I-0006 / Cryptography & computation

Tinfoil model identity (Modelwrap)

Tinfoil's method for proving which model weights its enclave-hosted inference service runs, by binding a dm-verity hash of the weights into remote attestation.

R3 In productionSource reviewed 2026-09-25Provider-reported evidence

01 / The mechanism and its boundary

What the technique establishes

Modelwrap is an open-source tool that lets clients of Tinfoil's enclave-hosted inference service check which model weights it runs. Tinfoil reports running the service on AMD or Intel confidential virtual machines with NVIDIA GPUs in confidential-computing mode. Modelwrap packs the weights into a read-only disk image with a 32-byte Merkle-tree commitment. That hash is written into the enclave's measured boot configuration, and the kernel checks every block read against it. Clients check the hardware-signed attestation against measurements published through Sigstore, and anyone can rebuild the hash for a public model. As of September 2026 no independent security evaluation has been published. The chain inherits the limits of the underlying TEEs. Researchers with physical access have forged Intel TDX and AMD SEV-SNP attestations, and a software-only attack forged SEV-SNP attestations before AMD released firmware fixes. For private models, clients can confirm only that the same weights are served each time.

Threat model
Semi-trusted prover
Adversarial evaluation
Published analysis
Hardware needed
Existing hardware features
Prover cooperation
Required
Confidentiality
Preserving
Category
Cryptography & computation
Technical detail and cited results
  • Build. Modelwrap downloads a pinned Hugging Face revision, normalizes the directory structure so the result is reproducible, and writes an EROFS image. It then computes a dm-verity root hash, a 32-byte commitment, with veritysetup S-0013. Its outputs are the image and a metadata file holding the root hash, offset and verity UUID. An encryption mode supports private models S-1209.
  • Binding. The root hash goes on the kernel command line, which the enclave measurement includes. At runtime dm-verity checks each block read by the inference engine against the root and fails on any mismatch S-0013.
  • Boot chain. The CPU measures the OVMF firmware first, then the kernel and initrd. A tinfoil-config.yml is checked against a hash on the kernel command line. The enclave checks each NVIDIA GPU's attestation with NVIDIA's local-gpu-verifier to confirm confidential-computing mode, and aborts the boot if the check fails. Model volumes are mounted read-only and checked against their Modelwrap commitments S-1207.
  • Client check. The SDK verifies the attestation certificate chain to the CPU vendor's root and verifies a Sigstore bundle of expected measurements. It then confirms that the TLS public key matches the key in the attestation document S-1207.
  • Reported costs. The hash tree adds about 0.8% to image size, and builds take 5 s for a 549 MB model and 13 min 25 s for a 554 GB model. Cold-cache loading takes about 80% longer S-0013.

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R3 In production

Assessed use: showing clients that the served weights match a committed hash

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Tinfoil reports running the chain in its production service, but almost all the evidence comes from Tinfoil, no independent evaluation exists, and the underlying TEEs have open critical flaws.

  • R1 met: the design is published S-0013.
  • R2 met: a public working implementation under an MIT license S-1209 is deployed on realistic hardware, AMD SEV-SNP or Intel TDX with NVIDIA H100, H200 or B200 (provider-reported) S-1206. Build results are reported for models of up to 554 GB S-0013.
  • R3 met on the provider's own account, as a production service that clients can use. Tinfoil reports serving each model from multiple enclaves in its production deployment, with client SDKs that verify the attestation before sending any data S-1208. The enclave checks model volumes against Modelwrap commitments at boot S-1207.
  • R4 not met. As of September 2026 no independent audit, red-team or peer-reviewed analysis of Modelwrap or Tinfoil's model-identity chain has been published. Independent research on the underlying TEEs used physical access to forge Intel TDX attestations and, by pairing them with relayed H100 attestations, passed a workload outside TEE protection S-1202. Other independent research forged AMD SEV-SNP attestations S-1210 S-1212. Tinfoil's documentation acknowledges physical attacks S-1206.

Evidence needed for the next level

  • An independent security evaluation of Modelwrap and the attestation chain that leaves no critical flaw open.

  • A supported tool for audit-time verification from transparency records.

  • A way for third parties to learn something about private models beyond consistency across requests.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

critical / open / demonstrated attack

Inherits attacks on the underlying TEEs

Tinfoil's model commitment and boot-time GPU check depend on the CPU attestation S-1207. The TEE findings distinguish Intel TDX forgery on DDR5, AMD SEV-SNP forgery on DDR4 in Battering RAM, and software-only RMPocalypse on platforms lacking AMD's fixes S-1202 S-1210 S-1212 S-1213. TEE.fail recovered a guest OpenSSL key on AMD, not an AMD attestation key S-1202. Its GPU relay demonstration used an H100 with forged TDX evidence; it does not establish the same result for Tinfoil's H200 or B200 configurations S-1202 S-1206.

S-1206S-1202S-1210S-1212S-1213S-1207
Response recorded by the source map

Tinfoil acknowledges the physical-access boundary. The TEE.fail authors report that Intel and AMD treat interposer attacks as outside their threat models and recommend physically secure servers S-1202 S-1206. AMD reports firmware fixes for RMPocalypse S-1213.

significant / open / theoretical argument

Side channels, I/O leakage and denial of service are outside enclave protection

Tinfoil's documentation lists timing, power and electromagnetic side channels, host observation of access patterns and I/O, denial of service, supply-chain compromise and rollback as limitations S-1206.

S-1206

significant / open / open question

Private models can be checked only for consistency

For unpublished weights, the root hash appears in the attestation without the weights being exposed. Users can then confirm only that they get the same model each time S-0013.

S-0013

What still blocks use or stronger assurance

  1. The underlying TEE attestation does not resist attackers with physical access to the host.

    Dependency: TEE remote attestation for AI workloads

    S-1202S-1206
  2. No independent evaluation of the model-identity chain has been published.

Connections in the research map

Depends on

Mechanisms implemented

Concepts used

Organizations and developers

Sources and provenance

  1. S-0013 / Tier C

    How Tinfoil Proves Exactly What Model Is Running ↗

    Tinfoil Team · 2026 · Tinfoil

    Supports: Modelwrap design, binding to kernel command line, runtime enforcement, private models, overheads (provider-reported)

    Version and catalogue details
  2. S-1206 / Tier B

    A primer on secure enclaves ↗

    Tinfoil · 2026 · Tinfoil documentation

    Supports: supported hardware, trust model, documented limitations (provider-reported)

    Locator: Supported hardware; Trust model; Limitations

    Version and catalogue details
  3. S-1207 / Tier B

    Backend infrastructure ↗

    Tinfoil · 2026 · Tinfoil documentation

    Supports: boot measurement chain, boot-time GPU attestation check linked to the CPU attestation report, Sigstore publication, client verification, closed-source components (provider-reported)

    Version and catalogue details
  4. S-1208 / Tier B

    How verification works in Tinfoil ↗

    Tinfoil · 2026 · Tinfoil documentation

    Supports: connection-time vs audit-time verification; production deployment; no supported audit tool (provider-reported)

    Locator: In-band vs. out-of-band verification

    Version and catalogue details
  5. S-1209 / Tier B

    modelwrap: Reproducible dm-verity read-only image of Huggingface models ↗

    Tinfoil · 2026 · GitHub

    Supports: open-source code, MIT license, release v0.3.0, outputs and encryption mode

    Version and catalogue details
  6. S-1202 / Tier A

    TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition ↗

    J. Chuang, A. Seto, N. Berrios, S. van Schaik, C. Garman, D. Genkin · 2026 · 2026 IEEE Symposium on Security and Privacy (SP)

    Supports: independent demonstration of Intel TDX attestation forgery, SEV-SNP OpenSSL key recovery and H100 attestation relay

    Locator: §1.1, §8.3, §10.2

    Version and catalogue details
  7. S-1210 / Tier A

    Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing ↗

    J. De Meulemeester, D. Oswald, I. Verbauwhede, J. Van Bulck · 2026 · 47th IEEE Symposium on Security and Privacy (S&P 2026)

    Supports: SEV-SNP attestation breach with a DDR4 interposer (Battering RAM)

    Locator: Abstract; site FAQ

    Version and catalogue details
  8. S-1212 / Tier A

    RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP ↗

    B. Schlüter, S. Shinde · 2025 · 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)

    Supports: software-only SEV-SNP attestation forgery by a malicious hypervisor (RMPocalypse)

    Locator: Abstract; site

    Version and catalogue details
  9. S-1213 / Tier B

    SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020) ↗

    AMD · 2025 · AMD product security bulletin

    Supports: AMD firmware fixes for RMPocalypse (vendor-reported)

    Locator: Mitigation tables

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review