I-0015 / Cryptography & computation

Verde and RepOps (Gensyn)

Gensyn's system for checking delegated machine-learning jobs, which settles disagreements between providers by re-running a single operation with bitwise-reproducible operators.

R3 In productionSource reviewed 2026-09-25Provider-reported evidence

01 / The mechanism and its boundary

What the technique establishes

Verde is a protocol from the company Gensyn for checking machine-learning jobs, such as inference, fine-tuning or training, that a client hands to untrusted compute providers. Several providers run the same job. If their results differ, a bisection game narrows the dispute to a single operation, which a referee re-runs to decide who is right. The client gets the correct result if at least one provider is honest. This needs identical results on different hardware, which Gensyn reports its RepOps library provides by fixing the order of floating-point operations. Gensyn reports settling markets in its Delphi app with REE, a runtime built on RepOps whose receipts let anyone re-run the inference, and states that Verde runs in its Judge service. RepOps ships as closed binaries. The research paper reports that RepOps roughly doubled Llama-8B inference time. As of September 2026 no independent evaluation has been published.

Threat model
Adversarial prover
Adversarial evaluation
Published analysis
Hardware needed
None
Prover cooperation
Required
Confidentiality
Revealing
Category
Cryptography & computation

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R3 In production

Assessed use: reproducing declared-model inference from receipts in Gensyn's information-market service

low confidence · current · assessed 2026-10-08 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Gensyn reports using its public runtime in production to settle markets whose answers anyone can re-run, but all evidence of that use comes from Gensyn, and no independent security evaluation of Verde or RepOps has been published.

  • R1 met: the paper states the claim, that the client obtains the correct result if at least one provider is honest, together with the dispute protocol and its assumptions S-1809.
  • R2 met: Gensyn's Reproducible Execution Environment, which runs LLM inference with RepOps and writes receipts for re-execution, is public as binaries with an MIT-licensed SDK S-1812. The paper measures RepOps on NVIDIA T4, RTX 3090 and A100 GPUs, including Llama-8B inference and fine-tuning on an A100, against a stated adversary: dishonest compute providers S-1809. The paper's evaluation reports overheads. The claim of bitwise-identical results across hardware comes from Gensyn's posts S-1810.
  • R3 met on the provider's own account, as a production service that others can check. Gensyn reports that Delphi, its information-market app, is live on its mainnet, that hosted REE settlement is available for partner markets, and that markets settled by open models inside REE produce receipts anyone can re-run to verify the answer S-3022. The May 2026 post describes no dispute process. Gensyn's service documentation also describes the REE judge receipts and mainnet deployment S-0075. REE's README lists v0.8.0, released on 5 October 2026, and Gensyn does not label its releases alpha or beta S-1812 S-3023. Gensyn also states that Verde and RepOps are deployed in Judge, its AI evaluation service, without saying how Judge uses them S-1810 S-1811. No party other than Gensyn is documented relying on Verde or REE for a verification decision. The production account covers receipt re-execution. It does not document how Verde's guarantee that one honest provider suffices is applied in that service S-3022 S-0075.
  • R4 not met: no independent audit, red-team or peer-reviewed security analysis has been published.

Confidence is low: R3 rests on Gensyn's own posts, and REE's documentation warns that receipts from one release may not re-verify under the next S-3023.

Evidence needed for the next level

  • An independent public security evaluation of the Verde dispute protocol and of RepOps reproducibility across hardware, which the paper asserts but does not test.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

No flaws are recorded in this snapshot. See the scope, assumptions, and blockers below.

What still blocks use or stronger assurance

  1. Reproducibility costs throughput: RepOps added 98% to Llama-8B inference time on an A100 in the paper, and Gensyn reports a threefold cut in REE's reproducible-mode overhead without absolute figures.

    S-1809S-1812
  2. The providers who re-run a job and the referee need the model and data, and the guarantee holds only if at least one provider is honest.

    S-1809

Connections in the research map

Mechanisms implemented

Concepts used

Organizations and developers

Sources and provenance

  1. S-1809 / Tier B

    Verde: Verification via Refereed Delegation for Machine Learning Programs ↗

    A. Arun, A. St. Arnaud, A. Titov, B. Wilcox, V. Kolobaric, M. Brinkmann, O. Ersoy, B. Fielding, J. Bonneau · 2025 · arXiv

    Supports: refereed delegation design, guarantee and its limit, bisection, single-operator re-execution, RepOps design, overheads, FP32 and single-GPU scope, author affiliations

    Locator: abstract; §1; §3.2; §4 Table 2; limitations

    Version and catalogue details
  2. S-1810 / Tier C

    Verde Verification System In Production ↗

    O. Ersoy · 2025 · Gensyn research blog

    Supports: deployment in Judge; bitwise reproducibility across hardware; tasks covered; what the guarantee does not cover (provider-reported)

    Version and catalogue details
  3. S-1811 / Tier C

    Introducing Judge ↗

    Gensyn · 2025 · Gensyn news

    Supports: Judge launch with a reasoning task framed as a prediction market (provider-reported)

    Version and catalogue details
  4. S-1812 / Tier B

    gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository) ↗

    Gensyn · 2026 · GitHub

    Supports: public REE binaries and SDK, licences, receipts, release limited to reproducible LLM inference, pipeline parallelism up to 72B and threefold overhead cut in v0.2.0, v0.8.0 released on 5 October 2026, receipt compatibility across releases (provider-reported)

    Locator: README; patch notes

    Version and catalogue details
  5. S-3022 / Tier C

    Building Delphi: Pricing, Settlement, and Agentic Trading ↗

    D. Jedamski · 2026 · Gensyn blog

    Supports: Delphi live on Gensyn's mainnet; REE settlement receipts that anyone can re-run; hosted REE settlement for partner markets (provider-reported)

    Locator: settlement section

    Version and catalogue details
  6. S-3023 / Tier B

    Reproducible Execution Environment (REE) (Gensyn documentation) ↗

    Gensyn · 2026 · Gensyn documentation

    Supports: REE modes, releases without an alpha or beta label, reproducible int8 attention and MoE kernels (provider-reported)

    Locator: whole page

    Version and catalogue details
  7. S-0075 / Tier B

    What is Delphi? (Delphi documentation) ↗

    Gensyn · 2026 · Delphi documentation

    Supports: Delphi mainnet service and REE judge receipts that anyone can re-run (provider-reported)

    Locator: Settled by AI, Verifiable by Anyone; Where Delphi Runs

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review