01 / The mechanism and its boundary
What the technique establishes
A proof of useful work shows that a given amount of computation, such as the matrix multiplications at the heart of AI models, was completed. The computation can serve a useful task, but the proof does not show that it did. For verification, the idea is to keep declared hardware occupied with agreed, provable work, so that little capacity is left for unmonitored work such as an unauthorised training run. The cryptographic building block exists: a 2025 construction adds asymptotically negligible overhead to large matrix multiplications, and a company runs a public blockchain built on it. On that network, an independent study found that random matrices passed verification. Using it to bound spare capacity is only proposed. The proof covers the computation; the capacity claim separately needs a credible estimate of the actor's available compute. Such proofs cannot find undeclared hardware.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- None
- Prover cooperation
- Required
- Confidentiality
- Partial
- Category
- Cryptography & computation
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
This compute runs inference, not training
Bounds the spare capacity of declared hardware that could run unauthorised training; Attestable pairs work accounting with ZK inference proofs.
Readiness for a stated use
Assessed use: bounding the spare capacity of declared hardware that could run training
low confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
The scheme is proposed, and the only implementation proves work for blockchain consensus, not that hardware has no spare capacity.
- R1 met: Attestable describes such a scheme, with its claim and a key assumption, namely a credible estimate of the actor's compute S-1102. Scher and Thiergart list proof of work, for compute declared to be doing crypto mining, among the ways to verify that known compute is not used for a large training run S-0005. The underlying proof-of-useful-work construction is publicly specified with its hardness assumptions S-1609.
- R2 not met for this use. The most mature implementation, Pearl, is assessed R3 only for the narrower claim that GPUs performed matrix-multiplication work. It is built for blockchain consensus, and no public implementation or result uses proofs of useful work to bound the spare capacity of declared hardware S-1105 S-1107.
Evidence needed for the next level
A public implementation or reproducible end-to-end result that uses proofs of work to bound the spare capacity of declared hardware against a stated adversary.
A method for the verifier to obtain a credible estimate of the prover's available compute.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / theoretical argument
Proves that work was done, not that no capacity remains
Proof-of-work accounting bounds unmonitored compute only relative to an estimate of what the actor has. Attestable states that the verifier "needs a credible estimate of the compute available" to the actor, and that a proof "cannot discover a datacenter that was never declared" S-1102.
significant / open / open question
Security rests on new hardness assumptions
Komargodski and Weinstein base security on hardness assumptions about batches of low-rank random linear equations, and list PoUW "from more standard or well-studied assumptions" as an open problem S-1609. Pearl's floating-point variant introduces a further "quantized-subspace hardness" assumption S-1105.
significant / open / theoretical argument
Known shortcuts let a miner claim somewhat more work than it did
Pearl's specification lists known mining speedups: crafted inputs, precision shortcuts, seed grinding, work reuse, and faster kernels or hardware. A policy check caps the summands a miner may skip at one-sixteenth of those in a tile S-1105. For capacity bounding, any gap between work proven and work possible leaves spare capacity.
What still blocks use or stronger assurance
- S-1102
Bounding spare capacity needs a credible estimate of the compute available to the actor, including third-party access S-1102.
- S-1102
Proofs of work cannot find facilities that were never declared S-1102.
As of September 2026 no implementation, demonstration or independent evaluation of proofs of work for capacity bounding has been published.
Connections in the research map
Complementary techniques
Concepts used
Organizations and developers
Implementations
Sources and provenance
- S-1609 / Tier B
Proofs of Useful Work from Arbitrary Matrix Multiplication ↗
I. Komargodski, O. Weinstein · 2025 · arXiv
Supports: PoUW construction for arbitrary matrix multiplication; miners choose the matrices; overhead; assumptions; open problems
Locator: abstract; §2; Remarks 2.1–2.2; §3; §5; §6.5 (ePrint numbering)
Version and catalogue details - S-1105 / Tier B
Pearl Floating Point Scheme Specification ↗
Pearl Research Team · 2026 · Pearl Research Labs
Supports: Pearl FP8 protocol, verifier, known mining speedups, assumption (provider-reported)
Locator: abstract; §2; §4; §5; §6; §7; App. B
Version and catalogue details - S-1106 / Tier B
Pearl INT Whitepaper ↗
Pearl Research Labs · 2026 · Pearl Research Labs
Supports: Pearl INT scheme, benchmark and launch statement (provider-reported)
Locator: §3; §4.7; §7 Table 1
Version and catalogue details - S-1107 / Tier B
pearl: Monorepo for the Pearl network ↗
Pearl Research Labs · 2026 · GitHub
Supports: public Pearl network code
Locator: README; release v1.2.1
Version and catalogue details - S-0071 / Tier B
The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol ↗
A. Basu · 2026 · arXiv
Supports: independent measurement of Pearl's mainnet: random-matrix mining; verification does not check matrix provenance
Locator: abstract; measurement and verification sections; conclusion
Version and catalogue details - S-1102 / Tier C
Pacing AI Requires Proof ↗
Attestable · 2026 · Attestable blog
Supports: proposal to use proof-of-work accounting to bound unmonitored compute (provider-reported)
Version and catalogue details - S-1608 / Tier B
Proofs of Useful Work ↗
M. Ball, A. Rosen, M. Sabin, P. N. Vasudevan · 2017 · IACR Cryptology ePrint Archive 2017/203
Supports: earlier PoUW for fine-grained complexity problems
Locator: abstract
Version and catalogue details - S-0005 / Tier B
Mechanisms to Verify International Agreements About AI Development ↗
A. Scher, L. Thiergart · 2025 · arXiv
Supports: proof of work to confirm that compute declared as crypto mining is mining, as a way to verify known compute is not used for a large training run; R1 evidence
Locator: 'Proof-of-Work methods for crypto mining', in 'Verifying That Known Compute is Not Being Used for a Large Training Run'
Version and catalogue details - S-3566 / Tier C
Can governments quickly and cheaply slow AI training? ↗
joshc · 2026 · AI Alignment Forum
Supports: independent analysis that the share of declared compute accounted for determines the residual budget for covert RL rollouts
Locator: §2.5; §4
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: memory filling with incompressible noise as a capacity check
Locator: §5.1.2
Version and catalogue details - S-1607 / Tier A
Proofs of Space ↗
S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak · 2015 · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796)
Supports: proofs of space as the storage analogue of proofs of work
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review