Compartmentalization ↗
Dividing a facility's accelerators into groups with restricted communication between them, so that combining groups for large training runs becomes slow or impractical.
A common vocabulary
The words in a verification proposal should be doing technical work. Start here for definitions, then follow the source and the claim boundary.
Dividing a facility's accelerators into groups with restricted communication between them, so that combining groups for large training runs becomes slow or impractical.
A way to fix a value now without revealing it, so that it can later be opened and shown not to have changed.
Tying verification evidence to the specific device, workload, data and time it describes, so it cannot be substituted, replayed or misattributed.
Estimating or verifying how many floating-point operations a training run or other workload used, often to compare against a threshold in a rule.
A governance or verification function built into AI chips or closely attached hardware, such as usage reporting, location attestation or enforced limits.
Training updates a model's weights from data. Inference uses fixed weights to produce outputs. Their different resource use underpins several verification methods.
The data rate of links between accelerators or groups of them; large-scale training needs far more of it than inference, so limiting it constrains workloads.
A device that copies the traffic on a network link for inspection without disrupting it; proposed for checking what AI data centres compute.
Differences between runs, or between machines, in the results of the same AI computation, because floating-point rounding depends on the order of operations.
A positive claim asserts that something is present or happened; a negative claim, that an activity or resource is absent; a mixed claim, both.
Evidence that a party spent a given amount of computation; in useful variants, the same work can also solve a problem someone wants solved.
A protocol in which a prover shows that it is dedicating a given amount of storage or memory, rather than computation, to a task.
The party that makes a claim about its own AI hardware, models or workloads and supplies the evidence a verifier checks.
Checking a claimed computation by re-running all of it, or a random sample, on hardware the verifier trusts and comparing the results.
A process in which a device sends signed evidence about its state, such as software measurements, so a remote party can judge its trustworthiness.
A component that anchors security functions such as measurement, storage and reporting, and must be trusted because its misbehaviour cannot be detected.
Checking a random sample of accelerators, workload segments or outputs rather than all of them, so that violations are caught with a calculable probability.
An unintended path by which information leaks from a system through effects of its operation, such as timing, power draw or electromagnetic emissions.
Tamper evidence makes interference detectable; tamper resistance makes it difficult or costly; tamper response reacts to it, often by erasing secrets.
An explicit statement of who might attack a system, what they can do, and which threats the design covers or leaves out of scope.
An execution area protected by the processor that keeps the data inside confidential and unaltered, and the code unaltered, even from the host's own software.
AI-relevant hardware, or uses of declared hardware, that a prover has not reported, and that verification must therefore detect or rule out.
The party that examines evidence supplied by, or collected about, a prover and decides whether the prover's claim holds.
Unauthorized copying of a model's trained parameters out of the environment meant to contain them, by theft or through covert channels.
A cryptographic protocol by which a prover convinces a verifier that a statement is true while revealing nothing beyond the fact that it is true.