwrap: Reproducible dm-verity read-only image of Huggingface models Tinfoil · GitHub | 2026 | B | Code | 4 |
| NanoZK: Privacy-Preserving Verifiable Inference for Large Language Models via Layerwise Zero-Knowledge Proofs Z. Wang · International Conference on Information and Communications Security (ICICS 2026) | 2026 | A | Peer-reviewed | 1 |
| Near-Term Verification Methods for AI Chip Exports B. Avellar & E. Grunewald · arXiv | 2026 | B | Preprint | 4 |
| Network Tapping for AI Verification: A Technical Assessment Amodo Design · Amodo Design | 2026 | C | Blog / article | 2 |
| Network Taps — A First Test Amodo Design · Amodo Design | 2026 | C | Blog / article | 2 |
| Network Traffic Hashing Amodo Design · Amodo Design | 2026 | C | Blog / article | 2 |
| NIST Computer Security Resource Center (CSRC) Glossary National Institute of Standards and Technology · NIST Computer Security Resource Center | 2026 | A | Government document | 8 |
| On restraining AI development for the sake of safety J. Carlsmith · Joseph Carlsmith | 2026 | C | Blog / article | — |
| On TEEs for Privacy-Preserving Monitoring in AI Governance Gloria Z · MIRI Technical Governance Team | 2026 | C | Blog / article | 12 |
| Our Team: Intelligence Security Laboratories · Intelligence Security Laboratories | 2026 | B | Documentation | 2 |
| Pacing AI Requires Proof Attestable · Attestable blog | 2026 | C | Blog / article | 8 |
| PAL*M: Property Attestation for Large Generative Models P. Chantasantitam et al. · arXiv | 2026 | B | Preprint | 7 |
| Pearl Floating Point Scheme Specification Pearl Research Team · Pearl Research Labs | 2026 | B | Technical report | 4 |
| Pearl INT Whitepaper Pearl Research Labs · Pearl Research Labs | 2026 | B | Technical report | 3 |
| pearl: Monorepo for the Pearl network Pearl Research Labs · GitHub | 2026 | B | Code | 3 |
| Planet Reports Financial Results for Second Quarter of Fiscal Year 2027 Planet Labs PBC · Business Wire (press release) | 2026 | C | Blog / article | 1 |
| Privacy-Preserving AI Verification via Minimal Information Disclosure S. Abdelghafar & G. Kulp · arXiv | 2026 | B | Preprint | 1 |
| Proof-of-Guardrail in AI Agents and What (Not) to Trust from It X. Jin et al. · arXiv | 2026 | B | Preprint | 2 |
| Proving LLMs at Scale Attestable · Attestable blog | 2026 | C | Blog / article | 3 |
| Scaling Recomputation Inference Verification Amodo Design · Amodo Design | 2026 | C | Blog / article | 4 |
| Sovereignty Certificates Working Group · sovcert.org | 2026 | B | Documentation | 1 |
| Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses N. Cankaya · MIRI Technical Governance Team | 2026 | C | Blog / article | 7 |
| TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition J. Chuang et al. · 2026 IEEE Symposium on Security and Privacy (SP) | 2026 | A | Peer-reviewed | 6 |
| The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use N. Cankaya · The Datacenter Lie Detector | 2026 | C | Blog / article | 6 |
| The Tray as a Bandwidth Boundary Amodo Design · Amodo Design | 2026 | C | Blog / article | 3 |
| The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol A. Basu · arXiv | 2026 | B | Preprint | 2 |
| Timing and Memory Telemetry on GPUs for AI Governance S. K. Monfared et al. · arXiv | 2026 | B | Preprint | 4 |
| Tracking Hyperscale AI Data Center Growth with Satellite Imagery C. Krawec · Federation of American Scientists | 2026 | B | Technical report | 4 |
| Traffic Shaping for Workload Classification Lucid Computing · Lucid Computing (Substack) | 2026 | C | Blog / article | 3 |
| Understanding Data Center Power Delivery Amodo Design · Amodo Design | 2026 | C | Blog / article | 2 |
| Verifiable constraints on frontier training via proofs of compartmentalization D. Reuter et al. · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | — |
| Verifiable Semiconductor Manufacturing A. Ilhan et al. · Oxford Martin AI Governance Initiative | 2026 | B | Technical report | 1 |
| Verifiable-ClawGuard: proof-of-guardrail reference code SaharaLabsAI · GitHub | 2026 | B | Code | 1 |
| Verification Plan R. Dean · AI 2040 | 2026 | C | Blog / article | 15 |
| Verifying AI Compute by Bounding Unexplained Information Exfiltration J. Petrie & Y. Mühlhäuser · ICML 2026 Workshop on Technical AI Governance Research | 2026 | B | Preprint | 1 |
| Verifying international AI deals: Plan A, the state-of-play, and what you can do to help T. Milton et al. · Amodo (Substack) | 2026 | C | Blog / article | 3 |
| Workload Identification with Physical Side Channels for AI Governance S. Gargiulo & G. Kulp · arXiv | 2026 | B | Preprint | 1 |
| Zero knowledge verification for frontier AI training is possible P. Peigné et al. · arXiv | 2026 | B | Preprint | 4 |
| adamkarvonen/difr (GitHub repository) A. Karvonen · GitHub | 2025 | B | Code | 2 |
| AI Security RFDs AI Security Forum · AI Security Forum | 2025 | C | Forum / discussion | — |
| An International Agreement to Prevent the Premature Creation of Artificial Superintelligence A. Scher et al. · Machine Intelligence Research Institute | 2025 | B | Technical report | 7 |
| Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments C. Schnabl et al. · ICML 2025 Workshop on Technical AI Governance | 2025 | B | Preprint | 9 |
| BarraCUDA: Edge GPUs do Leak DNN Weights P. Horvath et al. · 34th USENIX Security Symposium | 2025 | A | Peer-reviewed | 2 |
| Boost GPU Memory Performance with No Code Changes Using NVIDIA CUDA MPS S. Nassernia · NVIDIA Technical Blog | 2025 | B | Blog / article | 1 |
| Defeating Nondeterminism in LLM Inference H. He & Thinking Machines Lab · Thinking Machines Lab: Connectionism | 2025 | C | Blog / article | 3 |
| Detecting Anomalies in Machine Learning Infrastructure via Hardware Telemetry Z. Chen et al. · arXiv | 2025 | B | Preprint | 1 |
| DiFR: Inference Verification Despite Nondeterminism A. Karvonen et al. · arXiv | 2025 | B | Preprint | 8 |
| Executive Order 14148: Initial Rescissions of Harmful Executive Orders and Actions Executive Office of the President · Federal Register, 90 FR 8237 (document 2025-01901, published 2025-01-28) | 2025 | A | Government document | 2 |
| Faster AI Diffusion Through Hardware-Based Verification N. Ammann & D. Dalrymple · Institute for Progress | 2025 | C | Blog / article | — |
| Flexible Hardware-Enabled Guarantees for AI Compute J. Petrie et al. · arXiv | 2025 | B | Preprint | 7 |
| Guaranteeable Memory: An HBM-Based Chiplet for Verifiable AI Workloads J. Petrie · ICML 2025 Workshop on Technical AI Governance | 2025 | B | Preprint | 1 |
| GuardAIn: Protecting Emerging Generative AI Workloads on Heterogeneous NPU A. Dhar et al. · 2025 IEEE Symposium on Security and Privacy | 2025 | A | Peer-reviewed | 1 |
| Hardware-Enabled Mechanisms for Verifying Responsible AI Development A. O'Gara et al. · arXiv | 2025 | B | Preprint | 5 |
| Has My System Prompt Been Used? Large Language Model Prompt Membership Inference R. Levin et al. · arXiv | 2025 | B | Preprint | 1 |
| INTELLECT-2: A Reasoning Model Trained Through Globally Decentralized Reinforcement Learning Prime Intellect Team et al. · arXiv | 2025 | B | Technical report | 3 |
| International AI Safety Report Y. Bengio et al. · International AI Safety Report | 2025 | B | Technical report | — |
| International Security Applications of Flexible Hardware-Enabled Guarantees O. Aarne & J. Petrie · arXiv | 2025 | B | Preprint | 1 |
| Introducing the Frontier Data Centers Hub Epoch AI · Epoch AI | 2025 | C | Blog / article | 3 |
| Location Verification for AI Chips (issue brief) A. Brass & O. Aarne · Institute for AI Policy and Strategy | 2025 | B | Technical report | 3 |
| Mechanisms to Verify International Agreements About AI Development A. Scher & L. Thiergart · arXiv | 2025 | B | Preprint | 18 |
| MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs R. Ding et al. · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS 2025) | 2025 | A | Peer-reviewed | — |
| NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper) NVIDIA · NVIDIA documentation | 2025 | B | Documentation | 4 |
| Open Problems in Technical AI Governance A. Reuel et al. · Transactions on Machine Learning Research | 2025 | A | Peer-reviewed | 2 |
| Opt-In NVIDIA Software Enables Data Center Fleet Management NVIDIA · NVIDIA Blog | 2025 | B | Blog / article | 2 |
| PrimeIntellect-ai/toploc (GitHub repository) Prime Intellect · GitHub | 2025 | B | Code | 3 |
| Proofs of Useful Work from Arbitrary Matrix Multiplication I. Komargodski et al. · arXiv | 2025 | B | Preprint | 3 |
| RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP B. Schlüter & S. Shinde · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) | 2025 | A | Peer-reviewed | 6 |
| SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020) AMD · AMD product security bulletin | 2025 | B | Documentation | 5 |
| Single-Node Power Demand During AI Training: Measurements on an 8-GPU NVIDIA H100 System I. Latif et al. · IEEE Access, vol. 13, pp. 61740–61747 | 2025 | A | Peer-reviewed | 1 |
| Sovereignty Certificates: draft specification, version 0.1.0 Sovereignty Certificates Working Group · GitHub (Lucid-Computing/sovereignty-certificate-specification) | 2025 | B | Documentation | 4 |
| SYNTHETIC-2 Prime Intellect · Prime Intellect blog | 2025 | C | Blog / article | 2 |
| Technical Options for Flexible Hardware-Enabled Guarantees J. Petrie & O. Aarne · arXiv | 2025 | B | Preprint | 3 |
| TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference J. M. Ong et al. · Proceedings of the 42nd International Conference on Machine Learning (PMLR 267), pp. 47196-47211 | 2025 | A | Peer-reviewed | 3 |
| TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference (blog post) Prime Intellect · Prime Intellect blog | 2025 | C | Blog / article | 2 |
| Towards Deterministic Inference in SGLang and Reproducible RL Training The SGLang Team · LMSYS Org blog | 2025 | C | Blog / article | 1 |
| TSMC most definitely has a golden record of all AI chips it made N. Cankaya · Substack (Naci Cankaya) | 2025 | C | Blog / article | 1 |
| Verification for International AI Governance B. Harack et al. · Oxford Martin AI Governance Initiative | 2025 | B | Technical report | 8 |
| Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment M. Baker et al. · RAND Corporation | 2025 | B | Technical report | 20 |
| Verifying LLM Inference to Detect Model Weight Exfiltration R. Rinberg et al. · arXiv | 2025 | B | Preprint | 9 |
| WireTap: Breaking Server SGX via DRAM Bus Interposition A. Seto et al. · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) | 2025 | A | Peer-reviewed | 1 |
| Zkonduit EZKL Security Assessment F. Casal et al. · Trail of Bits (prepared for Zkonduit Inc.) | 2025 | B | Technical report | 1 |
| Computing Power and the Governance of Artificial Intelligence G. Sastry et al. · arXiv | 2024 | B | Preprint | 10 |
| DeepTheft: Stealing DNN Model Architectures through Power Side Channel Y. Gao et al. · 2024 IEEE Symposium on Security and Privacy | 2024 | A | Peer-reviewed | 2 |
| DiLoCo: Distributed Low-Communication Training of Language Models A. Douillard et al. · ICML 2024 Workshop on Advancing Neural Network Training (WANT) | 2024 | B | Preprint | 2 |
| Foundational Challenges in Assuring Alignment and Safety of Large Language Models U. Anwar et al. · Transactions on Machine Learning Research | 2024 | A | Peer-reviewed | — |
| Governing Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation L. Heim et al. · Oxford Martin AI Governance Initiative | 2024 | B | Technical report | 1 |
| Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 G. Kulp et al. · RAND Corporation | 2024 | B | Technical report | 12 |
| Input-Dependent Power Usage in GPUs T. Gregersen et al. · SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis (Sustainable Supercomputing workshop), pp. 1872–1877 | 2024 | B | Preprint | 1 |
| Location Verification for AI Chips A. Brass & O. Aarne · Institute for AI Policy and Strategy | 2024 | B | Technical report | 5 |
| Preventing model exfiltration with upload limits R. Greenblatt · AI Alignment Forum | 2024 | C | Forum / discussion | 1 |
| Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing O. Aarne et al. · Center for a New American Security | 2024 | B | Technical report | 7 |
| Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models S. Nevo et al. · RAND Corporation | 2024 | B | Technical report | 3 |
| Software-Based Memory Erasure with Relaxed Isolation Requirements S. Bursuc et al. · 2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024) | 2024 | A | Peer-reviewed | 3 |
| Trustless Audits without Revealing Data or Models S. Waiwitlikhit et al. · 41st International Conference on Machine Learning (ICML 2024) | 2024 | A | Peer-reviewed | 3 |
| Verifiable evaluations of machine learning models using zkSNARKs T. South et al. · arXiv | 2024 | B | Preprint | 1 |
| Verification methods for international AI agreements A. R. Wasil et al. · arXiv | 2024 | B | Preprint | 8 |
| Zero-Knowledge Proofs of Training for Deep Neural Networks K. Abbaszadeh et al. · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330 | 2024 | A | Peer-reviewed | 2 |
| zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models H. Sun · GitHub; archived on Zenodo | 2024 | B | Code | 3 |
| zkLLM: Zero Knowledge Proofs for Large Language Models H. Sun et al. · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024) | 2024 | A | Peer-reviewed | 8 |
| ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs B.-J. Chen et al. · 19th European Conference on Computer Systems (EuroSys 2024) | 2024 | A | Peer-reviewed | 1 |
| A Practical Introduction to Side-Channel Extraction of Deep Neural Network Parameters R. Joud et al. · 21st International Conference on Smart Card Research and Advanced Applications (CARDIS 2022), LNCS 13820, pp. 45–65 | 2023 | A | Peer-reviewed | — |
| Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI E. Apsey et al. · NVIDIA Technical Blog | 2023 | C | Blog / article | 2 |
| Exploration of secure hardware solutions for safe AI deployment Future of Life Institute · Future of Life Institute | 2023 | C | Blog / article | 2 |
| ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection T. Mosavirik et al. · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325 | 2023 | A | Peer-reviewed | 1 |
| International Governance of Civilian AI: A Jurisdictional Certification Approach R. Trager et al. · Centre for the Governance of AI | 2023 | B | Technical report | — |
| Part-time Power Measurements: nvidia-smi's Lack of Attention Z. Yang et al. · arXiv | 2023 | B | Preprint | 2 |
| Proof-of-Learning is Currently More Broken Than You Think C. Fang et al. · 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023) | 2023 | A | Peer-reviewed | 2 |
| Remote ATtestation procedureS (RATS) Architecture (RFC 9334) H. Birkholz et al. · Internet Engineering Task Force (RATS Working Group) | 2023 | B | Technical report | 4 |
| SAGE: Software-based Attestation for GPU Execution A. Ivanov et al. · 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 485–499 | 2023 | A | Peer-reviewed | 1 |
| Tools for Verifying Neural Models' Training Data D. Choi et al. · Advances in Neural Information Processing Systems 36 (NeurIPS 2023) | 2023 | A | Peer-reviewed | 2 |
| What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring Y. Shavit · arXiv | 2023 | B | Preprint | 20 |
| "Adversarial Examples" for Proof-of-Learning R. Zhang et al. · 2022 IEEE Symposium on Security and Privacy (SP) | 2022 | A | Peer-reviewed | 1 |
| Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems P. Staat et al. · 2022 IEEE Symposium on Security and Privacy | 2022 | A | Peer-reviewed | 1 |
| Common Terminology for Confidential Computing Confidential Computing Consortium · Confidential Computing Consortium | 2022 | B | Technical report | 2 |
| ZKProof Community Reference D. Benarroch et al. · ZKProof | 2022 | B | Technical report | 4 |
| Proof-of-Learning: code for Proof-of-Learning: Definitions and Practice CleverHans Lab · GitHub | 2021 | B | Code | 1 |
| Proof-of-Learning: Definitions and Practice H. Jia et al. · 42nd IEEE Symposium on Security and Privacy | 2021 | A | Peer-reviewed | 1 |
| Detecting Covert Cryptomining Using HPC A. Gangwal et al. · Cryptology and Network Security – CANS 2020, LNCS 12579, pp. 344–364 | 2020 | A | Peer-reviewed | 1 |
| Secure Physical Enclosures from Covers with Tamper-Resistance V. Immler et al. · IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96 | 2019 | A | Peer-reviewed | 1 |
| Platform Firmware Resiliency Guidelines (NIST SP 800-193) A. Regenscheid · National Institute of Standards and Technology | 2018 | A | Government document | 1 |
| The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond J. Obermaier & V. Immler · Journal of Hardware and Systems Security | 2018 | A | Peer-reviewed | 1 |
| Proofs of Useful Work M. Ball et al. · IACR Cryptology ePrint Archive 2017/203 | 2017 | B | Preprint | 2 |
| TCG Glossary Trusted Computing Group · Trusted Computing Group | 2017 | B | Documentation | 2 |
| Proofs of Space S. Dziembowski et al. · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796) | 2015 | A | Peer-reviewed | 5 |
| Tamper-Indicating Enclosures, A Current Survey H. A. Smartt & Z. N. Gastelum · Sandia National Laboratories, SAND2015-4251C | 2015 | B | Technical report | 1 |
| IBM 4765 Cryptographic Coprocessor Security Module: Security Policy IBM Corporation · NIST Cryptographic Module Validation Program | 2012 | B | Technical report | 1 |
| Secure Code Update for Embedded Devices via Proofs of Secure Erasure D. Perito & G. Tsudik · Computer Security – ESORICS 2010, LNCS 6345, pp. 643–662 | 2010 | A | Peer-reviewed | 2 |
| On the Difficulty of Software-Based Attestation of Embedded Devices C. Castelluccia et al. · ACM Conference on Computer and Communications Security (CCS 2009) | 2009 | A | Peer-reviewed | 1 |
| SWATT: SoftWare-based ATTestation for Embedded Devices A. Seshadri et al. · IEEE Symposium on Security and Privacy 2004 | 2004 | A | Peer-reviewed | 1 |
| Guidelines for Writing RFC Text on Security Considerations (RFC 3552, BCP 72) E. Rescorla et al. · Internet Engineering Task Force | 2003 | A | Standard | 1 |
| Security Requirements for Cryptographic Modules (FIPS PUB 140-2) National Institute of Standards and Technology · National Institute of Standards and Technology | 2001 | A | Standard | 1 |
| Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials R. G. Johnston · The Nonproliferation Review, Spring 2001, pp. 102–114 | 2001 | A | Peer-reviewed | 1 |
| Physical Security and Tamper-Indicating Devices R. G. Johnston & A. R. E. Garcia · Los Alamos National Laboratory, LA-UR-96-3827 | 1996 | B | Technical report | 2 |