290 sources / A traceable bibliography

Read past the diagram.

Follow the original work. The source map’s evidence tiers describe publication type; they do not guarantee a result is correct or that it applies to your threat model.

A Peer-reviewed papers, standards, and official government publications.

B Preprints, technical reports, documentation, and public code.

C Author blogs, talks, and commentary. Provider claims remain provider claims.

290 of 290 sources

S-1206 / Tier B2026 / docs

A primer on secure enclaves ↗

Tinfoil

Tinfoil documentation · Last accessed by source map: 2026-10-08

Version: Living documentation with no publication date shown. The year is the year the page was accessed.

Catalogue note

Tinfoil's own documentation: the hardware it supports, its trust model, and the limitations it documents (physical attacks, side channels, I/O leakage, denial of service, supply chain, rollback). Supports "Tinfoil reports" statements.

Original catalogue record ↗
S-1100 / Tier A2026 / peer reviewed

A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning ↗

Z. Peng, C. Zhao, T. Wang, G. Liao, Z. Lin, Y. Liu, B. Cao, L. Shi, Q. Yang, S. Zhang

Artificial Intelligence Review, vol. 59, no. 7, article 157 · Last accessed by source map: 2026-09-25

Version: Read arXiv v2 (29 March 2026). Journal venue and DOI from Crossref (published 13 April 2026), checked 2026-09-24.

Catalogue note

Survey of ZKML literature from June 2017 to August 2025, organised into verifiable training, testing and inference.

Original catalogue record ↗
S-3613 / Tier B2026 / docs

About Epoch AI ↗

Epoch AI · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: data-first research nonprofit investigating the future of AI.

Original catalogue record ↗
S-3609 / Tier B2026 / docs

About MIRI ↗

Machine Intelligence Research Institute · Last accessed by source map: 2026-10-07

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description, re-read 2026-10-07: a nonprofit whose research and public outreach are intended to help prevent human extinction from the development of artificial superintelligence.

Original catalogue record ↗
S-3604 / Tier B2026 / docs

About NVIDIA ↗

NVIDIA · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: self-description as pioneer of accelerated computing.

Original catalogue record ↗
S-3607 / Tier B2026 / docs

About RAND ↗

RAND · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: nonprofit nonpartisan research organization and evidence-based decisions.

Original catalogue record ↗
S-1818 / Tier B2026 / docs

About us: Centre for the Governance of AI (GovAI) ↗

Centre for the Governance of AI · Last accessed by source map: 2026-09-25

Catalogue note

About page of GovAI. States that GovAI is a think tank that aims to help decision-makers in government and industry navigate the transition to a world with advanced AI; that it was founded at Yale University in 2016, became an academic centre at Oxford in 2018 and an independent nonprofit in 2021; that it has offices in London and Washington, DC; and that it is a US 501(c)(3) organization with a UK subsidiary. Self-description; supports "GovAI states" statements.

Original catalogue record ↗
S-1705 / Tier B2026 / docs

About: Oxford Martin AIGI ↗

Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-09-25

Catalogue note

About page of the Oxford Martin AI Governance Initiative (AIGI). States that AIGI is housed in the Martin School of the University of Oxford, studies the governance of AI from both technical and policy perspectives, and is co-led by Robert Trager and Maike Osborne; the AIGI homepage lists both as Co-Director. No page date. Self-description; supports "AIGI states" statements.

Original catalogue record ↗
S-1008 / Tier C2026 / blog

AI 2040 Plan A — Verification SITREP ↗

Amodo Design

Amodo Design · Last accessed by source map: 2026-09-25

Catalogue note

Undated status page with no byline; its status labels ("Active effort", "Not started", "Not on track", "Uncertain") may change. Content as viewed on 2026-09-23; the recomputation items were unchanged on 2026-09-25.

Original catalogue record ↗
S-3301 / Tier B2026 / docs

AI Data Centers Documentation – Methodology ↗

Epoch AI

Epoch AI · Last accessed by source map: 2026-09-25

Catalogue note

Living documentation for Epoch AI's AI data centers hub, launched as the Frontier Data Centers Hub; the name was checked on 2026-10-07; the page is undated and was read on 2026-09-25, when it gave the coverage estimate as of that date. Supports only statements attributed to Epoch AI.

Original catalogue record ↗
S-3608 / Tier B2026 / docs

AI Futures Project homepage ↗

AI Futures Project · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: small research group forecasting the future of AI funded by donations and grants.

Original catalogue record ↗
S-3601 / Tier B2026 / docs

Amodo Design: About Us ↗

Amodo Design · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: engineering company building tools for research.

Original catalogue record ↗
S-1007 / Tier B2026 / code

Amodo-Design/Inference-Recomputation-Prototype (GitHub repository) ↗

Amodo Design

GitHub · Last accessed by source map: 2026-10-07

Version: Pinned to tag v0.2.0 (commit 7a77d927197750e16e839215e4d2400cd33e2c71), which Amodo's 15 September 2026 post links as the code for its tapped prototype (S-1312); read on 2026-10-07. Tag v0.1.0 is the earlier commit 4bc6872 (10 Sep 2026). The v0.2.0 README describes capture by a software sidecar and by a passive optical tap feeding a frame processor.

Catalogue note

The README describes its DiFR module as a vendored, modified copy of the upstream difr library.

Original catalogue record ↗
S-1321 / Tier B2026 / code

Amodo-Design/PoSE-Memory-Wiping (GitHub repository) ↗

Amodo Design

GitHub · Last accessed by source map: 2026-09-25

Version: Pinned to commit fae0935d37a4e2b983334e5b999cbc2c4b6edf67 (head of main on 2026-09-23, committed 2026-09-14; 2 commits, no tags).

Catalogue note

Linked from Amodo's note "Improving Disk Wiping Speed for Memory Wipes" (S-1303). The README says the repository is the disk-wiping path only and excludes the verifier and the RAM and GPU-HBM session code.

Original catalogue record ↗
S-3602 / Tier B2026 / docs

Attestable homepage ↗

Attestable · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: development of zero-knowledge proofs for AI systems.

Original catalogue record ↗
S-3360 / Tier C2026 / blog

Auditing a Frontier Model Without Seeing its Weights ↗

D. McCann-Sayles, T. Verma

Tinfoil blog · Last accessed by source map: 2026-09-25

Catalogue note

Tinfoil's account of Pour Demain running interpretability evaluations (vllm-lens) on GLM-5.1, about 744 billion parameters, on eight H200 GPUs in Tinfoil's confidential-computing platform, with the lab supplying the model, the auditor its evaluation code, and the weights kept inside the enclave. Reports 33-38% overhead with interpretability hooks enabled. Supports only "Tinfoil reports" statements.

Original catalogue record ↗
S-1207 / Tier B2026 / docs

Backend infrastructure ↗

Tinfoil

Tinfoil documentation · Last accessed by source map: 2026-10-08

Version: Living documentation with no publication date shown. The year is the year the page was accessed.

Catalogue note

Tinfoil's description of its measured boot chain, reproducible builds, Sigstore publication of expected measurements, and client-side verification. Supports "Tinfoil reports" statements.

Original catalogue record ↗
S-1013 / Tier B2026 / docs

Batch Invariance (vLLM documentation) ↗

vLLM project

vLLM documentation (GitHub, docs/features/batch_invariance.md) · Last accessed by source map: 2026-09-25

Version: Main branch as viewed on 2026-09-25 (GitHub source file; the rendered page at docs.vllm.ai did not return body text to the fetch tool on 2026-09-23). The feature is described as beta, supported on NVIDIA GPUs of compute capability 8.0 or higher and on Intel XPUs with Triton, and tested on dense and mixture-of-experts models.

Original catalogue record ↗
S-1210 / Tier A2026 / peer reviewed

Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing ↗

J. De Meulemeester, D. Oswald, I. Verbauwhede, J. Van Bulck

47th IEEE Symposium on Security and Privacy (S&P 2026) · Last accessed by source map: 2026-10-08

Version: Read the authors' site and the paper PDF linked from it (https://batteringram.eu/batteringram.pdf) on 2026-09-24. Venue from the BibTeX entry on the authors' site (47th IEEE S&P, May 2026); no DOI is printed in the PDF or on the site.

Catalogue note

Independent attack paper (KU Leuven, University of Birmingham and Durham University). DDR4 memory interposer with a bill of materials of $47.62. Reports arbitrary plaintext access to Intel Scalable SGX enclaves, extraction of SGX's platform provisioning key, and a full attestation breach on up-to-date AMD SEV-SNP by replaying launch digests. The site states that Intel and AMD acknowledged the findings but consider physical attacks on DRAM out of scope, and links Intel's guidance and AMD bulletin AMD-SB-3024. Hardware schematics and proof-of-concept code at https://github.com/batteringramattack/batteringram.

Original catalogue record ↗
S-1804 / Tier C2026 / blog

Beyond Prompt Injection: Hacking Apple's Private Cloud Compute ↗

D. Selmanaj

Sentry blog · Last accessed by source map: 2026-10-08

Catalogue note

Independent researcher's write-up of CVE-2026-20685, found in Apple's Virtual Research Environment: a path traversal in darwin-init's cryptex extraction gave root file writes that survived the node's userspace reboot and redirected splunkloggingd telemetry, exposing per-request metadata such as token counts and timings (the post does not say whether prompt or response content was exposed). All work was done in the VRE. States that the tampered node was indistinguishable from a clean one under `pccvre attestation verify`, and that Apple paid a $150,000 bounty.

Original catalogue record ↗
S-0020 / Tier B2026 / preprint

Bit-Exact AI Inference Verification Without Performance Tradeoffs ↗

N. Cankaya

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25

Version: arXiv v1 29 May 2026; v2 5 June 2026. The arXiv comments field reads "Best paper award, ICML 2026 TAIGR workshop"; the paper is listed in the workshop's poster session (https://icml.cc/virtual/2026/workshop/54084). Checked 2026-09-24.

Catalogue note

Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3129 / Tier A2026 / peer reviewed

Blueprint, Bootstrap, and Bridge: A Security Look at NVIDIA GPU Confidential Computing ↗

Z. Gu, E. Valdez, S. Ahmed, J. J. Stephen, M. V. Le, H. Jamjoom, S. Zhao, Z. Lin

Proceedings of the 9th MLSys Conference (MLSys 2026) · Last accessed by source map: 2026-09-25

Version: Read arXiv v2 (2026-04-17), whose header names the 9th MLSys Conference (Bellevue, 2026). v1 (2025-07-03) was titled "NVIDIA GPU Confidential Computing Demystified".

Catalogue note

Independent security analysis (IBM Research and The Ohio State University) of NVIDIA's GPU confidential computing on Hopper. Concludes that bulk command and data transfers are protected, but some metadata, timing behaviour and coordination signals remain in unprotected shared memory, which can reveal computational behaviour and in some cases allow manipulation of operations ("a partial loss of integrity"). Findings were disclosed to NVIDIA PSIRT. No attestation break is reported.

Original catalogue record ↗
S-3363 / Tier C2026 / blog

Building an Adversarial Testbed for AI Verification in Europe ↗

Lucid Computing

Lucid Computing (Substack) · Last accessed by source map: 2026-09-25

Catalogue note

Lucid's announcement of an adversarial testbed it is "building and operating" inside an unnamed "government-funded research institute that runs clusters for domestic workloads". The host institute "holds technical authority over adversarial testing" and sets the test plan. The first configuration retrofits two eight-GPU H100 servers against three claims (where compute runs, how it is used, what model is loaded), with an 18-month goal. Supports only "Lucid reports" statements.

Original catalogue record ↗
S-3022 / Tier C2026 / blog

Building Delphi: Pricing, Settlement, and Agentic Trading ↗

D. Jedamski

Gensyn blog · Last accessed by source map: 2026-09-25

Catalogue note

Developer's post on Delphi, Gensyn's information-market app. States that "Delphi is live on Gensyn Mainnet" and that "hosted REE settlement is available for partner markets", and that open-source models running inside REE "produce a receipt that can be independently rerun to verify the answer". Describes no dispute process and does not mention Verde. Supports only "Gensyn reports" statements.

Original catalogue record ↗
S-3612 / Tier B2026 / docs

Center for a New American Security: Mission ↗

Center for a New American Security · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: independent bipartisan nonprofit producing national-security and defense policy.

Original catalogue record ↗
S-3361 / Tier C2026 / blog

Confidential computing can enable better frontier AI auditing ↗

A. Tlaie Boria

Pour Demain · Last accessed by source map: 2026-09-25

Catalogue note

The auditor's own account. States that all measurements were collected on a production confidential-computing platform (Tinfoil Containers, Intel TDX, 8x NVIDIA H200) running GLM-5.1, a 744-billion-parameter open-weights mixture-of-experts model; five interpretability workloads; "raw tensors never cross the enclave boundary". Governance features were shown at single-session level only. Links a PDF white paper that was not read.

Original catalogue record ↗
S-3321 / Tier B2026 / docs

Confidential Space overview ↗

Google Cloud

Google Cloud documentation · Last accessed by source map: 2026-09-25

Version: Page last updated 2026-09-22 (UTC), read on 2026-09-25.

Catalogue note

Vendor documentation; supports only "Google reports" statements. Describes an isolated environment to operate on sensitive data from multiple parties, with data collaborators, workload authors and workload operators; data is released only to workloads whose attestation meets the collaborators' conditions, and the operator has no access to the data. Runs on AMD SEV, Intel TDX, or Intel TDX with NVIDIA Confidential Computing.

Original catalogue record ↗
S-3322 / Tier B2026 / docs

Confidential Space release notes ↗

Google Cloud

Google Cloud documentation · Last accessed by source map: 2026-09-25

Catalogue note

Vendor release notes; support only "Google reports" statements. Confidential Space generally available on 2023-03-28; on Intel TDX (C3) on 2025-03-31; on H100 GPUs (a3-highgpu-1g) on 2026-04-29; on H100 with Intel Trust Authority attestation on 2026-09-15.

Original catalogue record ↗
S-0011 / Tier B2026 / preprint

Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance ↗

S. Ding, E. Lee, R. Cheng, D. Kang

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25

Version: Only the abstract was read, on the ICML 2026 virtual poster page (https://icml.cc/virtual/2026/78562), on 2026-09-23 and 2026-09-25; the OpenReview forum and PDF were not reachable with the fetch tool. No arXiv version was found.

Catalogue note

Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1505 / Tier B2026 / code

Cove: Compositional Multi-Party Confidential Workflows for Verifiable AI Governance (reference implementation) ↗

covehub

GitHub · Last accessed by source map: 2026-10-08

Version: Pinned to commit a3e4904926d7c9c160d232222d95f5db316627ca (main as of 2026-09-23, obtained with git ls-remote). Read README.md, docs/internal/architecture.md and docs/internal/security_model.md at that commit via raw.githubusercontent.com; the files were identical to main on that date. On 2026-09-25 security_model.md was re-read at the pinned commit and README.md on main; the github.com repository page returned 404 to the fetch tool, while raw files on main still loaded.

Catalogue note

Reference implementation of S-0011; developer documentation of its own system supports "reports" statements only.

Original catalogue record ↗
S-1410 / Tier C2026 / blog

Covert AI Projects ↗

B. Halstead, T. Larsen

AI 2040 · Last accessed by source map: 2026-09-25

Catalogue note

Supplement to the AI 2040 scenario (AI Futures Project). The supplement page shows no date; the AI Futures blog announced AI 2040 on 2026-07-09, so the year is inferred from that announcement.

Original catalogue record ↗
S-1805 / Tier B2026 / docs

CVE-2026-20685 (Apple Private Cloud Compute Server Software) ↗

Apple (CVE Numbering Authority)

CVE Program · Last accessed by source map: 2026-09-25

Version: Read through the CVE Services API (https://cveawg.mitre.org/api/cve/CVE-2026-20685) because the cve.org page needs JavaScript. Affected product: Private Cloud Compute Server Software before 5E290.3.

Catalogue note

Vendor-assigned description: "An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation."

Original catalogue record ↗
S-3126 / Tier A2026 / peer reviewed

DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes ↗

J. De Meulemeester, S. Gloor, P. Jattke, D. Moghimi, D. Oswald, M. Thompson, K. Razavi, I. Verbauwhede, J. Van Bulck

2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26) · Last accessed by source map: 2026-10-08

Version: Read the authors' site and the paper PDF linked from it (https://ddropattack.eu/ddrop.pdf) on 2026-09-25. The PDF names CCS '26 (The Hague); the conference is in November 2026, and no DOI is printed. Disclosed on 2026-09-14.

Catalogue note

Independent attack paper (KU Leuven, ETH Zurich, Durham University and Google). An active DDR5 RDIMM interposer with a bill of materials of $159 injects parity errors so that cache-line writebacks are silently dropped, which the missing freshness protection in scalable memory encryption does not detect. Attacker model: brief physical access to install the interposer, plus control of host software and BIOS. Demonstrates forcing any TD into debug mode and forging attestation reports on an up-to-date Intel TDX platform, and integrity breaks of Scalable SGX and AMD SEV-SNP (no SEV-SNP attestation forgery reported). The site states that Intel and AMD consider physical attacks on DRAM out of scope for current products and issued security advisories on disclosure (AMD-SB-3048).

Original catalogue record ↗
S-3220 / Tier C2026 / blog

De-risking Interconnect Limits for AI Verification ↗

A. Scher, D. Sarbakysh, A. Moskvin

MIRI Technical Governance Team · Last accessed by source map: 2026-09-25

Catalogue note

Prototype of inter-node bandwidth monitoring against a threshold on a two-node Azure cluster (four A100 PCIe GPUs, one 100 GbE link), with violating training, compliant inference and a DiLoCo evasion workload. Carried out by Sarbakysh and Moskvin through SPAR under Scher's supervision. Code and reproduction instructions are linked at https://github.com/Yayka/ml-infra-profiler (MIT licence); no commit could be pinned, because the commit list could not be read on 2026-09-25.

Original catalogue record ↗
S-1011 / Tier B2026 / tech report

DeepSeek-V4: Towards Highly Efficient Million-Token Context Intelligence ↗

DeepSeek-AI

arXiv · Last accessed by source map: 2026-09-25

Version: Read v1 (PDF), section 3.3 on batch-invariant and deterministic kernel libraries. The abstract page gives a v1 timestamp of 26 Apr 2026, which does not match the 2606 identifier; date left unset.

Catalogue note

Developer's report on its own systems; kernel statements are provider-reported. Several hundred authors; listed under the organisational author.

Original catalogue record ↗
S-0059 / Tier A2026 / peer reviewed

Detecting Compute Structuring in AI Governance Is Likely Feasible ↗

E. Seferis, T. Fist

Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment) · Last accessed by source map: 2026-09-23

Version: An earlier version appeared at the ICML 2025 Workshop on Technical AI Governance (https://openreview.net/forum?id=qseqw1sWzz). AAAI proceedings page checked 2026-09-24 for venue, pages and DOI.

Catalogue note

Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-0037 / Tier B2026 / preprint

Detecting Hidden ML Training With Zero-Overhead Telemetry ↗

R. Rahman, S. Tajdari

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25

Version: v1 (2026-06-17) read on 2026-09-25. The paper header reads "Proceedings of the Second Workshop on Technical AI Governance Research (TAIGR) at the 43rd International Conference on Machine Learning, Seoul". Affiliations: R. Rahman (Machine Intelligence Research Institute), S. Tajdari (University of Virginia).

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-0060 / Tier B2026 / preprint

Does Distributed Training Undermine Compute Governance? ↗

R. Rahman

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25

Version: arXiv v1, 28 May 2026. Poster at the Second Workshop on Technical AI Governance Research (ICML 2026), per the workshop page (https://icml.cc/virtual/2026/workshop/54084), checked 2026-09-25.

Catalogue note

Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3320 / Tier B2026 / tech report

Double Blind Evals: Resolving the Dual Confidentiality Dilemma in AI Safety Auditing ↗

A. Trask, S. Messing, V. Pahwa, P. Maham, R. Kolga, A. Frantz, A. Tash, K. Thomas, S. McGregor, G. Balston, P. Paskov, M. Brundage, A. Vij, B. Hillenbrand, A. Karargyris, T. Acosta, J. Fenster, M. Eilish, R. Elasmar, M. Khan, K. van der Veen, R. S, S. Wagh, S. Gabriel, P. Werneck, L. Strahm, K. McDonough, R. Falcon, K. Lum, W. Isaac

Google DeepMind · Last accessed by source map: 2026-10-08

Version: Technical report linked from Google DeepMind's blog post "Piloting the world's first double-blind AI evaluations" (https://deepmind.google/blog/piloting-the-worlds-first-double-blind-ai-evaluations/, dated 2026-08-27). The PDF prints no date. Author affiliations as printed: Google, AVERI, Singapore AISI, OpenMined and ML Commons. No arXiv version was found on 2026-09-25.

Catalogue note

Report by the pilot's participants on their own system; supports "the participants report" statements. Gemini 2.5 Flash Lite was evaluated against private AILuminate prompts in a GCP Confidential Space enclave (a3-highgpu-1g, one NVIDIA H100 with Intel TDX), using OpenMined's PySyft; both parties verified the attestation before uploading assets.

Original catalogue record ↗
S-3020 / Tier B2026 / preprint

EigenAI: Deterministic Inference, Verifiable Results ↗

D. Ribeiro Alves, V. Patankar, M. Pereira, J. Stephens, N. Vaziri, S. Kannan

arXiv · Last accessed by source map: 2026-09-25

Version: v1 (30 Jan 2026), the only version, read in HTML.

Catalogue note

Developer's paper on its own system (all authors give eigenlabs.org addresses); statements about EigenAI are provider-reported. Describes a deterministic inference engine built on llama.cpp with custom GEMM and reduction kernels, and an optimistic re-execution protocol in which a stake-weighted committee re-executes challenged outputs inside TEEs. Table 5 reports bitwise-identical outputs on the same host and GPU and across hosts with the same GPU SKU, and a 0.0% match between A100 and H100.

Original catalogue record ↗
S-1503 / Tier B2026 / preprint

Enabling Verifiably-Scoped Monitoring through Large Language Models and Trusted Compute ↗

B. Penchas, G. Zhao, R. Rinberg

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25

Version: Only the abstract was read, on the ICML 2026 virtual poster page. The OpenReview forum (https://openreview.net/forum?id=AWZJq6O7Cj) was not reachable with the fetch tool.

Catalogue note

The second author appears as "G Zhao" on the ICML page.

Original catalogue record ↗
S-1802 / Tier C2026 / blog

Expanding Private Cloud Compute ↗

Apple Security Engineering and Architecture (SEAR)

Apple Security Research blog · Last accessed by source map: 2026-10-08

Catalogue note

Apple's announcement that PCC extends to Google Cloud systems with NVIDIA GPUs, using NVIDIA Confidential Computing, Intel CPUs with TDX and Google's Titan chip; for components that could be abused to exfiltrate user data if compromised, attestation "rooted in at least two separate roots of trust from independent vendors"; attested keys held in a separate confidential VM; binaries to be published and live nodes available in research mode through the Apple Security Bounty. States that PCC on Google Cloud "will be gradually ramping towards the complete set of protections throughout the summer preview period". Supports only "Apple reports" statements.

Original catalogue record ↗
S-1702 / Tier B2026 / docs

Experiments: Lucid Labs ↗

Lucid Computing · Last accessed by source map: 2026-10-08

Catalogue note

Lucid Computing's page on the bare-metal research cluster that it says the Verifiable Compute Foundation provides and allocates: accelerators, research "layers", and access terms ("Free for qualifying safety & verification research"; Lucid "takes no part in allocation decisions"). The page says the cluster opens to the community in November, without a year (2026 by context). No page date; copyright 2026. Supports "Lucid reports" statements only.

Original catalogue record ↗
S-3127 / Tier A2026 / peer reviewed

Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP ↗

B. Schlüter, C. Wech, S. Shinde

35th USENIX Security Symposium (USENIX Security '26) · Last accessed by source map: 2026-10-08

Version: USENIX Security '26 presentation page (pp. 5613–5632, August 2026) and the paper PDF (https://www.shwetashinde.org/publications/fabricked_usenix26.pdf), read on 2026-09-25. The authors' site (https://fabricked-attack.github.io/) could not be read by the fetch tool.

Catalogue note

Independent attack paper (ETH Zurich). A software adversary that controls the hypervisor and UEFI firmware misconfigures Infinity Fabric routing so that writes by the AMD Secure Processor during SEV-SNP initialisation go astray, leaving the system falsely initialised. Demonstrated on a Zen 5 EPYC 9135: arbitrary read and write in the victim CVM, debug mode enabled after attestation, and forged attestation reports. The authors could not test Zen 3 or Zen 4. AMD's bulletin is S-3128.

Original catalogue record ↗
S-1300 / Tier B2026 / preprint

Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors ↗

N. Cankaya, J. Kryś, J. Ng, L. Marks, F. Krückel

arXiv · Last accessed by source map: 2026-09-25

Version: v1, submitted 9 June 2026; read via the arXiv HTML rendering. The Oxford Martin AI Governance Initiative published an earlier version dated April 2026 (https://aigi.ox.ac.uk/wp-content/uploads/2026/04/Fingerprinting_All_AI_Cluster_IO.pdf; publication page dated 28 April 2026) before arXiv v1. Both versions give the first author's affiliations as MATS and the Oxford Hardware AI Governance Lab. arXiv still lists only v1, with no journal reference, on 2026-09-25.

Original catalogue record ↗
S-0003 / Tier B2026 / preprint

Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies ↗

M. Brundage, N. Dreksler, A. Homewood, S. McGregor, P. Paskov, C. Stosz, G. Sastry, A. F. Cooper, G. Balston, S. Adler, S. Casper, M. Anderljung, G. Werner, S. Mindermann, V. Mavroudis, B. Bucknall, C. Stix, J. Freund, L. Pacchiardi, J. Hernandez-Orallo, M. Pistillo, M. Chen, C. Painter, D. W. Ball, C. O'Keefe, G. Weil, B. Harack, G. Finley, R. Hassan, S. Emmons, C. Foster, A. Reuel, B. Treece, Y. Bengio, D. Reti, R. Bommasani, C. Trout, A. S. Shamsabadi, R. Dattani, A. Weller, R. Trager, J. Sevilla, L. Wagner, L. Soder, K. Ramakrishnan, H. Papadatos, M. Murray, R. Tovcimak

arXiv · Last accessed by source map: 2026-09-25

Catalogue note

Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3611 / Tier B2026 / docs

Future of Life Institute: Global Institutions Governing AI ↗

Future of Life Institute · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: self-description as independent nonprofit and mission to steer transformative technology away from extreme risks.

Original catalogue record ↗
S-1812 / Tier B2026 / code

gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository) ↗

Gensyn

GitHub · Last accessed by source map: 2026-10-07

Version: Main branch as viewed on 2026-10-07 (commit 9e9a784, 5 October 2026); README patch notes run to v0.8.0 (5 October 2026), after v0.7.0 (30 September 2026), and v0.2.0 (20 April 2026) adds pipeline parallelism for models of up to 72B and a threefold cut in reproducible-mode overhead. The SDK is MIT-licensed; the REE compiler and reproducible-operators binaries ship in Docker images under a proprietary binary licence.

Catalogue note

REE runs LLM inference reproducibly and writes JSON receipts with the model, prompt, output and the metadata needed to reproduce the run, with verify and validate subcommands. Developer's repository.

Original catalogue record ↗
S-3560 / Tier B2026 / docs

Gensyn: machines that predict the future ↗

Gensyn · Last accessed by source map: 2026-09-25

Catalogue note

Company homepage, read 2026-09-25. The title is the HTML page title. States that "Gensyn builds AI that forecasts – and keeps improving – by verifiably closing the loop between prediction and reality", and lists Delphi (information markets) and REE (Reproducible Execution Environment) among its products. Supports "Gensyn reports" statements only.

Original catalogue record ↗
S-1511 / Tier C2026 / blog

Get Involved in Verification ↗

AI Futures Project

AI 2040 · Last accessed by source map: 2026-09-25

Version: The page states it was updated on 9 July 2026. Content as viewed on 2026-09-23; the workstream statuses were unchanged on 2026-09-25, and the site changelog lists only changes to event and contact links on the page since then.

Catalogue note

Companion page to S-0067 listing open technical problems for the plan's verification components.

Original catalogue record ↗
S-1403 / Tier B2026 / preprint

GPU Fingerprinting for Location Verification ↗

W. Tee, J. Happel

arXiv · Last accessed by source map: 2026-09-25

Version: v1 (2026-05-03) read on 2026-09-23; v2 (2026-06-01) read on 2026-09-25 via arxiv.org/html/2605.01930v2. The figures cited (24 H200 GPUs, 480 runs, 98.8% single-run and 100% paired-run accuracy, about 2.9 s per run) and the stated limitations are unchanged in v2. Affiliations: W. Tee (Pivotal Research), J. Happel (TamperSec).

Original catalogue record ↗
S-1703 / Tier B2026 / docs

Hardware AI Governance Lab ↗

Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-10-08

Catalogue note

Programme page of the Hardware AI Governance Lab (HAIGL), "an interdisciplinary initiative hosted by the Oxford Martin AI Governance Initiative". States the lab's aims, says it expects to release its first hardware governance design profile in late 2026, names Amro Awad and Robert Trager as HAIGL Co-Directors and Ben Harack as Co-founder & Research Lead, and lists recent publications, including S-1300 (dated 28 April 2026 on the page) and S-1704. No page date. Self-description; supports "the lab states" statements.

Original catalogue record ↗
S-0036 / Tier B2026 / preprint

Hardware Mechanisms to Dynamically Throttle AI Performance ↗

H. Ma, J. Forzani, L. Malek, D. Wentzlaff

arXiv · Last accessed by source map: 2026-09-25

Version: Author order follows the current arXiv HTML version (arxiv.org/html/2607.18069), read 2026-09-23: Ma, Forzani, Malek, Wentzlaff, and it was unchanged on 2026-09-25. The v1 HTML (arxiv.org/html/2607.18069v1) lists Malek before Forzani, as the bibliography did.

Catalogue note

Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1010 / Tier A2026 / peer reviewed

Hawkeye: Reproducing GPU-Level Non-Determinism ↗

E. Badash, D. Boneh, I. Komargodski, M. Srivastava

Proceedings of Machine Learning and Systems 8 (MLSys 2026) · Last accessed by source map: 2026-10-08

Version: Full text read from arXiv HTML v2 (15 May 2026); MLSys proceedings abstract page checked. The arXiv abstract page could not be rendered by the fetch tool, so the v1 date was not confirmed.

Catalogue note

Code at github.com/badasherez/gpu-simulator (MIT; release tag "MLSys Release", 4 Apr 2026). Badash and Komargodski are at Pearl Research Labs, Boneh and Srivastava at Stanford University.

Original catalogue record ↗
S-1510 / Tier B2026 / tech report

Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering ↗

S. F. Comer, H. Pavela, V. Gandhi, K. Siler-Evans, E. Devendorf, B. Kelley, J. Gimbi, J. Aguirre, G. Kulp, M. Stalczynski, M. J. Malone

RAND Corporation (Research Report RR-A4827-1) · Last accessed by source map: 2026-09-25

Version: Read the landing page and the PDF (https://www.rand.org/content/dam/rand/pubs/research_reports/RRA4800/RRA4827-1/RAND_RRA4827-1.pdf), 51 pages. Author list taken from the PDF title page.

Catalogue note

Produced by RAND's Center on AI, Security, and Technology (CAST).

Original catalogue record ↗
S-1112 / Tier B2026 / preprint

Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference ↗

C. Gong, B. Liu, M. Li

arXiv · Last accessed by source map: 2026-09-25

Version: v1 (30 July 2026), read via the arXiv HTML and PDF renderings; the abstract page did not render for the fetch tool. Author order is as printed on the paper's title page; a mirror of the arXiv listing (pith.science) lists B. Liu first. A co-author's web page labels the paper "IEEE S&P 2026", but no proceedings record was found and a co-author's CV lists it as under submission, so it is recorded as a preprint.

Catalogue note

Independent analysis (University of Southern California) of zero-knowledge proofs of LLM inference. Shows that valid proofs do not bind the computation spent, using "ghost weights"; experiments use the proof procedure of zkGPT on a 6-layer, 512-dimensional transformer.

Original catalogue record ↗
S-1208 / Tier B2026 / docs

How verification works in Tinfoil ↗

Tinfoil

Tinfoil documentation · Last accessed by source map: 2026-09-25

Version: Living documentation with no publication date shown. The year is the year the page was accessed.

Catalogue note

Tinfoil's overview of connection-time verification and transparency logs. Supports "Tinfoil reports" statements.

Original catalogue record ↗
S-3130 / Tier B2026 / preprint

Insecure Despite Proven Updated: Extracting the Root VCEK Seed on EPYC Milan via a Software-Only Attack ↗

M. Shen, Y. Qin

arXiv · Last accessed by source map: 2026-10-08

Version: arXiv v1, submitted 13 May 2026. Re-read the abstract and HTML on 2026-10-08, including the threat model, affected EPYC Milan platform and vendor-response appendix. No venue is given.

Catalogue note

Attack preprint (Institute of Software, Chinese Academy of Sciences). With root control of the host and the ability to rewrite the SPI flash, but no physical access, the attacker downgrades an EPYC Milan (Zen 3) platform to legacy AMD Secure Processor firmware, gains code execution there (MilanLaunchy) and extracts the full hardware root seed from which SEV-SNP's VCEK attestation keys are derived (BadFuse). The authors state this lets them forge attestation reports for any firmware version. Disclosed to AMD in January and April 2026; AMD's bulletin on MilanLaunchy is S-3131.

Original catalogue record ↗
S-3610 / Tier B2026 / docs

Institute for AI Policy and Strategy homepage ↗

Institute for AI Policy and Strategy · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: nonpartisan think tank producing AI policy research.

Original catalogue record ↗
S-1706 / Tier B2026 / docs

Intelligence Security Laboratories: Building secure infrastructure for transformative AI ↗

Intelligence Security Laboratories · Last accessed by source map: 2026-09-25

Catalogue note

Homepage of Intelligence Security Laboratories (ISL); intseclab.org redirects here. States that ISL is a nonprofit research lab for high-security AI systems, its aim of developing and demonstrating the security that critical AI deployments need, its role as integrator of the secure data centre as a whole system, its use of STPA-Sec and formal methods, and its plan to hand knowledge and artifacts to others; refers to RAND's secure inference data center report (S-1510) for details of STPA-Sec. The footer gives 501(c)(3) nonprofit status. No page date. Self-description; supports "ISL states" statements.

Original catalogue record ↗
S-3180 / Tier B2026 / blog

Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization ↗

C. Shrauder, G. Frederick

NVIDIA Technical Blog · Last accessed by source map: 2026-09-25

Catalogue note

NVIDIA's description of its own fleet-management service; supports only "NVIDIA reports" statements. States that the service is generally available at no cost for Hopper, Blackwell and Vera Rubin GPUs; that a read-only, host-based agent (built on GPUd, DCGM and the NVIDIA Attestation SDK) streams power, temperature, performance, health and configuration telemetry to an NVIDIA cloud service; that the agent is released as open source "for auditability" (github.com/NVIDIA/Fleet-Intelligence-Agent); and that GPU attestation evidence obtained at run time is signed with on-device certificates rooted in NVIDIA's root of trust and verified with NRAS. It does not say that the telemetry values themselves are signed. Follows the December 2025 announcement in S-1413.

Original catalogue record ↗
S-0044 / Tier A2026 / peer reviewed

Kraken: Higher-order EM Side-Channel Attacks on DNNs in Near and Far Field ↗

P. Horvath, I. Shumailov, L. Chmielewski, L. Batina, Y. Yarom

IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026) · Last accessed by source map: 2026-09-25

Version: arXiv v1 3 Mar 2026, v3 27 Mar 2026. Listed among the accepted papers of IEEE SaTML 2026 (Munich, 23–25 March 2026), https://satml.org/2026/accepted-papers/, checked 2026-09-25.

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1808 / Tier B2026 / code

Lagrange-Labs/deep-prove (GitHub repository) ↗

Lagrange Labs

GitHub · Last accessed by source map: 2026-09-25

Version: Main branch as viewed on 2026-09-25 (1,219 commits, no releases). Licensed under the Lagrange License.

Catalogue note

Developer's repository. README reports end-to-end proofs of GPT-2, Gemma 3 and Llama 2 inference with sumcheck and logup GKR, and on a 24-core, 504 GB CPU server: GPT-2 at 512 tokens in 7.6 min (verify 1.3 s, 10.7 MiB proof) and Gemma 3 at 512 tokens in 19 min; at least 99.6% cosine similarity to floating point at 12-bit quantization (GPT-2).

Original catalogue record ↗
S-1407 / Tier B2026 / docs

Lucid Developer Platform documentation ↗

Lucid Computing · Last accessed by source map: 2026-09-25

Catalogue note

Pages read on 2026-09-23 include the index, concepts/architecture.html, concepts/glossary.html and reference/auditor-catalog.html; the auditor catalog and architecture pages were re-read on 2026-09-25. Supports "Lucid reports" statements only.

Original catalogue record ↗
S-1701 / Tier B2026 / docs

Lucid Labs: the verification flywheel ↗

Lucid Computing · Last accessed by source map: 2026-10-08

Catalogue note

Lucid Computing's page on its research programme: an experimentation cluster provided by the Verifiable Compute Foundation, which it describes as "an independent nonprofit working to create a toolbox of AI verification techniques"; red-teaming with national security agencies and government research institutes; deployment; and standards work. No page date; copyright 2026. Supports "Lucid reports" statements only.

Original catalogue record ↗
S-1302 / Tier C2026 / blog

Memory Wipes - Performance Analysis ↗

Amodo Design

Amodo Design · Last accessed by source map: 2026-09-25

Version: Page carries a correction note saying the original post's wipe-time results were revised; figures used here are the corrected ones.

Catalogue note

No individual byline on the page.

Original catalogue record ↗
S-3131 / Tier B2026 / docs

MilanLaunchy Firmware Loader (AMD-SB-3045) ↗

AMD

AMD product security bulletin · Last accessed by source map: 2026-09-25

Catalogue note

AMD's own bulletin on MilanLaunchy (S-3130); supports only "AMD reports" statements. Lists CVE-2021-26315, CVE-2024-21944 and CVE-2024-21981, rates the report informational, and calls it "a legacy attack that was previously mitigated in 2021". Mitigation: MilanPI 1.0.0.3 or later for EPYC 7003.

Original catalogue record ↗
S-0068 / Tier A2026 / peer reviewed

NanoZK: Privacy-Preserving Verifiable Inference for Large Language Models via Layerwise Zero-Knowledge Proofs ↗

Z. Wang

International Conference on Information and Communications Security (ICICS 2026) · Last accessed by source map: 2026-09-25

Version: Current arXiv HTML read on 2026-09-25; its abstract matches v2, which states acceptance at the 28th ICICS (Springer LNCS, Fukui, 27–30 October 2026) and is an extended version with appendices not in the proceedings. v1 (March 2026) reports different timings. The abstract gives 3.5–3.7 KB per sub-circuit proof, while §3.1 and §6.1 give 3.2–3.7 KB.

Catalogue note

Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1402 / Tier B2026 / tech report

Near-Term Verification Methods for AI Chip Exports ↗

B. Avellar, E. Grunewald

Institute for AI Policy and Strategy · Last accessed by source map: 2026-10-07

Version: IAPS report dated 19 August 2026; its research page, read on 2026-10-07, says it was written by Erich Grunewald and co-authored by Bruna Avellar. arXiv 2609.07637 v1 (7 September 2026) states that it is a reformatted version of that report. v1 read via the arXiv HTML rendering (arxiv.org/html/2609.07637); the abstract page returned no extractable text to the fetch tool. Affiliations as shown: B. Avellar (independent researcher), E. Grunewald (Institute for AI Policy and Strategy).

Original catalogue record ↗
S-1310 / Tier C2026 / blog

Network Tapping for AI Verification: A Technical Assessment ↗

Amodo Design

Amodo Design · Last accessed by source map: 2026-09-25

Catalogue note

No individual byline on the page. Amodo republished the note on its Substack on 2026-05-14 as "Tech note: network taps for AI verification" (https://amodo.substack.com/p/tech-note-network-taps-for-ai-verification), with the byline Thomas Milton and Sam Reynolds.

Original catalogue record ↗
S-1600 / Tier A2026 / gov doc

NIST Computer Security Resource Center (CSRC) Glossary ↗

National Institute of Standards and Technology

NIST Computer Security Resource Center · Last accessed by source map: 2026-09-23

Version: Living glossary. Each entry reproduces definitions from named NIST publications; locators in citing records give the term page and the underlying publication (e.g. NISTIR 8320, NIST SP 800-63-4). Entries read on 2026-09-23: roots_of_trust, trusted_execution_environment, attestation, side_channel_attack, tamper_evident, tamper_resistant, threat_modeling, zero_knowledge_proof, verifier, hash_function.

Original catalogue record ↗
S-3122 / Tier B2026 / docs

NVIDIA Trusted Computing Solutions Release Notes (R595 TRD1) ↗

NVIDIA

NVIDIA documentation · Last accessed by source map: 2026-09-25

Version: Document RN-12817-001_v02, dated April 2026; the newest release notes linked from https://docs.nvidia.com/confidential-computing/ on 2026-09-25.

Catalogue note

Vendor release notes; support only "NVIDIA reports" statements. Lists three generally available confidential modes: single-GPU passthrough on Hopper and Blackwell, Hopper multi-GPU passthrough with protected PCIe (NVLink traffic unencrypted), and Blackwell multi-GPU passthrough (encrypted NVLink). Adds HGX B200 and B300 platforms. No multi-node mode is listed.

Original catalogue record ↗
S-0014 / Tier C2026 / blog

On TEEs for Privacy-Preserving Monitoring in AI Governance ↗

Gloria Z

MIRI Technical Governance Team · Last accessed by source map: 2026-10-08

Catalogue note

Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0), which gives the author as "Zhao". The page itself (read 2026-09-23, dated 2026-06-18) shows the byline "Aaron Scher" and "Gloria Z", and states that the post was conducted as part of the MIRI Technical Governance Fellowship and "authored solely by Gloria", with thanks to Aaron Scher for guidance. The author is therefore recorded as shown on the page.

Original catalogue record ↗
S-1707 / Tier B2026 / docs

Our Team: Intelligence Security Laboratories ↗

Intelligence Security Laboratories · Last accessed by source map: 2026-09-25

Catalogue note

Team page. Lists Gabriel Kulp (Executive Director; before founding ISL, a fellow at RAND working on hardware-enabled governance mechanisms for GPU export controls and on international verification of agreements), Tom Gardiner (Staff Director) and Paul Murley (Technical Director; leads the development and infrastructure teams). No page date. Self-description.

Original catalogue record ↗
S-1102 / Tier C2026 / blog

Pacing AI Requires Proof ↗

Attestable

Attestable blog · Last accessed by source map: 2026-09-25

Catalogue note

Developer's own proposal to combine zero-knowledge inference proofs with proof-of-work accounting. No visible byline or date; the year comes from page metadata and should be checked.

Original catalogue record ↗
S-0012 / Tier B2026 / preprint

PAL*M: Property Attestation for Large Generative Models ↗

P. Chantasantitam, A. I. Caulfield, V. Duddu, L. J. Gunn, N. Asokan

arXiv · Last accessed by source map: 2026-10-08

Version: arXiv v3 (2026-04-30) read on 2026-09-25; still a preprint, with code "to be released after peer review".

Catalogue note

Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1105 / Tier B2026 / tech report

Pearl Floating Point Scheme Specification ↗

Pearl Research Team

Pearl Research Labs · Last accessed by source map: 2026-09-25

Version: First page dated September 2026; 22 pages.

Catalogue note

Developer's own specification of its FP8 proof-of-useful-work protocol; supports only "Pearl reports" statements. The Pearl research page lists this PDF as "The Pearl Protocol: A Proof-of-Useful-Work L1".

Original catalogue record ↗
S-1106 / Tier B2026 / tech report

Pearl INT Whitepaper ↗

Pearl Research Labs

Pearl Research Labs · Last accessed by source map: 2026-09-25

Catalogue note

Developer's original whitepaper for the integer matrix-multiplication mining scheme; supports only "Pearl reports" statements. No explicit publication date; the year is from the page's copyright notice.

Original catalogue record ↗
S-3603 / Tier B2026 / docs

Pearl Research Labs homepage ↗

Pearl Research Labs · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: infrastructure and algorithms for AI inference.

Original catalogue record ↗
S-1107 / Tier B2026 / code

pearl: Monorepo for the Pearl network ↗

Pearl Research Labs

GitHub · Last accessed by source map: 2026-09-25

Version: Release v1.2.1 (tag v1.2.1, commit e72ad36, 23 July), still the latest release listed on the releases page on 2026-09-25.

Catalogue note

Contains the reference full node, a vLLM-based GPU miner and a Plonky2/STARKy-based proof-of-work circuit and verifier.

Original catalogue record ↗
S-1700 / Tier C2026 / blog

Planet Reports Financial Results for Second Quarter of Fiscal Year 2027 ↗

Planet Labs PBC

Business Wire (press release) · Last accessed by source map: 2026-09-25

Catalogue note

Company press release for the quarter ended 31 July 2026, also carried on nasdaq.com. It states that in August 2026 Planet signed a renewal with a "hyperscaler AI developer" for global monitoring of data centres and of semiconductor manufacturing facility construction, using its Pelican high-resolution data, and it gives the company's "About Planet" description. Supports "Planet reports" statements only.

Original catalogue record ↗
S-3600 / Tier B2026 / docs

Prime Intellect homepage ↗

Prime Intellect · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: integrated compute, training, inference and sandbox stack.

Original catalogue record ↗
S-1506 / Tier B2026 / preprint

Privacy-Preserving AI Verification via Minimal Information Disclosure ↗

S. Abdelghafar, G. Kulp

arXiv · Last accessed by source map: 2026-09-25

Version: v1, the only version on 2026-09-25, read via the arXiv HTML rendering. The HTML fetch ends before the reference list, and the PDF returned HTTP 429, so the bibliography entries were not read.

Catalogue note

Authors affiliated with Rice University (Abdelghafar) and Intelligence Security Laboratories (Kulp).

Original catalogue record ↗
S-3125 / Tier B2026 / docs

Private Cloud Compute (Apple Developer) ↗

Apple

Apple Developer · Last accessed by source map: 2026-09-25

Version: Undated page, read on 2026-09-25. The access was announced at WWDC26 in June 2026 ("What's new in the Foundation Models framework", https://developer.apple.com/videos/play/wwdc2026/241/, which names the PrivateCloudComputeLanguageModel API).

Catalogue note

Apple's description of its own developer programme; supports only "Apple reports" statements. Developers enrolled in the App Store Small Business Program, with fewer than 2 million first-time downloads across their apps and the Private Cloud Compute entitlement assigned to their account, can use Apple Foundation Models on PCC in their apps at no cloud API cost. Developers who exceed the threshold must migrate within six months.

Original catalogue record ↗
S-3120 / Tier B2026 / docs

Private Processing for WhatsApp: Technical White Paper and Security Guide ↗

Meta

Meta · Last accessed by source map: 2026-09-25

Version: Version 2, updated 2026-03-16; version 1 was published 2025-06-10.

Catalogue note

Meta's description of its own system; supports only "Meta reports" statements. Private Processing runs WhatsApp's AI requests in confidential VMs on AMD EPYC CPUs with SEV-SNP and NVIDIA Hopper GPUs. The client checks the attestation and transparency proofs, including entries in a third-party transparency log run with Cloudflare, before it connects. The threat model lists physical host attacks, with data-centre security, memory encryption and third-party relays as mitigations.

Original catalogue record ↗
S-3571 / Tier C2026 / blog

Proof of Useful Work from the Ground Up ↗

Pearl Research Labs

Pearl Research Labs · Last accessed by source map: 2026-09-25

Catalogue note

Pearl reports end-to-end serving overhead for its integer proof-of-useful-work kernel against stock serving engines: 5.08% for Llama 70B at DP=4 on four H200 GPUs and 3.9% for DeepSeek V3.2 at DP=8 plus expert parallelism on eight H200 GPUs. The page gives no publication date; year follows its copyright notice. Developer report only.

Original catalogue record ↗
S-1500 / Tier B2026 / preprint

Proof-of-Guardrail in AI Agents and What (Not) to Trust from It ↗

X. Jin, M. Duan, Q. Lin, A. Chan, Z. Chen, J. Du, X. Ren

arXiv · Last accessed by source map: 2026-10-08

Version: arXiv v1 (2026-03-06) and v2 (2026-06-26), read via the arXiv HTML renderings on 2026-09-23 and 2026-09-25; the abs page did not render for the fetch tool. v2 keeps the figures the records cite (34% average latency overhead, Table 2 per-step overheads of 24.8–38.0%, F1 0.56 on the unsafe class).

Catalogue note

The paper header names the Trustworthy AI for Good (AI4GOOD) workshop at ICML 2026, with the ICML template's "PMLR 306" line; PMLR volume 306 is set aside for the ICML 2026 main conference (github.com/mlresearch/v306), so the paper is recorded as a workshop paper and tier B preprint. Authors are affiliated with Sahara AI and the University of Southern California.

Original catalogue record ↗
S-1101 / Tier C2026 / blog

Proving LLMs at Scale ↗

Attestable

Attestable blog · Last accessed by source map: 2026-09-25

Catalogue note

Developer's own description of its zero-knowledge inference prover; supports only "Attestable reports" statements. No byline on the page; the date is taken from the Attestable resources listing. No paper, code or docs are linked.

Original catalogue record ↗
S-3023 / Tier B2026 / docs

Reproducible Execution Environment (REE) (Gensyn documentation) ↗

Gensyn

Gensyn documentation · Last accessed by source map: 2026-10-08

Version: Page as viewed on 2026-10-08, giving v0.8.0 as the current release (no release date shown).

Catalogue note

Developer's documentation of its own runtime. Describes three modes: default (standard PyTorch kernels, no determinism guarantee), deterministic (PyTorch deterministic algorithms, reproducible on the same hardware) and reproducible (RepOp kernels, bitwise-identical across supported hardware). Lists reproducible int8 attention, fused gathered-log-probability and MoE expert GEMM kernels; warns that earlier receipts may not re-verify with v0.8.0; states that REE as a whole is not open source. Supports only "Gensyn reports" statements.

Original catalogue record ↗
S-3362 / Tier C2026 / blog

Safety Without Compromising on Privacy ↗

D. McCann-Sayles, S. Servan-Schreiber, T. Verma

Tinfoil blog · Last accessed by source map: 2026-09-25

Catalogue note

Tinfoil's description of its own safeguard pipeline: safeguard models that "run exclusively inside secure enclaves" and output only a flag, with the pipeline code public and its enforcement "verifiable through attestation". Updated 16 September 2026. The post does not say explicitly which safeguard components are in the attested measurement. Supports only "Tinfoil reports" statements.

Original catalogue record ↗
S-3128 / Tier B2026 / docs

SEV-SNP Routing Misconfiguration (AMD-SB-3034) ↗

AMD

AMD product security bulletin · Last accessed by source map: 2026-10-08

Version: Initial publication 2026-04-14; read in the revision of 2026-09-24.

Catalogue note

AMD's own bulletin on CVE-2025-54510 (Fabricked, S-3127); supports only "AMD reports" statements. Credits Schlüter, Wech and Shinde of ETH Zurich. Rates the issue CVSS 5.9 (medium). Lists platform-initialisation firmware updates for EPYC 7003, 8004, 9004 and 9005 server series released 2025-11-26 to 2025-12-15, and for the embedded series to 2026-04-13.

Original catalogue record ↗
S-3606 / Tier B2026 / docs

Singapore AI Safety Hub: About ↗

Singapore AI Safety Hub · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: research and field-building organisation rooted in Singapore.

Original catalogue record ↗
S-1405 / Tier B2026 / docs

Sovereignty Certificates Working Group ↗

sovcert.org · Last accessed by source map: 2026-09-23

Catalogue note

Working-group website; content copyright 2025-2026, no page date. Content as read on 2026-09-23; the site could not be reached on 2026-09-25 (connection error). Self-description of the initiative, so it supports "the working group states" statements only. The live site failed again on 2026-10-07 (TLS error). The archived copy of 17 May 2026, read on 2026-10-07, has the same self-description and a timeline ending with the final version presented in January 2026.

Original catalogue record ↗
S-3123 / Tier A2026 / peer reviewed

StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack Engine ↗

R. Zhang, T. Hornetz, D. Weber, F. Thomas, M. Schwarz

35th USENIX Security Symposium (USENIX Security '26) · Last accessed by source map: 2026-10-08

Version: USENIX Security '26 presentation page (pp. 5691–5709, August 2026). Also read the authors' site (https://stackwarpattack.com/) and paper PDF (https://stackwarpattack.com/stackwarp_usenix26.pdf) on 2026-09-25.

Catalogue note

Independent attack paper (CISPA Helmholtz Center for Information Security). A malicious hypervisor toggles an undocumented MSR bit on a sibling hyperthread to shift an SEV-SNP guest's stack pointer, breaking the guest's integrity; demonstrated on AMD Zen 1 to Zen 5 with simultaneous multithreading enabled, including OpenSSH authentication bypass, sudo privilege escalation and RSA key recovery. CVE-2025-29943; AMD released hot-loadable microcode patches (bulletin AMD-SB-3027), and disabling SMT is an interim mitigation. Proof-of-concept code at https://github.com/cispa/StackWarp.

Original catalogue record ↗
S-3380 / Tier C2026 / blog

Summary: TGT's 2026 ICML Papers ↗

Machine Intelligence Research Institute

Machine Intelligence Research Institute · Last accessed by source map: 2026-09-25

Catalogue note

MIRI post summarising six papers by its Technical Governance Team (TGT) at the second Workshop on Technical AI Governance Research (TAIGR) at ICML 2026, including S-0020 (marked as the best-paper award winner), S-0037, S-0060 and S-1300. The date is taken from the URL; the page as fetched showed no byline. Self-description; supports "MIRI reports" statements.

Original catalogue record ↗
S-3500 / Tier A2026 / peer reviewed

TAO: Tolerance-Aware Optimistic Verification for Floating-Point Neural Networks ↗

J. Yao, H. Su, T. Liao, Z. Cheng, H. Zhang, X. Wang, P. Viswanath

Proceedings of the 21st European Conference on Computer Systems (EuroSys 2026), pp. 1515-1532 · Last accessed by source map: 2026-09-25

Version: Full text read from arXiv HTML v4 (6 Jun 2026; v1 15 Oct 2025). Venue, pages and DOI are from the arXiv journal reference. The ACM DOI page could not be read by the fetch tool (HTTP 403).

Catalogue note

Yao, Cheng and Viswanath are at Princeton University, Su and Wang at HKUST (Guangzhou), Liao and Zhang at the University of Illinois Urbana-Champaign. TAO accepts operator-level outputs within bounds that combine IEEE-754 worst-case error bounds with empirical percentile profiles, instead of requiring bitwise equality, and keeps hardware heterogeneity. Disputes are settled by a Merkle-anchored, threshold-guided dispute game whose coordinator is a smart-contract deployment on the Ethereum Holesky testnet. Evaluated on RTX 4090, A100, H100 and RTX 6000 GPUs; reports 0.3% overhead on Qwen3-8B.

Original catalogue record ↗
S-1202 / Tier A2026 / peer reviewed

TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition ↗

J. Chuang, A. Seto, N. Berrios, S. van Schaik, C. Garman, D. Genkin

2026 IEEE Symposium on Security and Privacy (SP) · Last accessed by source map: 2026-10-08

Version: Read the authors' site and the paper PDF linked from it (https://tee.fail/files/paper.pdf) on 2026-09-23.

Catalogue note

Independent attack paper. Venue confirmed on 2026-09-23: the authors' site lists the 47th IEEE Symposium on Security and Privacy (IEEE S&P '26), co-author C. Garman's publication list gives IEEE Symposium on Security and Privacy (SP) 2026, and the IEEE Computer Society Digital Library lists it among the SP 2026 proceedings articles (https://www.computer.org/csdl/proceedings-article/sp/2026/606500b876/2bojwtctN28; page content not machine-readable, so no DOI is recorded). The site (re-read 2026-09-25) links an Intel security announcement of 2025-10-28 and AMD bulletin AMD-SB-3040; it states that both vendors treat interposer attacks as out of scope and that there are no mitigations on the NVIDIA side. Cited by S-0012 (as TEE.fail) and discussed in S-0014 and the Tinfoil documentation.

Original catalogue record ↗
S-0071 / Tier B2026 / preprint

The Usefulness Gap in Proof-of-Useful-Work: An Empirical Study of Pearl's cuPOW Protocol ↗

A. Basu

arXiv · Last accessed by source map: 2026-09-25

Version: Read arXiv HTML v2 (5 June 2026), which describes itself as under review; v1 was read on 2026-09-23. The arXiv abstract page could not be rendered by the fetch tool.

Catalogue note

Independent measurement study of Pearl's mainnet; the author (NIELIT New Delhi; IIIT Allahabad) is not affiliated with Pearl Research Labs.

Original catalogue record ↗
S-3562 / Tier B2026 / docs

Thinking Machines Lab ↗

Thinking Machines Lab · Last accessed by source map: 2026-09-25

Catalogue note

Company homepage, read 2026-09-25. States: "Thinking Machines Lab is an artificial intelligence research and product company." Lists its models, the Tinker platform and its research blog, Connectionism. Supports "Thinking Machines reports" statements only.

Original catalogue record ↗
S-3605 / Tier B2026 / docs

Tinfoil homepage ↗

Tinfoil · Last accessed by source map: 2026-09-25

Catalogue note

Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: AI models running inside secure hardware enclaves.

Original catalogue record ↗
S-0048 / Tier C2026 / blog

Understanding Data Center Power Delivery ↗

Amodo Design

Amodo Design · Last accessed by source map: 2026-09-25

Version: The URL imported from the Hodgkins bibliography (https://amododesign.com/data-center-power-delivery/) redirects to the notes page above, which was read on 2026-09-23. The page credits "Amodo Design" and names no individual authors; the bibliography's list of three individual authors could not be confirmed on the page.

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1803 / Tier A2026 / peer reviewed

Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence ↗

Y. Dittmar, M. J. Stephan, T. Völkl, M. Hollick, J. Classen

Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '26) · Last accessed by source map: 2026-09-25

Version: Read the arXiv HTML v1 (22 May 2026), whose ACM reference format names WiSec '26 (30 June–3 July 2026, Saarbrücken) and prints the DOI above (doi.org returned 403 to the fetch tool, so the DOI was not resolved). Authors at the Hasso Plattner Institute, TU Darmstadt and IMDEA Networks; none at Apple.

Catalogue note

Independent analysis that reverse-engineers PCC's client on macOS 15.5 and iOS 26.2 and queries the production service. Reports that there are no reproducible builds or symbols, request-token handling that departs from Apple's documentation (reusable one-time tokens, skipped signature validation, linkable salts), disclosure to Apple, and that Apple only clarified its documentation. It does not test attestation.

Original catalogue record ↗
S-0091 / Tier B2026 / docs

Verifiable Compute Foundation ↗

Verifiable Compute Foundation · Last accessed by source map: 2026-10-08

Catalogue note

The foundation's public homepage describes its nonprofit mission and free Bay Area research cluster, operated by Lucid Computing. It reports two H100 nodes operational in a beta launch, with H200, B300 and MI355X hardware scheduled, and lists research access and physical instrumentation. Operational and availability statements are provider-reported. Read from the public HTML's bundled document.

Original catalogue record ↗
S-0026 / Tier B2026 / preprint

Verifiable constraints on frontier training via proofs of compartmentalization ↗

D. Reuter, L. Marks, A. Carlucci, J. Ng, J. Petrie, J. Hausenloy, A. Karvonen, M. Baker

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-23

Version: Author list and abstract verified on the official ICML 2026 TAIGR workshop poster page on 2026-09-25. The OpenReview full text was inaccessible; only abstract-level claims are used.

Catalogue note

Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1704 / Tier B2026 / tech report

Verifiable Semiconductor Manufacturing ↗

A. Ilhan, C. Withers, H. Gietz, B. Harack

Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-10-08

Version: Research paper dated April 2026. The landing page and the abstract and author block of the PDF (https://aigi.ox.ac.uk/wp-content/uploads/2026/04/Verifiable-Semiconductor-Manufacturing.pdf) were read; the body was not reviewed.

Catalogue note

Affiliations as printed: A. Ilhan (ERA Cambridge; Oxford Hardware AI Governance Lab), C. Withers (Center for a New American Security), H. Gietz (ERA Cambridge), B. Harack (Oxford Martin AI Governance Initiative; Oxford Hardware AI Governance Lab). Listed among the Hardware AI Governance Lab's publications (S-1703).

Original catalogue record ↗
S-1501 / Tier B2026 / code

Verifiable-ClawGuard: proof-of-guardrail reference code ↗

SaharaLabsAI

GitHub · Last accessed by source map: 2026-09-25

Version: main branch as viewed on 2026-09-23, README read via raw.githubusercontent.com. No release tag exists; the main branch head at that time was commit 77a4fdbcf9f7ff196bf577bd42b8817472729126 (from git ls-remote). README re-read on 2026-09-25; the repository page still showed 28 commits and no releases, and the commit list could not be read (robots.txt).

Catalogue note

Code release linked from S-1500. The README describes it as a proof of concept that is not production-ready.

Original catalogue record ↗
S-0019 / Tier B2026 / preprint

Verifying AI Compute by Bounding Unexplained Information Exfiltration ↗

J. Petrie, Y. Mühlhäuser

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25

Version: OpenReview returned a browser check on 2026-09-23 and 2026-09-25, so only the title, authors and abstract were read, on the workshop's ICML 2026 virtual page (https://icml.cc/virtual/2026/78565). No arXiv version found as of 2026-09-25.

Catalogue note

Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1512 / Tier C2026 / blog

Verifying international AI deals: Plan A, the state-of-play, and what you can do to help ↗

T. Milton, S. Reynolds, C. Jacobi, J. Foster

Amodo (Substack) · Last accessed by source map: 2026-09-25

Catalogue note

Byline shown as "Amodo, Thomas Milton, Sam Reynolds, and 2 others"; the post names Connagh Jacobi and Joel Foster as the other contributors. A search-engine listing gave a slightly longer title that includes "AI 2040"; the title here is the post's H1 as fetched.

Original catalogue record ↗
S-3080 / Tier A2026 / peer reviewed

VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs ↗

G. Liao, T. Wang, S. Zhang, J. Zhang, L. Shi, D. Tao

NDSS Symposium 2026 · Last accessed by source map: 2026-10-08

Version: Published at the NDSS Symposium 2026; the paper page, read on 2026-10-07, gives the title, authors and affiliations and shows no DOI. Preprint arXiv 2508.21393 (DOI 10.48550/arXiv.2508.21393), first posted 29 August 2025; arXiv v3 dated 2 December 2025. The abstract and HTML, read on 2026-09-25, use the title VeriLoRA and state that the paper was accepted for publication at NDSS 2026.

Catalogue note

Proves one LoRA fine-tuning iteration (forward pass, backward pass, parameter update) on a single-sample minibatch for LLaMA-3.2 3B and 11B, LLaMA-2 7B and 13B and OPT 6.7B and 13B on one NVIDIA A100 80 GB GPU. The full text read reports 121.93–249.38 s of proving, 156–554 s of commitment generation and 1.87–3.73 s of verification per step. Code linked from the paper at https://github.com/liaoguofu/zkLoRA (MIT licence, README titled VeriLoRA, built on the zkLLM code base); commit not pinned.

Original catalogue record ↗
S-0075 / Tier B2026 / docs

What is Delphi? (Delphi documentation) ↗

Gensyn

Delphi documentation · Last accessed by source map: 2026-10-08

Version: Documentation as viewed on 2026-10-08; no publication date is given.

Catalogue note

Developer's documentation of its information-market service. States that Delphi runs on Gensyn mainnet and that an open-source judge model runs inside REE to settle markets. Describes receipts that record the model, inputs, output and a cryptographic hash, letting anyone re-run the computation. This supports receipt re-execution, not a documented application of Verde's dispute protocol. Supports only "Gensyn reports" statements.

Original catalogue record ↗
S-3121 / Tier C2026 / blog

What we learned about TEE security from auditing WhatsApp's Private Inference ↗

Trail of Bits

Trail of Bits blog · Last accessed by source map: 2026-10-08

Catalogue note

The auditors' own summary of their pre-launch security review of WhatsApp Private Processing (AMD SEV-SNP with NVIDIA confidential GPUs); the post does not say who commissioned it. Reports 28 issues, eight of high severity, and describes environment variables and ACPI tables loaded outside the attestation measurement, patch levels trusted without checking AMD's certificates, and attestations with no freshness guarantee. Meta resolved 16 issues and partly addressed four before launch; the remaining eight are low or informational. States that the SEV-SNP threat model does not fully protect against advanced physical attacks, so Meta added controls on which CPUs are trusted (TOB-WAPI-10). The full report (https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf, dated August 2025) could not be read by the fetch tool on 2026-09-25; finding severities come from the library entry, S-3124.

Original catalogue record ↗
S-1412 / Tier B2026 / preprint

Workload Identification with Physical Side Channels for AI Governance ↗

S. Gargiulo, G. Kulp

arXiv · Last accessed by source map: 2026-09-25

Version: v1 (2026-08-31), the version shown on 2026-09-25. Read via the arXiv HTML rendering (arxiv.org/html/2609.00309); the abstract page returned no extractable text to the fetch tool. The paper states that the recordings are released as a Hugging Face dataset; the dataset page returned HTTP 401 on 2026-09-23 and 2026-09-25. Affiliations as shown: S. Gargiulo (Pivotal Research), G. Kulp (Intelligence Security Laboratories).

Original catalogue record ↗
S-1806 / Tier B2026 / code

zkonduit/ezkl (GitHub repository) ↗

Zkonduit Inc.

GitHub · Last accessed by source map: 2026-09-25

Version: Main branch as viewed on 2026-09-25 (860 commits); the releases page lists v23.0.5 as the latest release. The root listing showed no licence file; the README carries a no-warranty notice and a contributor licence agreement.

Catalogue note

Developer's own repository; supports "Zkonduit reports" statements about the tool. README: ezkl proves inference of ONNX models with halo2, supports public or private models and data, notes that quantization can make outputs differ slightly from Python, and links the Trail of Bits audit (S-0070).

Original catalogue record ↗
S-1814 / Tier C2025 / forum

[Feature]: Batch Invariant Feature and Performance Optimization (vLLM issue #27433) ↗

vLLM project contributors

GitHub (vllm-project/vllm issues) · Last accessed by source map: 2026-09-25

Catalogue note

vLLM developers' tracking issue for batch invariance. Its body states "We have basically support Batch Invariant based on" the Thinking Machines post (S-1009), and lists open work such as performance, NVFP4, AMD testing and speculative decoding. Still open on 2026-09-25.

Original catalogue record ↗
S-3221 / Tier C2025 / blog

Activating AI Safety Level 3 Protections ↗

Anthropic

Anthropic · Last accessed by source map: 2026-09-25

Catalogue note

Developer's announcement of its own security measures. Describes egress bandwidth controls that limit the rate of outbound network traffic from environments holding model weights. Supports "Anthropic reports" statements only.

Original catalogue record ↗
S-1005 / Tier B2025 / code

adamkarvonen/difr (GitHub repository) ↗

A. Karvonen

GitHub · Last accessed by source map: 2026-09-25

Version: Pinned to commit eecde35 (eecde35f6458d76af86d68afac00594237162cf2, 8 Dec 2025), the head of the main branch per the GitHub API on 2026-09-23; the branch showed 21 commits and no release tags. Unchanged (21 commits, no tags) on 2026-09-25.

Original catalogue record ↗
S-0008 / Tier C2025 / forum

AI Security RFDs ↗

AI Security Forum

AI Security Forum · Last accessed by source map: 2026-09-23

Catalogue note

Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3261 / Tier A2025 / peer reviewed

Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection ↗

M. S. Tabar, J. Kortz, P. Staat, H. Elders-Boll, C. Paar, C. Zenger

18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025) · Last accessed by source map: 2026-10-08

Version: Read via the arXiv HTML (v1) and PDF; the ACM DOI page returned HTTP 403. Venue and author order from the dblp record (conf/wisec/TabarKSEPZ25) and P. Staat's publication list.

Original catalogue record ↗
S-0009 / Tier B2025 / preprint

Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments ↗

C. Schnabl, D. Hugenroth, B. Marino, A. R. Beresford

ICML 2025 Workshop on Technical AI Governance · Last accessed by source map: 2026-10-08

Version: arXiv v1 (2025-06-30) read on 2026-09-23 and 2026-09-25; no later version or archival publication found. The arXiv comment reads "ICML 2024 Workshop TAIG", and the PDF and HTML carry the ICML 2025 template header ("Proceedings of the 42nd International Conference on Machine Learning ... PMLR 267"). The ICML 2025 virtual site (https://icml.cc/virtual/2025/48334) lists it as a workshop poster at the Workshop on Technical AI Governance, and it was not found in the PMLR 267 volume, so it is recorded as a workshop paper, not a main-conference publication.

Catalogue note

Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3544 / Tier A2025 / gov doc

California Senate Bill 53 (2025): Transparency in Frontier Artificial Intelligence Act ↗

California State Legislature

Statutes of 2025, Chapter 138 (Business and Professions Code §22757.10 et seq.) · Last accessed by source map: 2026-09-25

Version: Chaptered text, approved by the Governor and filed with the Secretary of State on 29 September 2025. The official page (https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53) disallows the fetch tool, so the chaptered text was read on LegiScan. §22757.11(i) defines a frontier model by training compute greater than 10^26 integer or floating-point operations, including later fine-tuning, reinforcement learning or other material modifications; §22757.12 sets the frontier AI framework and transparency-report duties.

Original catalogue record ↗
S-1817 / Tier C2025 / blog

Confidential Inference via Trusted Virtual Machines ↗

Anthropic, Pattern Labs

Anthropic research · Last accessed by source map: 2026-09-25

Catalogue note

Published in collaboration with Pattern Labs, with a companion report ("Confidential Inference Systems: Design principles and security risks", June 2025). Sketches a small, attested model loader and invoker that decrypts data only inside a trusted environment and passes it to the accelerator, for protecting model weights and user data; states the work is early. Developer's description of its own research; supports "Anthropic reports" statements.

Original catalogue record ↗
S-3382 / Tier B2025 / tech report

Countering AI Chip Smuggling Has Become a National Security Priority ↗

E. Grunewald, T. Fist

Center for a New American Security (working paper) · Last accessed by source map: 2026-09-25

Catalogue note

CNAS working paper. Affiliations as shown on the CNAS page: E. Grunewald (Institute for AI Policy and Strategy), T. Fist (CNAS). Estimates AI chip smuggling to the PRC in 2024 at 10,000 to several hundred thousand chips, median about 140,000, and recommends software-based location verification and a notification requirement for exports, re-exports and ownership transfers of controlled AI chips.

Original catalogue record ↗
S-1009 / Tier C2025 / blog

Defeating Nondeterminism in LLM Inference ↗

H. He, Thinking Machines Lab

Thinking Machines Lab: Connectionism · Last accessed by source map: 2026-09-25

Catalogue note

Byline reads "Horace He in collaboration with others at Thinking Machines". Code is published at github.com/thinking-machines-lab/batch_invariant_ops (S-1813).

Original catalogue record ↗
S-0039 / Tier B2025 / preprint

Detecting Anomalies in Machine Learning Infrastructure via Hardware Telemetry ↗

Z. Chen, S. Chien, P. Qian, N. Zilberman

arXiv · Last accessed by source map: 2026-09-23

Version: Title and author order follow the arXiv listing (abstract-page title, also used on the Oxford Computing Infrastructure Group publications page). The paper's own header in the arXiv HTML (v1 and v2) and PDF reads "Detecting Anomalies in Systems for AI Using Hardware Telemetry", with authors in the order Z. Chen, P. Qian, S. W. D. Chien, N. Zilberman, all University of Oxford; the system is named Reveal. Checked 2026-09-23.

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-0016 / Tier B2025 / preprint

DiFR: Inference Verification Despite Nondeterminism ↗

A. Karvonen, D. Reuter, R. Rinberg, L. Marks, A. Garriga-Alonso, K. Warr

ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25

Version: arXiv v1 (25 Nov 2025) is the only version as of 2026-09-25. The paper was a poster at the Second Workshop on Technical AI Governance Research at ICML 2026 (https://icml.cc/virtual/2026/78608). Checked 2026-09-25.

Catalogue note

Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3021 / Tier C2025 / blog

EigenCloud Brings Verifiable AI to Mass Market with EigenAI and EigenCompute Launches ↗

EigenCloud

Eigen Labs blog · Last accessed by source map: 2026-09-25

Catalogue note

Developer's launch announcement (the blog.eigencloud.xyz address redirects here). States that EigenAI and EigenCompute launched "on mainnet alpha", that the backing stake "is not exposed to slashing risk yet during the alpha phase", that code will be open-sourced so users can verify responses, and that the API first serves gpt-oss-120b-f16. Supports only "Eigen Labs reports" statements.

Original catalogue record ↗
S-3160 / Tier B2025 / preprint

Embedded Off-Switches for AI Compute ↗

J. Petrie

arXiv · Last accessed by source map: 2026-09-25

Version: v1 (2025-09-09), the only version, read on 2026-09-25.

Catalogue note

Design for thousands of redundant on-chip security blocks that each block essential accelerator operations unless they hold a recent, signed authorization. The paper gives gate-count and area estimates and reports no built or measured hardware. A proof-of-concept repository by the same author is S-3161.

Original catalogue record ↗
S-3240 / Tier A2025 / peer reviewed

Empirical Evaluation of Memory-Erasure Protocols ↗

R. Gil-Pons, S. Mauw, R. Trujillo-Rasua

Proceedings of the 22nd International Conference on Security and Cryptography (SECRYPT 2025), pp. 209–220 · Last accessed by source map: 2026-09-25

Version: Read the SciTePress PDF and the arXiv HTML preprint (arXiv 2509.10224); venue, pages and DOI checked against Crossref on 2026-09-25.

Catalogue note

Code at gitlab.com/uniluxembourg/fstm/dcs/satoss/memory-erasure-experiments, per the paper.

Original catalogue record ↗
S-3561 / Tier B2025 / docs

EZKL documentation (overview) ↗

Zkonduit Inc.

EZKL documentation · Last accessed by source map: 2026-09-25

Catalogue note

Developer's documentation home, read 2026-09-25. Describes EZKL as "a developer-friendly system for verifiable AI and analytics" and carries the notice "© Copyright Zkonduit Inc. 2025". Zkonduit's GitHub organization (github.com/zkonduit) describes itself as "Making ezkl". Supports "Zkonduit reports" statements only.

Original catalogue record ↗
S-0034 / Tier B2025 / preprint

Guaranteeable Memory: An HBM-Based Chiplet for Verifiable AI Workloads ↗

J. Petrie

ICML 2025 Workshop on Technical AI Governance · Last accessed by source map: 2026-09-25

Version: Workshop poster. Read via the ICML 2025 virtual-site abstract (https://icml.cc/virtual/2025/48329) on 2026-09-23 and 2026-09-25; the OpenReview page and PDF could not be read.

Catalogue note

Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3543 / Tier A2025 / gov doc

Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act) ↗

European Commission

European Commission, Communication C(2025) 5045 final · Last accessed by source map: 2026-09-25

Version: The landing page gives the publication date and the entry into application on 2 August 2025. The text (§2.3.1 on the 10^25 FLOP presumption, §2.3.2 on notification within two weeks) was read in the annex PDF on the AI Act Service Desk.

Original catalogue record ↗
S-1502 / Tier B2025 / preprint

Has My System Prompt Been Used? Large Language Model Prompt Membership Inference ↗

R. Levin, V. Cherepanova, A. Hans, A. Schwarzschild, T. Goldstein

arXiv · Last accessed by source map: 2026-09-25

Version: Abstract read on the arXiv abs page; method and setup read via the v1 HTML rendering. Only v1 exists on arXiv (checked 2026-09-25). ML Anthology lists the paper under the ICLR 2025 BuildingTrust workshop (https://mlanthology.org/iclrw/2025/levin2025iclrw-my/); a workshop paper, so tier B is kept.

Original catalogue record ↗
S-1003 / Tier B2025 / tech report

INTELLECT-2: A Reasoning Model Trained Through Globally Decentralized Reinforcement Learning ↗

Prime Intellect Team, S. Jaghouar, J. Mattern, J. M. Ong, J. Straube, M. Basra, A. Pazdera, K. Thaman, M. Di Ferrante, F. Gabriel, F. Obeid, K. Erdem, M. Keiblinger, J. Hagemann

arXiv · Last accessed by source map: 2026-09-25

Version: Read arXiv v1 (HTML), section 2.3 on TOPLOC and section 2.4 on validation.

Catalogue note

Developer's report on its own training run; TOPLOC statements are provider-reported.

Original catalogue record ↗
S-0054 / Tier B2025 / tech report

International AI Safety Report ↗

Y. Bengio, S. Mindermann, D. Privitera, T. Besiroglu, R. Bommasani, S. Casper, Y. Choi, P. Fox, B. Garfinkel, D. Goldfarb, H. Heidari, A. Ho, S. Kapoor, L. Khalatbari, S. Longpre, S. Manning, V. Mavroudis, M. Mazeika, J. Michael, J. Newman, K. Y. Ng, C. T. Okolo, D. Raji, G. Sastry, E. Seger, T. Skeadas, T. South, E. Strubell, F. Tramèr, L. Velasco, N. Wheeler, D. Acemoglu, O. Adekanmbi, D. Dalrymple, T. G. Dietterich, E. W. Felten, P. Fung, P.-O. Gourinchas, F. Heintz, G. Hinton, N. Jennings, A. Krause, S. Leavy, P. Liang, T. Ludermir, V. Marda, H. Margetts, J. McDermid, J. Munga, A. Narayanan, A. Nelson, C. Neppel, A. Oh, G. Ramchurn, S. Russell, M. Schaake, B. Schölkopf, D. Song, A. Soto, L. Tiedrich, G. Varoquaux, A. Yao, Y.-Q. Zhang, F. Albalawi, M. Alserkal, O. Ajala, G. Avrin, C. Busch, A. C. P. de Leon Ferreira de Carvalho, B. Fox, A. S. Gill, A. H. Hatip, J. Heikkilä, G. Jolly, Z. Katzir, H. Kitano, A. Krüger, C. Johnson, S. M. Khan, K. M. Lee, D. V. Ligot, O. Molchanovskyi, A. Monti, N. Mwamanzi, M. Nemer, N. Oliver, J. R. López Portillo, B. Ravindran, R. Pezoa Rivera, H. Riza, C. Rugege, C. Seoighe, J. Sheehan, H. Sheikh, D. Wong, Y. Zeng

International AI Safety Report · Last accessed by source map: 2026-09-23

Catalogue note

Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1811 / Tier C2025 / blog

Introducing Judge ↗

Gensyn

Gensyn news · Last accessed by source map: 2026-09-25

Catalogue note

Developer's announcement of Judge, an AI evaluation service built on Verde and Gensyn's Reproducible Runtime, showcased with a reasoning task framed as a prediction market. Supports only "Gensyn reports" statements.

Original catalogue record ↗
S-1411 / Tier C2025 / blog

Introducing the Frontier Data Centers Hub ↗

Epoch AI

Epoch AI · Last accessed by source map: 2026-09-25

Catalogue note

Announcement of Epoch AI's public dataset of large AI data centres, launched as the Frontier Data Centers Hub. Epoch now calls it the AI data centers hub, at epoch.ai/data/ai-data-centers (checked 2026-10-07).

Original catalogue record ↗
S-3161 / Tier B2025 / code

JamesPetrie/off-switch (GitHub repository) ↗

J. Petrie

GitHub · Last accessed by source map: 2026-09-25

Version: Pinned to commit 4911839c11d95496255df626f59bdae973713e9d (head of main on 2026-09-25, committed 2026-09-17; first commit 2025-11-10; 131 commits, no releases or tags), obtained through the GitHub API. The README was read at that commit via raw.githubusercontent.com.

Catalogue note

SystemVerilog proof of concept of the security block in S-3160, with Verilator testbenches. Per its README, it gates an example Int8 adder, supports ECDSA (secp256k1) or HSS/LMS signatures, and omits production features including constant-time field arithmetic, a configurable public key and redundant blocks. The repository also has a pynq-z2 folder with an FPGA build script and a Python client; the README reports no FPGA results.

Original catalogue record ↗
S-1401 / Tier B2025 / tech report

Location Verification for AI Chips (issue brief) ↗

A. Brass

Institute for AI Policy and Strategy · Last accessed by source map: 2026-09-25

Catalogue note

Two-page IAPS issue brief. The document says "Issue brief written May 2025, full 2024 report by Asher Brass & Onni Aarne"; the IAPS page that presents the brief (iaps.ai/research/location-verification-for-ai-chips) reads "Written By Asher Brass" and is dated May 16 (2025). It reports an H100 prototype with a video demonstration at ping-location.info. The site's technical details are separately recorded in S-3570.

Original catalogue record ↗
S-3124 / Tier B2025 / docs

Meta WhatsApp Private Processing (security review) ↗

Trail of Bits

Trail of Bits publications library · Last accessed by source map: 2026-10-08

Version: Library entry for the review dated August 2025. The full report (https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf) could not be read by the fetch tool on 2026-09-25; the library entry gives the finding titles and severities.

Catalogue note

Independent auditors' summary of their review of WhatsApp Private Processing. Lists 28 issues (8 high, 4 medium, 4 low, 12 informational). The eight high-severity findings include attestation without freshness, the SEV-SNP TCB version not checked against the VCEK certificate, SEV-SNP attestation not bound to Meta-specific machines, CVMs compromised through environment-variable injection, ACPI SSDT injection by a malicious hypervisor, CVM images that cannot be reproduced, and GPU-hosted models that do not verify NVIDIA GPU attestation. The client is not named on the page.

Original catalogue record ↗
S-3540 / Tier A2025 / peer reviewed

Model Equality Testing: Which Model Is This API Serving? ↗

I. Gao, P. Liang, C. Guestrin

International Conference on Learning Representations (ICLR 2025) · Last accessed by source map: 2026-09-25

Version: arXiv v2 (8 April 2025), marked as the ICLR 2025 camera-ready version; v1 was posted on 26 October 2024. The ICLR 2025 publication was confirmed through the conference's slides page and the ML Anthology entry; the OpenReview forum (https://openreview.net/forum?id=QCDdI7X3f9) was not readable by the fetch tool.

Original catalogue record ↗
S-3162 / Tier B2025 / blog

No Backdoors. No Kill Switches. No Spyware. ↗

D. Reber Jr.

NVIDIA Blog · Last accessed by source map: 2026-09-25

Catalogue note

NVIDIA blog post by David Reber Jr. stating the company's position (the page gives no job title); supports only "NVIDIA states" statements. It states that NVIDIA GPUs "do not and should not have kill switches and backdoors", and distinguishes optional software features controlled by the user from a kill switch hardwired into a chip.

Original catalogue record ↗
S-1200 / Tier B2025 / docs

NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper) ↗

NVIDIA

NVIDIA documentation · Last accessed by source map: 2026-09-25

Version: Document WP-12554-001_v1.3, dated 2025-08-14, as read on 2026-09-23 and 2026-09-25 (still the version linked on 2026-09-25). Linked from https://docs.nvidia.com/confidential-computing/.

Catalogue note

Vendor documentation about NVIDIA's own confidential-computing feature; supports only "NVIDIA reports" statements. Covers the CPU-TEE pairing, device identity and root of trust, SPDM session, bounce buffers, TDISP/IDE, multi-GPU modes, the in-scope and out-of-scope threat lists (pp. 14-15) and performance counters in CC mode (p. 18).

Original catalogue record ↗
S-0001 / Tier A2025 / peer reviewed

Open Problems in Technical AI Governance ↗

A. Reuel, B. Bucknall, S. Casper, T. Fist, L. Soder, O. Aarne, L. Hammond, L. Ibrahim, A. Chan, P. Wills, M. Anderljung, B. Garfinkel, L. Heim, A. Trask, G. Mukobi, R. Schaeffer, M. Baker, S. Hooker, I. Solaiman, A. S. Luccioni, N. Rajkumar, N. Moës, J. Ladish, D. Bau, P.-A. Bricman, N. Guha, J. Newman, Y. Bengio, T. South, A. Pentland, S. Koyejo, M. J. Kochenderfer, R. Trager

Transactions on Machine Learning Research · Last accessed by source map: 2026-09-23

Catalogue note

Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1413 / Tier B2025 / blog

Opt-In NVIDIA Software Enables Data Center Fleet Management ↗

NVIDIA

NVIDIA Blog · Last accessed by source map: 2026-09-25

Catalogue note

NVIDIA's announcement of its own fleet-management service (byline: NVIDIA Newsroom); supports only "NVIDIA states" or "NVIDIA reports" statements. Describes an opt-in, customer-installed service that streams read-only GPU telemetry to an NVIDIA portal, with a client agent slated to be open-sourced, and states that NVIDIA GPUs do not have hardware tracking technology, kill switches and backdoors. It does not describe location verification.

Original catalogue record ↗
S-3570 / Tier B2025 / docs

Ping-based Location ↗

Ulyssean

Ulyssean demonstration site · Last accessed by source map: 2026-09-25

Version: The site gives no publication date. Its text was read from the public JavaScript asset https://ping-location.info/assets/index-sg1kynaJ.js linked by the home page on 2026-09-25. The 2025 IAPS brief (S-1401) links to the demonstration, so 2025 is the latest possible year for its initial publication.

Catalogue note

Ulyssean's account of its H100 and AMD SEV-SNP demonstration, using 38 Google Cloud Run landmarks. It describes the setup and timing method and says the code will be open-sourced after cleanup. It gives no systematic end-to-end location results or error rates. Developer documentation supports attributed claims about this demo.

Original catalogue record ↗
S-1816 / Tier C2025 / blog

Private AI Compute: our next step in building private and helpful AI ↗

J. Yagnik

Google blog (The Keyword) · Last accessed by source map: 2026-09-25

Catalogue note

Google's announcement of Private AI Compute: Gemini models on Google's TPUs with Titanium Intelligence Enclaves (TIE), and remote attestation and encryption connecting the device to the "hardware-secured sealed cloud environment"; first used by Magic Cue and Recorder on Pixel. Vendor post; supports only "Google reports" statements.

Original catalogue record ↗
S-1609 / Tier B2025 / preprint

Proofs of Useful Work from Arbitrary Matrix Multiplication ↗

I. Komargodski, O. Weinstein

arXiv · Last accessed by source map: 2026-09-25

Version: v1 14 April 2025; v4 13 November 2025. Also IACR ePrint 2025/685 (last revised 8 December 2025), listed there as a preprint. v3 listed I. Schen as a third author; v4 and the ePrint version list two. Remark, assumption and open-problem numbers follow the ePrint PDF.

Catalogue note

The construction underlying Pearl (I-0004). Pearl Research Labs lists the paper among its protocol research, and Komargodski gives Pearl Research Labs as his affiliation on S-1010. The paper itself names no company.

Original catalogue record ↗
S-1212 / Tier A2025 / peer reviewed

RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP ↗

B. Schlüter, S. Shinde

2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) · Last accessed by source map: 2026-10-08

Version: Read the authors' site and the paper PDF linked from it (https://rmpocalypse.github.io/rmpocalypse-CCS2025.pdf) on 2026-09-24. The DOI and venue are from the ACM reference block printed in the PDF.

Catalogue note

Independent attack paper (ETH Zurich). A malicious hypervisor corrupts AMD's Reverse Map Table during SEV-SNP initialisation, with no physical access. Confirmed on Zen 3, Zen 4 and Zen 5 processors. Demonstrates enabling debug on production confidential VMs, faking attestation, register-state replay and code injection. AMD assigned CVE-2025-0033; AMD's bulletin is S-1213.

Original catalogue record ↗
S-1213 / Tier B2025 / docs

SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020) ↗

AMD

AMD product security bulletin · Last accessed by source map: 2026-10-08

Version: Initial publication 2025-10-13; read in the revision last updated 2026-02-23.

Catalogue note

AMD's own bulletin on CVE-2025-0033 (RMPocalypse, S-1212); supports only "AMD reports" statements. Rates the issue CVSS 6.0 (medium) and lists SEV firmware, microcode or platform-initialisation firmware updates for affected EPYC 7003, 8004, 9004 and 9005 server series and embedded series, with release dates from June 2025 to February 2026.

Original catalogue record ↗
S-0041 / Tier A2025 / peer reviewed

Single-Node Power Demand During AI Training: Measurements on an 8-GPU NVIDIA H100 System ↗

I. Latif, A. C. Newkirk, M. R. Carbone, A. Munir, Y. Lin, J. Koomey, X. Yu, Z. Dong

IEEE Access, vol. 13, pp. 61740–61747 · Last accessed by source map: 2026-09-23

Version: Published in IEEE Access under a new title. The arXiv preprint (v1 11 December 2024, v2 20 December 2024) is titled "Empirical Measurements of AI Training Power Demand on a GPU-Accelerated Node". The published abstract, checked 2026-09-24, states the 8.4 kW peak and the 18% gap to the rated 10.2 kW that citing records use.

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1404 / Tier B2025 / docs

Sovereignty Certificates: draft specification, version 0.1.0 ↗

Sovereignty Certificates Working Group

GitHub (Lucid-Computing/sovereignty-certificate-specification) · Last accessed by source map: 2026-09-25

Version: Status "Draft", version 0.1.0, dated 2025-10-21, "Prepared by: Sovereignty Certificates Working Group". Read from spec/sovereignty-certificates.md on the main branch on 2026-09-23, at commit e65f5c1ba19094430bf586917b4760151759e990 (commit dated 2026-02-09; the repository's v0.1.0 tag points to the earlier commit 1d4bd34a6bff342db4fa4a43d143fe95eaa46b7d). Re-read on 2026-09-25: the repository still shows three commits and no code, and the title block, threat model (§8.1), §7.1.2-7.1.4, §8.3.3-8.3.4 and Annex B read as before.

Catalogue note

Hosted in Lucid Computing's GitHub organization. Documentation about the specifying party's own system, so it supports "the specification states / Lucid reports" statements only.

Original catalogue record ↗
S-1004 / Tier C2025 / blog

SYNTHETIC-2 ↗

Prime Intellect

Prime Intellect blog · Last accessed by source map: 2026-09-25

Catalogue note

Developer's blog post; describes its use of "TOPLOC v2". Supports only "Prime Intellect reports" statements.

Original catalogue record ↗
S-1813 / Tier B2025 / code

thinking-machines-lab/batch_invariant_ops (GitHub repository) ↗

Thinking Machines Lab

GitHub · Last accessed by source map: 2026-09-25

Version: Main branch as viewed on 2026-09-24 (7 commits). MIT licence.

Catalogue note

Companion library to S-1009. Replaces torch.mm, torch.addmm, torch.log_softmax and torch.mean with batch-invariant kernels through torch.Library, and includes a deterministic vLLM example: 18 unique samples out of 1000 completions without the upstream vLLM change, one unique sample with it.

Original catalogue record ↗
S-1000 / Tier A2025 / peer reviewed

TOPLOC: A Locality Sensitive Hashing Scheme for Trustless Verifiable Inference ↗

J. M. Ong, M. Di Ferrante, A. Pazdera, R. Garner, S. Jaghouar, M. Basra, M. Ryabinin, J. Hagemann

Proceedings of the 42nd International Conference on Machine Learning (PMLR 267), pp. 47196-47211 · Last accessed by source map: 2026-10-08

Version: Full text read from arXiv v2 (30 May 2025, HTML and PDF); PMLR abstract page checked for venue, pages and author list.

Original catalogue record ↗
S-1810 / Tier C2025 / blog

Verde Verification System In Production ↗

O. Ersoy

Gensyn research blog · Last accessed by source map: 2026-09-25

Catalogue note

Developer's post (page shows last modified 4 Sep 2026). States that Verde and RepOps are deployed in Judge, that Verde covers training, fine-tuning and inference, that RepOps gives bitwise-reproducible results across hardware, and that Verde guarantees the output came from the declared model and data, not that the model is correct. Supports only "Gensyn reports" statements.

Original catalogue record ↗
S-1809 / Tier B2025 / preprint

Verde: Verification via Refereed Delegation for Machine Learning Programs ↗

A. Arun, A. St. Arnaud, A. Titov, B. Wilcox, V. Kolobaric, M. Brinkmann, O. Ersoy, B. Fielding, J. Bonneau

arXiv · Last accessed by source map: 2026-10-08

Version: v1 (26 Feb 2025) read in HTML. dblp lists only the arXiv version.

Catalogue note

Most authors at Gensyn; Arun and Bonneau at New York University (Bonneau also a16z crypto research). Describes the Verde dispute protocol (correct result if at least one provider is honest) and RepOps; evaluation reports RepOps overheads on T4, RTX 3090 and A100 GPUs for DistilBERT and Llama models (Table 2: Llama-8B on A100 80 GB, 98% inference, 126% LoRA fine-tuning). RepOps supports FP32 and one GPU per setup.

Original catalogue record ↗
S-0004 / Tier B2025 / tech report

Verification for International AI Governance ↗

B. Harack, R. F. Trager, A. Reuel, D. Manheim, M. Brundage, O. Aarne, A. Scher, Y. Pan, J. Xiao, K. Loke, S. N. Adan, G. Bas, N. A. Caputo, J. C. Morse, J. Ahuja, I. Duan, J. Egan, B. Bucknall, B. Rosen, R. Araujo, V. Boulanin, R. Lall, F. Barez, S. Alvira, C. Katzke, A. Atamli, A. Awad

Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-09-25

Catalogue note

Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1211 / Tier A2025 / peer reviewed

WireTap: Breaking Server SGX via DRAM Bus Interposition ↗

A. Seto, O. K. Duran, S. Amer, J. Chuang, S. van Schaik, D. Genkin, C. Garman

2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) · Last accessed by source map: 2026-10-08

Version: Read the authors' site and the paper PDF linked from it (https://wiretap.fail/files/wiretap.pdf) on 2026-09-24. The DOI and venue are from the ACM reference block printed in the PDF; the ACM Digital Library page could not be fetched.

Catalogue note

Independent attack paper (Purdue University, Georgia Tech). DDR4 memory-bus interposer built for under $1000 (bill of materials $857) that records bus traffic. Recovers the ECDSA attestation key of Intel SGX's Quoting Enclave from a Xeon Scalable server in fully trusted status and forges SGX DCAP quotes. The site states that Intel considers the attack outside the SGX threat model and that there are no mitigations besides physical security. Several authors also wrote TEE.fail (S-1202).

Original catalogue record ↗
S-3060 / Tier A2025 / peer reviewed

zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM Inference ↗

W. Qu, Y. Sun, X. Liu, T. Lu, Y. Guo, K. Chen, J. Zhang

34th USENIX Security Symposium (USENIX Security 25), pp. 2045–2063 · Last accessed by source map: 2026-09-25

Version: Proceedings paper read from the USENIX PDF (usenixsecurity25-qu-zkgpt.pdf). Code archived on Zenodo, DOI 10.5281/zenodo.14727819 (v1, 23 January 2025, CC BY 4.0).

Catalogue note

National University of Singapore and Hong Kong University of Science and Technology. Proves GPT-2 inference with GKR, Lasso lookups and Hyrax commitments, made non-interactive with Fiat–Shamir; Table 3 reports 21.8 s proving (32 threads), 0.35 s verification and a 101 KB proof on a 16-core Xeon server with 200 GB of memory.

Original catalogue record ↗
S-0070 / Tier B2025 / tech report

Zkonduit EZKL Security Assessment ↗

F. Casal, T. Hess, L. Bourtoule, S. Hussain, G. Larregay

Trail of Bits (prepared for Zkonduit Inc.) · Last accessed by source map: 2026-09-23

Version: Final report of 12 March 2025. Review of 6–27 January 2025 (11 engineer-weeks) of ezkl at commit bdcba5ca61ada24f17dd754e6e3c71d0a1ef72d9 and two halo2-solidity-verifier pull requests; fix review 3–4 March 2025 (Appendix D).

Catalogue note

Independent security audit of the ezkl zero-knowledge inference library, commissioned by its developer. Reports 34 findings (8 high severity), including circuit soundness issues and quantization-activated model backdoors. Appendix D's limited fix review marks 29 resolved (including all 8 high-severity issues), 3 partially resolved and 2 unresolved. It says some contract fixes were in private repositories and had not been merged into public repositories at review time.

Original catalogue record ↗
S-0073 / Tier A2024 / peer reviewed

Accurate and Convenient Energy Measurements for GPUs: A Detailed Study of NVIDIA GPU's Built-In Power Sensor ↗

Z. Yang, K. Adamek, W. Armour

SC24: International Conference for High Performance Computing, Networking, Storage and Analysis · Last accessed by source map: 2026-09-25

Version: Published in the SC24 proceedings (presented 2024-11-19; DOI 10.1109/SC41406.2024.00028). The arXiv preprint is titled "Part-time Power Measurements: nvidia-smi's Lack of Attention" (v1 2023-12-05, v3 2024-12-12). The arXiv v3 abstract and HTML were read on 2026-09-25; the SC24 programme abstract was read the same day and states the 25% sampling finding. The IEEE and ACM pages could not be read.

Catalogue note

Micro-benchmark study of nvidia-smi power readings on over 70 NVIDIA GPUs across 12 architecture generations. States that nvidia-smi uses NVML (§2.4), that on A100 and H100 GPUs only 25% of runtime is sampled for power, and that the reading's error is ±5% (within ±5% in most cases, §4.2) rather than the ±5 W NVIDIA claims.

Original catalogue record ↗
S-0053 / Tier B2024 / preprint

Computing Power and the Governance of Artificial Intelligence ↗

G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle

arXiv · Last accessed by source map: 2026-09-25

Catalogue note

Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0). Also listed on the Oxford Martin AI Governance Initiative's publications page (https://aigi.ox.ac.uk/publications/computing-power-and-the-governance-of-artificial-intelligence/, read 2026-09-24). Also presented as a GovAI research paper (https://www.governance.ai/research-paper/computing-power-and-the-governance-of-artificial-intelligence, read 2026-09-24).

Original catalogue record ↗
S-1314 / Tier B2024 / preprint

DiLoCo: Distributed Low-Communication Training of Language Models ↗

A. Douillard, Q. Feng, A. A. Rusu, R. Chhaparia, Y. Donchev, A. Kuncoro, M. Ranzato, A. Szlam, J. Shen

ICML 2024 Workshop on Advancing Neural Network Training (WANT) · Last accessed by source map: 2026-09-25

Version: v1 submitted 14 November 2023; v3 revised 23 September 2024. Poster at the 2nd Workshop on Advancing Neural Network Training (WANT@ICML 2024), per the ICML 2024 page (https://icml.cc/virtual/2024/37144), checked 2026-09-24.

Original catalogue record ↗
S-0055 / Tier A2024 / peer reviewed

Foundational Challenges in Assuring Alignment and Safety of Large Language Models ↗

U. Anwar, A. Saparov, J. Rando, D. Paleka, M. Turpin, P. Hase, E. S. Lubana, E. Jenner, S. Casper, O. Sourbut, B. L. Edelman, Z. Zhang, M. Günther, A. Korinek, J. Hernandez-Orallo, L. Hammond, E. Bigelow, A. Pan, L. Langosco, T. Korbak, H. Zhang, R. Zhong, S. Ó hÉigeartaigh, G. Recchia, G. Corsi, A. Chan, M. Anderljung, L. Edwards, A. Petrov, C. Schroeder de Witt, S. R. Motwani, Y. Bengio, D. Chen, P. H. S. Torr, S. Albanie, T. Maharaj, J. Foerster, F. Tramèr, H. He, A. Kasirzadeh, Y. Choi, D. Krueger

Transactions on Machine Learning Research · Last accessed by source map: 2026-09-23

Version: Published in TMLR (2024); arXiv preprint 2404.09932. Venue and author list checked 2026-09-24 against the ML Anthology record of the TMLR paper, which gives "Sumeet Ramesh Motwani" (the arXiv metadata reads "Motwan").

Catalogue note

Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-0058 / Tier B2024 / tech report

Governing Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation ↗

L. Heim, T. Fist, J. Egan, S. Huang, S. Zekany, R. Trager, M. Osborne, N. Zilberman

Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-09-25

Version: Oxford Martin AI Governance Initiative policy paper dated 13 March 2024; also on arXiv (v1 13 March 2024, v2 26 March 2024), with no journal reference as of 2026-09-25.

Catalogue note

Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-0042 / Tier B2024 / preprint

Input-Dependent Power Usage in GPUs ↗

T. Gregersen, P. Patel, E. Choukse

SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis (Sustainable Supercomputing workshop), pp. 1872–1877 · Last accessed by source map: 2026-09-23

Version: Workshop paper at Sustainable Supercomputing at SC24 (IEEE Xplore document 10820679); kept at tier B as a workshop paper. The URL points to the arXiv version. Venue, pages and DOI from Crossref, checked 2026-09-24.

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1400 / Tier B2024 / tech report

Location Verification for AI Chips ↗

A. Brass, O. Aarne

Institute for AI Policy and Strategy · Last accessed by source map: 2026-09-25

Catalogue note

The IAPS page links the full report PDF (static1.squarespace.com/static/64edf8e7f2b10d716b5ba0e1/t/6670467ebe2a477eb1554f40/1718634112482/Location%2BVerification%2Bfor%2BAI%2BChips.pdf), which was read on 2026-09-23. The PDF text as fetched shows no byline or date. The current IAPS landing page presents the May 2025 issue brief by Asher Brass. Authors are taken from the IAPS issue brief (S-1401), which names Asher Brass and Onni Aarne and refers to a "full 2024 report", and from citations in S-1402 and S-0007. S-1402 cites it as April 2024; the month is not confirmed on the IAPS page itself.

Original catalogue record ↗
S-3081 / Tier A2024 / peer reviewed

Optimistic Verifiable Training by Controlling Hardware Nondeterminism ↗

M. Srivastava, S. Arora, D. Boneh

Advances in Neural Information Processing Systems 37 (NeurIPS 2024) · Last accessed by source map: 2026-09-25

Version: arXiv v3 (25 November 2024) read in HTML; v1 posted 14 March 2024. Venue from the arXiv comments field and the code README. The NeurIPS proceedings page was not read.

Catalogue note

Code at https://github.com/meghabyte/verifiable-training (not pinned). Exact FP32 replication of ResNet-50 (CIFAR-10) training and GPT-2 fine-tuning across NVIDIA A40, Titan XP and RTX 2080 Ti; trainer overhead 1.2–1.4×, auditor 1.3–1.7×; assumes one of n auditors is honest.

Original catalogue record ↗
S-1800 / Tier C2024 / blog

Private Cloud Compute: A new frontier for AI privacy in the cloud ↗

Apple Security Engineering and Architecture (SEAR)

Apple Security Research blog · Last accessed by source map: 2026-09-25

Catalogue note

Byline: SEAR with Apple's User Privacy, Core Operating Systems, Services Engineering, and Machine Learning and AI teams. Apple's description of its own system; supports only "Apple reports" statements. Covers the five core requirements, Apple silicon servers with the Secure Enclave and Secure Boot, the rule that devices wrap request keys only to nodes whose attested measurements match a release in the public transparency log, publication of production images within 90 days of log inclusion, integrity protection of code and model assets, and a threat model that includes attackers with physical access to a node.

Original catalogue record ↗
S-3542 / Tier A2024 / gov doc

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) ↗

European Parliament, Council of the European Union

Official Journal of the European Union, OJ L, 2024/1689 · Last accessed by source map: 2026-09-25

Version: The fetch tool could not render the articles on EUR-Lex, so Articles 51, 52 and 113 were read on the European Commission's AI Act Service Desk (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-51, article-52 and article-113). Article 51(2) presumes high-impact capabilities above 10^25 FLOP of cumulative training compute; Article 52(1) requires notification of the Commission within two weeks; Article 113(b) applies Chapter V from 2 August 2025.

Original catalogue record ↗
S-1801 / Tier C2024 / blog

Security research on Private Cloud Compute ↗

Apple Security Engineering and Architecture (SEAR)

Apple Security Research blog · Last accessed by source map: 2026-09-25

Catalogue note

Apple's announcement of its PCC research resources: the PCC Security Guide, the Virtual Research Environment (runs PCC node software in a VM on an Apple silicon Mac; lists and inspects releases, checks the transparency log, runs inference against demonstration models), source code for CloudAttestation, Thimble, splunkloggingd and srd_tools under a limited-use licence (github.com/apple/security-pcc), and PCC bounty categories of up to $1,000,000. Supports only "Apple reports" statements. The Security Guide itself (security.apple.com/documentation/private-cloud-compute) needs JavaScript and was not read.

Original catalogue record ↗
S-0032 / Tier A2024 / peer reviewed

Software-Based Memory Erasure with Relaxed Isolation Requirements ↗

S. Bursuc, R. Gil-Pons, S. Mauw, R. Trujillo-Rasua

2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024) · Last accessed by source map: 2026-09-25

Version: The record previously pointed to the arXiv extended version, "Software-Based Memory Erasure with relaxed isolation requirements: Extended Version" (https://arxiv.org/abs/2401.06626); section locators in citing records refer to that version. Venue and DOI from the Crossref record for the CSF 2024 paper, checked 2026-09-24.

Catalogue note

Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-3381 / Tier C2024 / blog

Verifiable Training of AI Models ↗

A. Aguirre, R. Millet

Future of Life Institute · Last accessed by source map: 2026-09-25

Version: The page shows publication on 2024-07-23 and an update on 2025-05-20.

Catalogue note

FLI (Aguirre) and Mithril Security (Millet) describe AICert, a proof of concept that uses Trusted Platform Modules to bind a model's weights to its training code and data, and state its limits (fine-tuning only, no third-party audit, no detection of poisoned models or datasets). Code at https://github.com/mithril-security/aicert, whose README warns that AICert is still under development and not for production use (read 2026-09-25). Supports "FLI reports" statements only.

Original catalogue record ↗
S-1110 / Tier A2024 / peer reviewed

Zero-Knowledge Proofs of Training for Deep Neural Networks ↗

K. Abbaszadeh, C. Pappas, J. Katz, D. Papadopoulos

2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330 · Last accessed by source map: 2026-10-08

Version: Read the IACR ePrint version (last revised 22 July 2024). Venue and DOI from the HKUST research portal record. On 2026-10-08 the abstract and indexed paper excerpts were re-read; direct PDF downloads were not reachable.

Catalogue note

Describes the Kaizen zkPoT system.

Original catalogue record ↗
S-0047 / Tier A2023 / peer reviewed

A Practical Introduction to Side-Channel Extraction of Deep Neural Network Parameters ↗

R. Joud, P.-A. Moëllic, S. Pontié, J.-B. Rigaud

21st International Conference on Smart Card Research and Advanced Applications (CARDIS 2022), LNCS 13820, pp. 45–65 · Last accessed by source map: 2026-09-23

Version: The CARDIS 2022 proceedings (LNCS 13820) were published in 2023 (online 29 January 2023); the year is the proceedings year. Venue, pages and DOI from the Springer chapter page, checked 2026-09-24.

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-0061 / Tier B2023 / tech report

International Governance of Civilian AI: A Jurisdictional Certification Approach ↗

R. Trager, B. Harack, A. Reuel, A. Carnegie, L. Heim, L. Ho, S. Kreps, R. Lall, O. Larter, S. Ó hÉigeartaigh, S. Staffell, J. J. Villalobos

Centre for the Governance of AI · Last accessed by source map: 2026-09-25

Catalogue note

Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0). Also listed on the Oxford Martin AI Governance Initiative's publications page (https://aigi.ox.ac.uk/publications/international-governance-of-civilian-ai-a-jurisdictional-certification-approach/, read 2026-09-24). Also presented as a GovAI research paper (https://www.governance.ai/research-paper/international-governance-of-civilian-ai, read 2026-09-24).

Original catalogue record ↗
S-1603 / Tier B2023 / tech report

Remote ATtestation procedureS (RATS) Architecture (RFC 9334) ↗

H. Birkholz, D. Thaler, M. Richardson, N. Smith, W. Pan

Internet Engineering Task Force (RATS Working Group) · Last accessed by source map: 2026-09-25

Version: IETF Informational RFC, January 2023. Not a Standards Track specification; the header states it represents the consensus of the IETF community. Recorded as a technical report (tier B) rather than a standard for that reason.

Original catalogue record ↗
S-1109 / Tier A2022 / peer reviewed

"Adversarial Examples" for Proof-of-Learning ↗

R. Zhang, J. Liu, Y. Ding, Z. Wang, Q. Wu, K. Ren

2022 IEEE Symposium on Security and Privacy (SP), pp. 1408-1422 · Last accessed by source map: 2026-09-25

Catalogue note

Read the arXiv version. Venue per the authors' code repository README (github.com/ZhangRui98/Adversarial-examples-for-Proof-of-Learning). The DOI resolves to IEEE Xplore document 9833596; OpenAlex gives the title, authors, venue and pages for it (checked 2026-09-25).

Original catalogue record ↗
S-0028 / Tier A2021 / peer reviewed

Proof-of-Learning: Definitions and Practice ↗

H. Jia, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, A. Thudi, V. Chandrasekaran, N. Papernot

2021 IEEE Symposium on Security and Privacy (SP), pp. 1039-1056 · Last accessed by source map: 2026-09-25

Version: Read the arXiv version (v1, 9 March 2021). DOI and pages from OpenAlex, checked 2026-09-25.

Catalogue note

Listed under "Proof of learning and training" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-0040 / Tier A2020 / peer reviewed

Detecting Covert Cryptomining Using HPC ↗

A. Gangwal, S. G. Piazzetta, G. Lain, M. Conti

Cryptology and Network Security – CANS 2020, LNCS 12579, pp. 344–364 · Last accessed by source map: 2026-09-25

Version: arXiv preprint first posted in 2019 (1909.00268); published at the 19th International Conference on Cryptology and Network Security (CANS 2020). The year is the proceedings year. Venue, pages and DOI from the Springer chapter page, checked 2026-09-24.

Catalogue note

Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).

Original catalogue record ↗
S-1608 / Tier B2017 / preprint

Proofs of Useful Work ↗

M. Ball, A. Rosen, M. Sabin, P. N. Vasudevan

IACR Cryptology ePrint Archive 2017/203 · Last accessed by source map: 2026-09-25

Version: The ePrint page describes it as a major revision of an IACR publication in CRYPTO 2018.

Original catalogue record ↗
S-1602 / Tier B2017 / docs

TCG Glossary ↗

Trusted Computing Group

Trusted Computing Group · Last accessed by source map: 2026-09-25

Version: Version 1.1, Revision 1.00 (11 May 2017). Full text read at https://trustedcomputinggroup.org/wp-content/uploads/TCG-Glossary-V1.1-Rev-1.0.pdf

Original catalogue record ↗
S-1607 / Tier A2015 / peer reviewed

Proofs of Space ↗

S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak

CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796) · Last accessed by source map: 2026-09-25

Version: The ePrint version states it is a minor revision of the CRYPTO 2015 publication.

Original catalogue record ↗
S-3260 / Tier A2011 / gov doc

Cryptographic Module Validation Program Certificate #1505: IBM 4765 Cryptographic Coprocessor Security Module ↗

National Institute of Standards and Technology

NIST Cryptographic Module Validation Program · Last accessed by source map: 2026-09-25

Version: Living certificate page. Read on 2026-09-25: initial validation 2011-02-24, last update 2012-12-21, overall Level 4, status Historical (reason given: RNG transition under SP 800-131A Rev. 1), so the module should not be included by federal agencies in new procurements.

Original catalogue record ↗
S-0074 / Tier B2010 / tech report

Refutation of "On the Difficulty of Software-Based Attestation of Embedded Devices" ↗

A. Perrig, L. van Doorn

Technical note (CyLab, Carnegie Mellon University) · Last accessed by source map: 2026-10-08

Version: Dated 11 August 2010. Read the copy hosted by ETH Zurich's network security group on 2026-10-07; the copy on sparrow.ece.cmu.edu refuses automated access. Some later papers cite it as April 2010.

Catalogue note

Reply to S-1308 by two designers of SWATT and ICE (Perrig at CyLab/CMU, van Doorn at AMD). Supports attributed statements only. Castelluccia et al. answered in a 2010 note; no public full text was found.

Original catalogue record ↗
S-0072 / Tier A2003 / standard

Guidelines for Writing RFC Text on Security Considerations (RFC 3552, BCP 72) ↗

E. Rescorla, B. Korver, Internet Architecture Board

Internet Engineering Task Force · Last accessed by source map: 2026-09-25

Version: IETF Best Current Practice (BCP 72), July 2003. Section 3, "The Internet Threat Model", defines a threat model and states its purpose. The RFC Editor lists it as updated by RFC 8996 (deprecating TLS 1.0 and 1.1) and RFC 9416 (transient numeric identifiers); neither changes Section 3.

Original catalogue record ↗