A common vocabulary

Terms of assurance.

The words in a verification proposal should be doing technical work. Start here for definitions, then follow the source and the claim boundary.

K-0017

Compartmentalization ↗

Dividing a facility's accelerators into groups with restricted communication between them, so that combining groups for large training runs becomes slow or impractical.

K-0024

Cryptographic commitment ↗

A way to fix a value now without revealing it, so that it can later be opened and shown not to have changed.

K-0019

Evidence binding ↗

Tying verification evidence to the specific device, workload, data and time it describes, so it cannot be substituted, replayed or misattributed.

K-0023

FLOP accounting ↗

Estimating or verifying how many floating-point operations a training run or other workload used, often to compare against a threshold in a rule.

K-0007

Hardware-enabled mechanism (HEM) ↗

A governance or verification function built into AI chips or closely attached hardware, such as usage reporting, location attestation or enforced limits.

K-0025

Inference and training workloads ↗

Training updates a model's weights from data. Inference uses fixed weights to produce outputs. Their different resource use underpins several verification methods.

K-0021

Interconnect bandwidth ↗

The data rate of links between accelerators or groups of them; large-scale training needs far more of it than inference, so limiting it constrains workloads.

K-0014

Network tap ↗

A device that copies the traffic on a network link for inspection without disrupting it; proposed for checking what AI data centres compute.

K-0008

Numerical nondeterminism ↗

Differences between runs, or between machines, in the results of the same AI computation, because floating-point rounding depends on the order of operations.

K-0003

Positive and negative claims ↗

A positive claim asserts that something is present or happened; a negative claim, that an activity or resource is absent; a mixed claim, both.

K-0011

Proof of (useful) work ↗

Evidence that a party spent a given amount of computation; in useful variants, the same work can also solve a problem someone wants solved.

K-0012

Proof of space ↗

A protocol in which a prover shows that it is dedicating a given amount of storage or memory, rather than computation, to a task.

K-0001

Prover ↗

The party that makes a claim about its own AI hardware, models or workloads and supplies the evidence a verifier checks.

K-0009

Recomputation ↗

Checking a claimed computation by re-running all of it, or a random sample, on hardware the verifier trusts and comparing the results.

K-0004

Remote attestation ↗

A process in which a device sends signed evidence about its state, such as software measurements, so a remote party can judge its trustworthiness.

K-0005

Root of trust ↗

A component that anchors security functions such as measurement, storage and reporting, and must be trusted because its misbehaviour cannot be detected.

K-0020

Sampling and assurance ↗

Checking a random sample of accelerators, workload segments or outputs rather than all of them, so that violations are caught with a calculable probability.

K-0013

Side channel ↗

An unintended path by which information leaks from a system through effects of its operation, such as timing, power draw or electromagnetic emissions.

K-0018

Threat model ↗

An explicit statement of who might attack a system, what they can do, and which threats the design covers or leaves out of scope.

K-0006

Trusted execution environment (TEE) ↗

An execution area protected by the processor that keeps the data inside confidential and unaltered, and the code unaltered, even from the host's own software.

K-0016

Undeclared compute ↗

AI-relevant hardware, or uses of declared hardware, that a prover has not reported, and that verification must therefore detect or rule out.

K-0002

Verifier ↗

The party that examines evidence supplied by, or collected about, a prover and decides whether the prover's claim holds.

K-0022

Weight exfiltration ↗

Unauthorized copying of a model's trained parameters out of the environment meant to contain them, by theft or through covert channels.

K-0010

Zero-knowledge proof ↗

A cryptographic protocol by which a prover convinces a verifier that a statement is true while revealing nothing beyond the fact that it is true.