01 / The mechanism and its boundary
What is being described
Evidence binding ties a piece of verification evidence to the device, workload, data and time it describes, so that it cannot be replayed, substituted or attributed to something else S-1603 S-0018.
The IETF remote-attestation architecture states the requirement for devices: evidence must be securely associated with the environment it describes, so that a verifier cannot be tricked into accepting claims that originate elsewhere S-1603. Binding has several dimensions:
- Device. Evidence is signed with key material held by the attesting device, as in TEE remote attestation S-1603. Scher and Thiergart note that if the private key a chip uses to attest its location were extracted, the chip's location could be spoofed S-0005.
- Time. A nonce from the appraising party, signed into the evidence, shows that it is fresh rather than replayed S-1603, and network taps hash and timestamp the traffic they capture S-0031.
- Workload. Shavit's design has chip firmware hash weight snapshots taken at random times, then store the hash where only the firmware can write it or sign it with the chip's private key S-0029. One low-trust system aims to identify each forward pass uniquely and attribute it to the hardware and time that processed it S-0018.
- Model and data. PAL*M tracks dataset integrity with incremental multiset hashing inside confidential virtual machines, so that attested properties refer to the model and data actually used S-0012.
Binding also constrains when evidence is fixed: for sampled checks, the prover must commit to its records before it learns which ones will be audited S-0017.
Connections in the research map
Related research
Sources and provenance
- S-1603 / Tier B
Remote ATtestation procedureS (RATS) Architecture (RFC 9334) ↗
H. Birkholz, D. Thaler, M. Richardson, N. Smith, W. Pan · 2023 · Internet Engineering Task Force (RATS Working Group)
Supports: evidence must be securely associated with its target environment so a verifier cannot be tricked into accepting claims from a different environment; evidence generated with the attester's key material; signed nonces for freshness
Locator: §3.1; §8.1; §10.2
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: evidence can identify each forward pass uniquely and attribute it to the hardware and time it was processed on
Locator: verification goals
Version and catalogue details - S-0005 / Tier B
Mechanisms to Verify International Agreements About AI Development ↗
A. Scher, L. Thiergart · 2025 · arXiv
Supports: if a chip's location-attestation private key were extracted, its location could be spoofed
Locator: On-chip mechanisms for location verification
Version and catalogue details - S-0031 / Tier C
The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use ↗
N. Cankaya · 2026 · The Datacenter Lie Detector
Supports: taps hash and timestamp captured traffic
Locator: tap functions
Version and catalogue details - S-0029 / Tier B
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗
Y. Shavit · 2023 · arXiv
Supports: chip firmware hashes weight snapshots taken at random times; the hash is stored in firmware-only memory or signed with the chip's private key
Locator: §4
Version and catalogue details - S-0012 / Tier B
PAL*M: Property Attestation for Large Generative Models ↗
P. Chantasantitam, A. I. Caulfield, V. Duddu, L. J. Gunn, N. Asokan · 2026 · arXiv
Supports: confidential VMs with GPUs and incremental multiset hashing to track dataset integrity for property attestation
Locator: abstract
Version and catalogue details - S-0017 / Tier C
Example Schemes for Verifying High-Stakes AI Agreements ↗
Amodo Design · 2026 · Amodo Design
Supports: prover commits a hash of sampled weights before it learns whether a step will be audited
Locator: pre-training scheme
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review