S-1206 / Tier B2026 / docs
Tinfoil
Tinfoil documentation · Last accessed by source map: 2026-10-08
Version: Living documentation with no publication date shown. The year is the year the page was accessed.
Catalogue note
Tinfoil's own documentation: the hardware it supports, its trust model, and the limitations it documents (physical attacks, side channels, I/O leakage, denial of service, supply chain, rollback). Supports "Tinfoil reports" statements.
Original catalogue record ↗S-1100 / Tier A2026 / peer reviewed
Z. Peng, C. Zhao, T. Wang, G. Liao, Z. Lin, Y. Liu, B. Cao, L. Shi, Q. Yang, S. Zhang
Artificial Intelligence Review, vol. 59, no. 7, article 157 · Last accessed by source map: 2026-09-25
Version: Read arXiv v2 (29 March 2026). Journal venue and DOI from Crossref (published 13 April 2026), checked 2026-09-24.
Catalogue note
Survey of ZKML literature from June 2017 to August 2025, organised into verifiable training, testing and inference.
Original catalogue record ↗S-0018 / Tier B2026 / tech report
N. Cankaya
Machine Intelligence Research Institute · Last accessed by source map: 2026-10-08
Catalogue note
Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3613 / Tier B2026 / docs
Epoch AI · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: data-first research nonprofit investigating the future of AI.
Original catalogue record ↗S-3609 / Tier B2026 / docs
Machine Intelligence Research Institute · Last accessed by source map: 2026-10-07
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description, re-read 2026-10-07: a nonprofit whose research and public outreach are intended to help prevent human extinction from the development of artificial superintelligence.
Original catalogue record ↗S-3604 / Tier B2026 / docs
NVIDIA · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: self-description as pioneer of accelerated computing.
Original catalogue record ↗S-3607 / Tier B2026 / docs
RAND · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: nonprofit nonpartisan research organization and evidence-based decisions.
Original catalogue record ↗S-1818 / Tier B2026 / docs
Centre for the Governance of AI · Last accessed by source map: 2026-09-25
Catalogue note
About page of GovAI. States that GovAI is a think tank that aims to help decision-makers in government and industry navigate the transition to a world with advanced AI; that it was founded at Yale University in 2016, became an academic centre at Oxford in 2018 and an independent nonprofit in 2021; that it has offices in London and Washington, DC; and that it is a US 501(c)(3) organization with a UK subsidiary. Self-description; supports "GovAI states" statements.
Original catalogue record ↗S-1705 / Tier B2026 / docs
Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-09-25
Catalogue note
About page of the Oxford Martin AI Governance Initiative (AIGI). States that AIGI is housed in the Martin School of the University of Oxford, studies the governance of AI from both technical and policy perspectives, and is co-led by Robert Trager and Maike Osborne; the AIGI homepage lists both as Co-Director. No page date. Self-description; supports "AIGI states" statements.
Original catalogue record ↗S-1507 / Tier B2026 / preprint
N. Kezins
arXiv · Last accessed by source map: 2026-09-25
Version: Read via the arXiv HTML rendering, which is dated 24 Aug 2026 (v1). The abs page did not render for the fetch tool.
Catalogue note
Independent attack paper (author affiliation Delft University of Technology) on the verification scheme of S-0015.
Original catalogue record ↗S-1008 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
Undated status page with no byline; its status labels ("Active effort", "Not started", "Not on track", "Uncertain") may change. Content as viewed on 2026-09-23; the recomputation items were unchanged on 2026-09-25.
Original catalogue record ↗S-3301 / Tier B2026 / docs
Epoch AI
Epoch AI · Last accessed by source map: 2026-09-25
Catalogue note
Living documentation for Epoch AI's AI data centers hub, launched as the Frontier Data Centers Hub; the name was checked on 2026-10-07; the page is undated and was read on 2026-09-25, when it gave the coverage estimate as of that date. Supports only statements attributed to Epoch AI.
Original catalogue record ↗S-3608 / Tier B2026 / docs
AI Futures Project · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: small research group forecasting the future of AI funded by donations and grants.
Original catalogue record ↗S-2010 / Tier C2026 / blog
B. Harack
Lawfare · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-3601 / Tier B2026 / docs
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: engineering company building tools for research.
Original catalogue record ↗S-1007 / Tier B2026 / code
Amodo Design
GitHub · Last accessed by source map: 2026-10-07
Version: Pinned to tag v0.2.0 (commit 7a77d927197750e16e839215e4d2400cd33e2c71), which Amodo's 15 September 2026 post links as the code for its tapped prototype (S-1312); read on 2026-10-07. Tag v0.1.0 is the earlier commit 4bc6872 (10 Sep 2026). The v0.2.0 README describes capture by a software sidecar and by a passive optical tap feeding a frame processor.
Catalogue note
The README describes its DiFR module as a vendored, modified copy of the upstream difr library.
Original catalogue record ↗S-1321 / Tier B2026 / code
Amodo Design
GitHub · Last accessed by source map: 2026-09-25
Version: Pinned to commit fae0935d37a4e2b983334e5b999cbc2c4b6edf67 (head of main on 2026-09-23, committed 2026-09-14; 2 commits, no tags).
Catalogue note
Linked from Amodo's note "Improving Disk Wiping Speed for Memory Wipes" (S-1303). The README says the repository is the disk-wiping path only and excludes the verifier and the RAM and GPU-HBM session code.
Original catalogue record ↗S-3001 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
No individual byline. Describes the authors' first prototype, which reuses the DiFR library, and its tests against two LoRA fine-tuning attacks on an 8×H100 server. Results are provider-reported.
Original catalogue record ↗S-3564 / Tier A2026 / gov doc
National Institute of Standards and Technology
National Institute of Standards and Technology · Last accessed by source map: 2026-09-25
Catalogue note
NIST describes OpenMined as a nonprofit developing open-source software for secure computation across organizations and names PySyft in a research agreement on confidential AI evaluations.
Original catalogue record ↗S-3602 / Tier B2026 / docs
Attestable · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: development of zero-knowledge proofs for AI systems.
Original catalogue record ↗S-3360 / Tier C2026 / blog
D. McCann-Sayles, T. Verma
Tinfoil blog · Last accessed by source map: 2026-09-25
Catalogue note
Tinfoil's account of Pour Demain running interpretability evaluations (vllm-lens) on GLM-5.1, about 744 billion parameters, on eight H200 GPUs in Tinfoil's confidential-computing platform, with the lab supplying the model, the auditor its evaluation code, and the weights kept inside the enclave. Reports 33-38% overhead with interpretability hooks enabled. Supports only "Tinfoil reports" statements.
Original catalogue record ↗S-1504 / Tier C2026 / blog
R. Rinberg, B. Penchas
LessWrong · Last accessed by source map: 2026-09-25
Catalogue note
Authors' own post describing a reference implementation (code linked from the post at github.com/RoyRin/auditor-in-a-TEE; its README was empty when fetched on 2026-09-23, so the code was not read).
Original catalogue record ↗S-1207 / Tier B2026 / docs
Tinfoil
Tinfoil documentation · Last accessed by source map: 2026-10-08
Version: Living documentation with no publication date shown. The year is the year the page was accessed.
Catalogue note
Tinfoil's description of its measured boot chain, reproducible builds, Sigstore publication of expected measurements, and client-side verification. Supports "Tinfoil reports" statements.
Original catalogue record ↗S-1013 / Tier B2026 / docs
vLLM project
vLLM documentation (GitHub, docs/features/batch_invariance.md) · Last accessed by source map: 2026-09-25
Version: Main branch as viewed on 2026-09-25 (GitHub source file; the rendered page at docs.vllm.ai did not return body text to the fetch tool on 2026-09-23). The feature is described as beta, supported on NVIDIA GPUs of compute capability 8.0 or higher and on Intel XPUs with Triton, and tested on dense and mixture-of-experts models.
Original catalogue record ↗S-1210 / Tier A2026 / peer reviewed
J. De Meulemeester, D. Oswald, I. Verbauwhede, J. Van Bulck
47th IEEE Symposium on Security and Privacy (S&P 2026) · Last accessed by source map: 2026-10-08
Version: Read the authors' site and the paper PDF linked from it (https://batteringram.eu/batteringram.pdf) on 2026-09-24. Venue from the BibTeX entry on the authors' site (47th IEEE S&P, May 2026); no DOI is printed in the PDF or on the site.
Catalogue note
Independent attack paper (KU Leuven, University of Birmingham and Durham University). DDR4 memory interposer with a bill of materials of $47.62. Reports arbitrary plaintext access to Intel Scalable SGX enclaves, extraction of SGX's platform provisioning key, and a full attestation breach on up-to-date AMD SEV-SNP by replaying launch digests. The site states that Intel and AMD acknowledged the findings but consider physical attacks on DRAM out of scope, and links Intel's guidance and AMD bulletin AMD-SB-3024. Hardware schematics and proof-of-concept code at https://github.com/batteringramattack/batteringram.
Original catalogue record ↗S-1804 / Tier C2026 / blog
D. Selmanaj
Sentry blog · Last accessed by source map: 2026-10-08
Catalogue note
Independent researcher's write-up of CVE-2026-20685, found in Apple's Virtual Research Environment: a path traversal in darwin-init's cryptex extraction gave root file writes that survived the node's userspace reboot and redirected splunkloggingd telemetry, exposing per-request metadata such as token counts and timings (the post does not say whether prompt or response content was exposed). All work was done in the VRE. States that the tampered node was indistinguishable from a clean one under `pccvre attestation verify`, and that Apple paid a $150,000 bounty.
Original catalogue record ↗S-0020 / Tier B2026 / preprint
N. Cankaya
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25
Version: arXiv v1 29 May 2026; v2 5 June 2026. The arXiv comments field reads "Best paper award, ICML 2026 TAIGR workshop"; the paper is listed in the workshop's poster session (https://icml.cc/virtual/2026/workshop/54084). Checked 2026-09-24.
Catalogue note
Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3129 / Tier A2026 / peer reviewed
Z. Gu, E. Valdez, S. Ahmed, J. J. Stephen, M. V. Le, H. Jamjoom, S. Zhao, Z. Lin
Proceedings of the 9th MLSys Conference (MLSys 2026) · Last accessed by source map: 2026-09-25
Version: Read arXiv v2 (2026-04-17), whose header names the 9th MLSys Conference (Bellevue, 2026). v1 (2025-07-03) was titled "NVIDIA GPU Confidential Computing Demystified".
Catalogue note
Independent security analysis (IBM Research and The Ohio State University) of NVIDIA's GPU confidential computing on Hopper. Concludes that bulk command and data transfers are protected, but some metadata, timing behaviour and coordination signals remain in unprotected shared memory, which can reveal computational behaviour and in some cases allow manipulation of operations ("a partial loss of integrity"). Findings were disclosed to NVIDIA PSIRT. No attestation break is reported.
Original catalogue record ↗S-3363 / Tier C2026 / blog
Lucid Computing
Lucid Computing (Substack) · Last accessed by source map: 2026-09-25
Catalogue note
Lucid's announcement of an adversarial testbed it is "building and operating" inside an unnamed "government-funded research institute that runs clusters for domestic workloads". The host institute "holds technical authority over adversarial testing" and sets the test plan. The first configuration retrofits two eight-GPU H100 servers against three claims (where compute runs, how it is used, what model is loaded), with an 18-month goal. Supports only "Lucid reports" statements.
Original catalogue record ↗S-3022 / Tier C2026 / blog
D. Jedamski
Gensyn blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's post on Delphi, Gensyn's information-market app. States that "Delphi is live on Gensyn Mainnet" and that "hosted REE settlement is available for partner markets", and that open-source models running inside REE "produce a receipt that can be independently rerun to verify the answer". Describes no dispute process and does not mention Verde. Supports only "Gensyn reports" statements.
Original catalogue record ↗S-3566 / Tier C2026 / blog
joshc
AI Alignment Forum · Last accessed by source map: 2026-09-25
Catalogue note
Author's public analysis of inference-only verification limits, RL rollouts, work accounting and residual bandwidth.
Original catalogue record ↗S-3612 / Tier B2026 / docs
Center for a New American Security · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: independent bipartisan nonprofit producing national-security and defense policy.
Original catalogue record ↗S-0065 / Tier C2026 / blog
A. Chan
A Strange Attractor · Last accessed by source map: 2026-09-23
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3361 / Tier C2026 / blog
A. Tlaie Boria
Pour Demain · Last accessed by source map: 2026-09-25
Catalogue note
The auditor's own account. States that all measurements were collected on a production confidential-computing platform (Tinfoil Containers, Intel TDX, 8x NVIDIA H200) running GLM-5.1, a 744-billion-parameter open-weights mixture-of-experts model; five interpretability workloads; "raw tensors never cross the enclave boundary". Governance features were shown at single-session level only. Links a PDF white paper that was not read.
Original catalogue record ↗S-3321 / Tier B2026 / docs
Google Cloud
Google Cloud documentation · Last accessed by source map: 2026-09-25
Version: Page last updated 2026-09-22 (UTC), read on 2026-09-25.
Catalogue note
Vendor documentation; supports only "Google reports" statements. Describes an isolated environment to operate on sensitive data from multiple parties, with data collaborators, workload authors and workload operators; data is released only to workloads whose attestation meets the collaborators' conditions, and the operator has no access to the data. Runs on AMD SEV, Intel TDX, or Intel TDX with NVIDIA Confidential Computing.
Original catalogue record ↗S-3322 / Tier B2026 / docs
Google Cloud
Google Cloud documentation · Last accessed by source map: 2026-09-25
Catalogue note
Vendor release notes; support only "Google reports" statements. Confidential Space generally available on 2023-03-28; on Intel TDX (C3) on 2025-03-31; on H100 GPUs (a3-highgpu-1g) on 2026-04-29; on H100 with Intel Trust Authority attestation on 2026-09-15.
Original catalogue record ↗S-0011 / Tier B2026 / preprint
S. Ding, E. Lee, R. Cheng, D. Kang
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25
Version: Only the abstract was read, on the ICML 2026 virtual poster page (https://icml.cc/virtual/2026/78562), on 2026-09-23 and 2026-09-25; the OpenReview forum and PDF were not reachable with the fetch tool. No arXiv version was found.
Catalogue note
Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1505 / Tier B2026 / code
covehub
GitHub · Last accessed by source map: 2026-10-08
Version: Pinned to commit a3e4904926d7c9c160d232222d95f5db316627ca (main as of 2026-09-23, obtained with git ls-remote). Read README.md, docs/internal/architecture.md and docs/internal/security_model.md at that commit via raw.githubusercontent.com; the files were identical to main on that date. On 2026-09-25 security_model.md was re-read at the pinned commit and README.md on main; the github.com repository page returned 404 to the fetch tool, while raw files on main still loaded.
Catalogue note
Reference implementation of S-0011; developer documentation of its own system supports "reports" statements only.
Original catalogue record ↗S-1410 / Tier C2026 / blog
B. Halstead, T. Larsen
AI 2040 · Last accessed by source map: 2026-09-25
Catalogue note
Supplement to the AI 2040 scenario (AI Futures Project). The supplement page shows no date; the AI Futures blog announced AI 2040 on 2026-07-09, so the year is inferred from that announcement.
Original catalogue record ↗S-1805 / Tier B2026 / docs
Apple (CVE Numbering Authority)
CVE Program · Last accessed by source map: 2026-09-25
Version: Read through the CVE Services API (https://cveawg.mitre.org/api/cve/CVE-2026-20685) because the cve.org page needs JavaScript. Affected product: Private Cloud Compute Server Software before 5E290.3.
Catalogue note
Vendor-assigned description: "An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation."
Original catalogue record ↗S-3126 / Tier A2026 / peer reviewed
J. De Meulemeester, S. Gloor, P. Jattke, D. Moghimi, D. Oswald, M. Thompson, K. Razavi, I. Verbauwhede, J. Van Bulck
2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26) · Last accessed by source map: 2026-10-08
Version: Read the authors' site and the paper PDF linked from it (https://ddropattack.eu/ddrop.pdf) on 2026-09-25. The PDF names CCS '26 (The Hague); the conference is in November 2026, and no DOI is printed. Disclosed on 2026-09-14.
Catalogue note
Independent attack paper (KU Leuven, ETH Zurich, Durham University and Google). An active DDR5 RDIMM interposer with a bill of materials of $159 injects parity errors so that cache-line writebacks are silently dropped, which the missing freshness protection in scalable memory encryption does not detect. Attacker model: brief physical access to install the interposer, plus control of host software and BIOS. Demonstrates forcing any TD into debug mode and forging attestation reports on an up-to-date Intel TDX platform, and integrity breaks of Scalable SGX and AMD SEV-SNP (no SEV-SNP attestation forgery reported). The site states that Intel and AMD consider physical attacks on DRAM out of scope for current products and issued security advisories on disclosure (AMD-SB-3048).
Original catalogue record ↗S-3220 / Tier C2026 / blog
A. Scher, D. Sarbakysh, A. Moskvin
MIRI Technical Governance Team · Last accessed by source map: 2026-09-25
Catalogue note
Prototype of inter-node bandwidth monitoring against a threshold on a two-node Azure cluster (four A100 PCIe GPUs, one 100 GbE link), with violating training, compliant inference and a DiLoCo evasion workload. Carried out by Sarbakysh and Moskvin through SPAR under Scher's supervision. Code and reproduction instructions are linked at https://github.com/Yayka/ml-infra-profiler (MIT licence); no commit could be pinned, because the commit list could not be read on 2026-09-25.
Original catalogue record ↗S-1011 / Tier B2026 / tech report
DeepSeek-AI
arXiv · Last accessed by source map: 2026-09-25
Version: Read v1 (PDF), section 3.3 on batch-invariant and deterministic kernel libraries. The abstract page gives a v1 timestamp of 26 Apr 2026, which does not match the 2606 identifier; date left unset.
Catalogue note
Developer's report on its own systems; kernel statements are provider-reported. Several hundred authors; listed under the organisational author.
Original catalogue record ↗S-3400 / Tier A2026 / gov doc
Organisation for the Prohibition of Chemical Weapons
OPCW · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-0059 / Tier A2026 / peer reviewed
E. Seferis, T. Fist
Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment) · Last accessed by source map: 2026-09-23
Version: An earlier version appeared at the ICML 2025 Workshop on Technical AI Governance (https://openreview.net/forum?id=qseqw1sWzz). AAAI proceedings page checked 2026-09-24 for venue, pages and DOI.
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0037 / Tier B2026 / preprint
R. Rahman, S. Tajdari
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25
Version: v1 (2026-06-17) read on 2026-09-25. The paper header reads "Proceedings of the Second Workshop on Technical AI Governance Research (TAIGR) at the 43rd International Conference on Machine Learning, Seoul". Affiliations: R. Rahman (Machine Intelligence Research Institute), S. Tajdari (University of Virginia).
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0060 / Tier B2026 / preprint
R. Rahman
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25
Version: arXiv v1, 28 May 2026. Poster at the Second Workshop on Technical AI Governance Research (ICML 2026), per the workshop page (https://icml.cc/virtual/2026/workshop/54084), checked 2026-09-25.
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3320 / Tier B2026 / tech report
A. Trask, S. Messing, V. Pahwa, P. Maham, R. Kolga, A. Frantz, A. Tash, K. Thomas, S. McGregor, G. Balston, P. Paskov, M. Brundage, A. Vij, B. Hillenbrand, A. Karargyris, T. Acosta, J. Fenster, M. Eilish, R. Elasmar, M. Khan, K. van der Veen, R. S, S. Wagh, S. Gabriel, P. Werneck, L. Strahm, K. McDonough, R. Falcon, K. Lum, W. Isaac
Google DeepMind · Last accessed by source map: 2026-10-08
Version: Technical report linked from Google DeepMind's blog post "Piloting the world's first double-blind AI evaluations" (https://deepmind.google/blog/piloting-the-worlds-first-double-blind-ai-evaluations/, dated 2026-08-27). The PDF prints no date. Author affiliations as printed: Google, AVERI, Singapore AISI, OpenMined and ML Commons. No arXiv version was found on 2026-09-25.
Catalogue note
Report by the pilot's participants on their own system; supports "the participants report" statements. Gemini 2.5 Flash Lite was evaluated against private AILuminate prompts in a GCP Confidential Space enclave (a3-highgpu-1g, one NVIDIA H100 with Intel TDX), using OpenMined's PySyft; both parties verified the attestation before uploading assets.
Original catalogue record ↗S-3020 / Tier B2026 / preprint
D. Ribeiro Alves, V. Patankar, M. Pereira, J. Stephens, N. Vaziri, S. Kannan
arXiv · Last accessed by source map: 2026-09-25
Version: v1 (30 Jan 2026), the only version, read in HTML.
Catalogue note
Developer's paper on its own system (all authors give eigenlabs.org addresses); statements about EigenAI are provider-reported. Describes a deterministic inference engine built on llama.cpp with custom GEMM and reduction kernels, and an optimistic re-execution protocol in which a stake-weighted committee re-executes challenged outputs inside TEEs. Table 5 reports bitwise-identical outputs on the same host and GPU and across hosts with the same GPU SKU, and a 0.0% match between A100 and H100.
Original catalogue record ↗S-1503 / Tier B2026 / preprint
B. Penchas, G. Zhao, R. Rinberg
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25
Version: Only the abstract was read, on the ICML 2026 virtual poster page. The OpenReview forum (https://openreview.net/forum?id=AWZJq6O7Cj) was not reachable with the fetch tool.
Catalogue note
The second author appears as "G Zhao" on the ICML page.
Original catalogue record ↗S-0017 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1802 / Tier C2026 / blog
Apple Security Engineering and Architecture (SEAR)
Apple Security Research blog · Last accessed by source map: 2026-10-08
Catalogue note
Apple's announcement that PCC extends to Google Cloud systems with NVIDIA GPUs, using NVIDIA Confidential Computing, Intel CPUs with TDX and Google's Titan chip; for components that could be abused to exfiltrate user data if compromised, attestation "rooted in at least two separate roots of trust from independent vendors"; attested keys held in a separate confidential VM; binaries to be published and live nodes available in research mode through the Apple Security Bounty. States that PCC on Google Cloud "will be gradually ramping towards the complete set of protections throughout the summer preview period". Supports only "Apple reports" statements.
Original catalogue record ↗S-1702 / Tier B2026 / docs
Lucid Computing · Last accessed by source map: 2026-10-08
Catalogue note
Lucid Computing's page on the bare-metal research cluster that it says the Verifiable Compute Foundation provides and allocates: accelerators, research "layers", and access terms ("Free for qualifying safety & verification research"; Lucid "takes no part in allocation decisions"). The page says the cluster opens to the community in November, without a year (2026 by context). No page date; copyright 2026. Supports "Lucid reports" statements only.
Original catalogue record ↗S-3127 / Tier A2026 / peer reviewed
B. Schlüter, C. Wech, S. Shinde
35th USENIX Security Symposium (USENIX Security '26) · Last accessed by source map: 2026-10-08
Version: USENIX Security '26 presentation page (pp. 5613–5632, August 2026) and the paper PDF (https://www.shwetashinde.org/publications/fabricked_usenix26.pdf), read on 2026-09-25. The authors' site (https://fabricked-attack.github.io/) could not be read by the fetch tool.
Catalogue note
Independent attack paper (ETH Zurich). A software adversary that controls the hypervisor and UEFI firmware misconfigures Infinity Fabric routing so that writes by the AMD Secure Processor during SEV-SNP initialisation go astray, leaving the system falsely initialised. Demonstrated on a Zen 5 EPYC 9135: arbitrary read and write in the victim CVM, debug mode enabled after attestation, and forged attestation reports. The authors could not test Zen 3 or Zen 4. AMD's bulletin is S-3128.
Original catalogue record ↗S-3200 / Tier C2026 / blog
Singapore AI Safety Hub (SASH)
SASH blog · Last accessed by source map: 2026-09-25
Catalogue note
Dated July 2026 on the page; no individual byline.
Original catalogue record ↗S-1300 / Tier B2026 / preprint
N. Cankaya, J. Kryś, J. Ng, L. Marks, F. Krückel
arXiv · Last accessed by source map: 2026-09-25
Version: v1, submitted 9 June 2026; read via the arXiv HTML rendering. The Oxford Martin AI Governance Initiative published an earlier version dated April 2026 (https://aigi.ox.ac.uk/wp-content/uploads/2026/04/Fingerprinting_All_AI_Cluster_IO.pdf; publication page dated 28 April 2026) before arXiv v1. Both versions give the first author's affiliations as MATS and the Oxford Hardware AI Governance Lab. arXiv still lists only v1, with no journal reference, on 2026-09-25.
Original catalogue record ↗S-1312 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-10-07
Catalogue note
No individual byline. The post links its code at tag v0.2.0 (S-1007).
Original catalogue record ↗S-1103 / Tier C2026 / blog
Attestable
Attestable blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's own proposal for a "verification firewall" that checks sampled outputs with zero-knowledge proofs. No visible date; the year comes from the site's copyright notice.
Original catalogue record ↗S-0003 / Tier B2026 / preprint
M. Brundage, N. Dreksler, A. Homewood, S. McGregor, P. Paskov, C. Stosz, G. Sastry, A. F. Cooper, G. Balston, S. Adler, S. Casper, M. Anderljung, G. Werner, S. Mindermann, V. Mavroudis, B. Bucknall, C. Stix, J. Freund, L. Pacchiardi, J. Hernandez-Orallo, M. Pistillo, M. Chen, C. Painter, D. W. Ball, C. O'Keefe, G. Weil, B. Harack, G. Finley, R. Hassan, S. Emmons, C. Foster, A. Reuel, B. Treece, Y. Bengio, D. Reti, R. Bommasani, C. Trout, A. S. Shamsabadi, R. Dattani, A. Weller, R. Trager, J. Sevilla, L. Wagner, L. Soder, K. Ramakrishnan, H. Papadatos, M. Murray, R. Tovcimak
arXiv · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3611 / Tier B2026 / docs
Future of Life Institute · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: self-description as independent nonprofit and mission to steer transformative technology away from extreme risks.
Original catalogue record ↗S-1812 / Tier B2026 / code
Gensyn
GitHub · Last accessed by source map: 2026-10-07
Version: Main branch as viewed on 2026-10-07 (commit 9e9a784, 5 October 2026); README patch notes run to v0.8.0 (5 October 2026), after v0.7.0 (30 September 2026), and v0.2.0 (20 April 2026) adds pipeline parallelism for models of up to 72B and a threefold cut in reproducible-mode overhead. The SDK is MIT-licensed; the REE compiler and reproducible-operators binaries ship in Docker images under a proprietary binary licence.
Catalogue note
REE runs LLM inference reproducibly and writes JSON receipts with the model, prompt, output and the metadata needed to reproduce the run, with verify and validate subcommands. Developer's repository.
Original catalogue record ↗S-3560 / Tier B2026 / docs
Gensyn · Last accessed by source map: 2026-09-25
Catalogue note
Company homepage, read 2026-09-25. The title is the HTML page title. States that "Gensyn builds AI that forecasts – and keeps improving – by verifiably closing the loop between prediction and reality", and lists Delphi (information markets) and REE (Reproducible Execution Environment) among its products. Supports "Gensyn reports" statements only.
Original catalogue record ↗S-1511 / Tier C2026 / blog
AI Futures Project
AI 2040 · Last accessed by source map: 2026-09-25
Version: The page states it was updated on 9 July 2026. Content as viewed on 2026-09-23; the workstream statuses were unchanged on 2026-09-25, and the site changelog lists only changes to event and contact links on the page since then.
Catalogue note
Companion page to S-0067 listing open technical problems for the plan's verification components.
Original catalogue record ↗S-1403 / Tier B2026 / preprint
W. Tee, J. Happel
arXiv · Last accessed by source map: 2026-09-25
Version: v1 (2026-05-03) read on 2026-09-23; v2 (2026-06-01) read on 2026-09-25 via arxiv.org/html/2605.01930v2. The figures cited (24 H200 GPUs, 480 runs, 98.8% single-run and 100% paired-run accuracy, about 2.9 s per run) and the stated limitations are unchanged in v2. Affiliations: W. Tee (Pivotal Research), J. Happel (TamperSec).
Original catalogue record ↗S-1508 / Tier B2026 / preprint
R. Rinberg, A. M. Carrell, S. Henniger, N. Carlini, K. Warr
arXiv · Last accessed by source map: 2026-09-25
Version: v2 or later, read via the arXiv HTML rendering; v1 was titled "Haiku to Opus in Just 10 bits: LLMs Unlock Massive Compression Gains". Code: https://github.com/RoyRin/model-compression-bit-limiting. No venue found as of 2026-09-25.
Original catalogue record ↗S-1703 / Tier B2026 / docs
Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-10-08
Catalogue note
Programme page of the Hardware AI Governance Lab (HAIGL), "an interdisciplinary initiative hosted by the Oxford Martin AI Governance Initiative". States the lab's aims, says it expects to release its first hardware governance design profile in late 2026, names Amro Awad and Robert Trager as HAIGL Co-Directors and Ben Harack as Co-founder & Research Lead, and lists recent publications, including S-1300 (dated 28 April 2026 on the page) and S-1704. No page date. Self-description; supports "the lab states" statements.
Original catalogue record ↗S-0036 / Tier B2026 / preprint
H. Ma, J. Forzani, L. Malek, D. Wentzlaff
arXiv · Last accessed by source map: 2026-09-25
Version: Author order follows the current arXiv HTML version (arxiv.org/html/2607.18069), read 2026-09-23: Ma, Forzani, Malek, Wentzlaff, and it was unchanged on 2026-09-25. The v1 HTML (arxiv.org/html/2607.18069v1) lists Malek before Forzani, as the bibliography did.
Catalogue note
Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0007 / Tier B2026 / preprint
S. Ansari
arXiv · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1010 / Tier A2026 / peer reviewed
E. Badash, D. Boneh, I. Komargodski, M. Srivastava
Proceedings of Machine Learning and Systems 8 (MLSys 2026) · Last accessed by source map: 2026-10-08
Version: Full text read from arXiv HTML v2 (15 May 2026); MLSys proceedings abstract page checked. The arXiv abstract page could not be rendered by the fetch tool, so the v1 date was not confirmed.
Catalogue note
Code at github.com/badasherez/gpu-simulator (MIT; release tag "MLSys Release", 4 Apr 2026). Badash and Komargodski are at Pearl Research Labs, Boneh and Srivastava at Stanford University.
Original catalogue record ↗S-1510 / Tier B2026 / tech report
S. F. Comer, H. Pavela, V. Gandhi, K. Siler-Evans, E. Devendorf, B. Kelley, J. Gimbi, J. Aguirre, G. Kulp, M. Stalczynski, M. J. Malone
RAND Corporation (Research Report RR-A4827-1) · Last accessed by source map: 2026-09-25
Version: Read the landing page and the PDF (https://www.rand.org/content/dam/rand/pubs/research_reports/RRA4800/RRA4827-1/RAND_RRA4827-1.pdf), 51 pages. Author list taken from the PDF title page.
Catalogue note
Produced by RAND's Center on AI, Security, and Technology (CAST).
Original catalogue record ↗S-1112 / Tier B2026 / preprint
C. Gong, B. Liu, M. Li
arXiv · Last accessed by source map: 2026-09-25
Version: v1 (30 July 2026), read via the arXiv HTML and PDF renderings; the abstract page did not render for the fetch tool. Author order is as printed on the paper's title page; a mirror of the arXiv listing (pith.science) lists B. Liu first. A co-author's web page labels the paper "IEEE S&P 2026", but no proceedings record was found and a co-author's CV lists it as under submission, so it is recorded as a preprint.
Catalogue note
Independent analysis (University of Southern California) of zero-knowledge proofs of LLM inference. Shows that valid proofs do not bind the computation spent, using "ghost weights"; experiments use the proof procedure of zkGPT on a 6-layer, 512-dimensional transformer.
Original catalogue record ↗S-0013 / Tier C2026 / blog
Tinfoil Team
Tinfoil · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1208 / Tier B2026 / docs
Tinfoil
Tinfoil documentation · Last accessed by source map: 2026-09-25
Version: Living documentation with no publication date shown. The year is the year the page was accessed.
Catalogue note
Tinfoil's overview of connection-time verification and transparency logs. Supports "Tinfoil reports" statements.
Original catalogue record ↗S-2004 / Tier A2026 / gov doc
International Atomic Energy Agency
IAEA fact sheet · Last accessed by source map: 2026-09-25
Catalogue note
The page is undated; the year is the year it was read.
Original catalogue record ↗S-1303 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
No individual byline on the page.
Original catalogue record ↗S-1319 / Tier B2026 / code
Singapore AI Safety Hub (SASH)
GitHub · Last accessed by source map: 2026-09-25
Version: Pinned to commit d7353b55fea6f36a6faa801011b203df7f0945e3 (head of main on 2026-09-23, committed 2026-09-02; 35 commits, no tagged releases).
Original catalogue record ↗S-3130 / Tier B2026 / preprint
M. Shen, Y. Qin
arXiv · Last accessed by source map: 2026-10-08
Version: arXiv v1, submitted 13 May 2026. Re-read the abstract and HTML on 2026-10-08, including the threat model, affected EPYC Milan platform and vendor-response appendix. No venue is given.
Catalogue note
Attack preprint (Institute of Software, Chinese Academy of Sciences). With root control of the host and the ability to rewrite the SPI flash, but no physical access, the attacker downgrades an EPYC Milan (Zen 3) platform to legacy AMD Secure Processor firmware, gains code execution there (MilanLaunchy) and extracts the full hardware root seed from which SEV-SNP's VCEK attestation keys are derived (BadFuse). The authors state this lets them forge attestation reports for any firmware version. Disclosed to AMD in January and April 2026; AMD's bulletin on MilanLaunchy is S-3131.
Original catalogue record ↗S-3610 / Tier B2026 / docs
Institute for AI Policy and Strategy · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: nonpartisan think tank producing AI policy research.
Original catalogue record ↗S-1706 / Tier B2026 / docs
Intelligence Security Laboratories · Last accessed by source map: 2026-09-25
Catalogue note
Homepage of Intelligence Security Laboratories (ISL); intseclab.org redirects here. States that ISL is a nonprofit research lab for high-security AI systems, its aim of developing and demonstrating the security that critical AI deployments need, its role as integrator of the secure data centre as a whole system, its use of STPA-Sec and formal methods, and its plan to hand knowledge and artifacts to others; refers to RAND's secure inference data center report (S-1510) for details of STPA-Sec. The footer gives 501(c)(3) nonprofit status. No page date. Self-description; supports "ISL states" statements.
Original catalogue record ↗S-1320 / Tier C2026 / blog
Singapore AI Safety Hub (SASH)
SASH blog · Last accessed by source map: 2026-10-05
Catalogue note
Dated June 2026 on the page; no individual byline.
Original catalogue record ↗S-3180 / Tier B2026 / blog
C. Shrauder, G. Frederick
NVIDIA Technical Blog · Last accessed by source map: 2026-09-25
Catalogue note
NVIDIA's description of its own fleet-management service; supports only "NVIDIA reports" statements. States that the service is generally available at no cost for Hopper, Blackwell and Vera Rubin GPUs; that a read-only, host-based agent (built on GPUd, DCGM and the NVIDIA Attestation SDK) streams power, temperature, performance, health and configuration telemetry to an NVIDIA cloud service; that the agent is released as open source "for auditability" (github.com/NVIDIA/Fleet-Intelligence-Agent); and that GPU attestation evidence obtained at run time is signed with on-device certificates rooted in NVIDIA's root of trust and verified with NRAS. It does not say that the telemetry values themselves are signed. Follows the December 2025 announcement in S-1413.
Original catalogue record ↗S-0044 / Tier A2026 / peer reviewed
P. Horvath, I. Shumailov, L. Chmielewski, L. Batina, Y. Yarom
IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2026) · Last accessed by source map: 2026-09-25
Version: arXiv v1 3 Mar 2026, v3 27 Mar 2026. Listed among the accepted papers of IEEE SaTML 2026 (Munich, 23–25 March 2026), https://satml.org/2026/accepted-papers/, checked 2026-09-25.
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1808 / Tier B2026 / code
Lagrange Labs
GitHub · Last accessed by source map: 2026-09-25
Version: Main branch as viewed on 2026-09-25 (1,219 commits, no releases). Licensed under the Lagrange License.
Catalogue note
Developer's repository. README reports end-to-end proofs of GPT-2, Gemma 3 and Llama 2 inference with sumcheck and logup GKR, and on a 24-core, 504 GB CPU server: GPT-2 at 512 tokens in 7.6 min (verify 1.3 s, 10.7 MiB proof) and Gemma 3 at 512 tokens in 19 min; at least 99.6% cosine similarity to floating point at 12-bit quantization (GPT-2).
Original catalogue record ↗S-1014 / Tier B2026 / preprint
R. Gond, A. K. Kamath, R. Ramjee, A. Panwar
arXiv · Last accessed by source map: 2026-09-25
Version: Abstract of v2 (30 Jan 2026) read; full text not reviewed. Code listed at github.com/microsoft/llm-42.
Original catalogue record ↗S-1406 / Tier B2026 / docs
Lucid Computing · Last accessed by source map: 2026-09-25
Catalogue note
Company homepage, read 2026-09-23 and 2026-09-25. The title above is the hero text; the HTML page title is "Lucid Computing - Provable trust infrastructure for frontier AI". Supports "Lucid reports" statements only.
Original catalogue record ↗S-1407 / Tier B2026 / docs
Lucid Computing · Last accessed by source map: 2026-09-25
Catalogue note
Pages read on 2026-09-23 include the index, concepts/architecture.html, concepts/glossary.html and reference/auditor-catalog.html; the auditor catalog and architecture pages were re-read on 2026-09-25. Supports "Lucid reports" statements only.
Original catalogue record ↗S-1701 / Tier B2026 / docs
Lucid Computing · Last accessed by source map: 2026-10-08
Catalogue note
Lucid Computing's page on its research programme: an experimentation cluster provided by the Verifiable Compute Foundation, which it describes as "an independent nonprofit working to create a toolbox of AI verification techniques"; red-teaming with national security agencies and government research institutes; deployment; and standards work. No page date; copyright 2026. Supports "Lucid reports" statements only.
Original catalogue record ↗S-1302 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Version: Page carries a correction note saying the original post's wipe-time results were revised; figures used here are the corrected ones.
Catalogue note
No individual byline on the page.
Original catalogue record ↗S-3131 / Tier B2026 / docs
AMD
AMD product security bulletin · Last accessed by source map: 2026-09-25
Catalogue note
AMD's own bulletin on MilanLaunchy (S-3130); supports only "AMD reports" statements. Lists CVE-2021-26315, CVE-2024-21944 and CVE-2024-21981, rates the report informational, and calls it "a legacy attack that was previously mitigated in 2021". Mitigation: MilanPI 1.0.0.3 or later for EPYC 7003.
Original catalogue record ↗S-1209 / Tier B2026 / code
Tinfoil
GitHub · Last accessed by source map: 2026-09-25
Version: Release v0.3.0 (commit b6850e3), still the latest release listed on 2026-09-25.
Catalogue note
Open-source tool Tinfoil uses to commit model weights to a dm-verity root hash (see S-0013).
Original catalogue record ↗S-0068 / Tier A2026 / peer reviewed
Z. Wang
International Conference on Information and Communications Security (ICICS 2026) · Last accessed by source map: 2026-09-25
Version: Current arXiv HTML read on 2026-09-25; its abstract matches v2, which states acceptance at the 28th ICICS (Springer LNCS, Fukui, 27–30 October 2026) and is an extended version with appendices not in the proceedings. v1 (March 2026) reports different timings. The abstract gives 3.5–3.7 KB per sub-circuit proof, while §3.1 and §6.1 give 3.2–3.7 KB.
Catalogue note
Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1402 / Tier B2026 / tech report
B. Avellar, E. Grunewald
Institute for AI Policy and Strategy · Last accessed by source map: 2026-10-07
Version: IAPS report dated 19 August 2026; its research page, read on 2026-10-07, says it was written by Erich Grunewald and co-authored by Bruna Avellar. arXiv 2609.07637 v1 (7 September 2026) states that it is a reformatted version of that report. v1 read via the arXiv HTML rendering (arxiv.org/html/2609.07637); the abstract page returned no extractable text to the fetch tool. Affiliations as shown: B. Avellar (independent researcher), E. Grunewald (Institute for AI Policy and Strategy).
Original catalogue record ↗S-1310 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
No individual byline on the page. Amodo republished the note on its Substack on 2026-05-14 as "Tech note: network taps for AI verification" (https://amodo.substack.com/p/tech-note-network-taps-for-ai-verification), with the byline Thomas Milton and Sam Reynolds.
Original catalogue record ↗S-1309 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
No individual byline on the page.
Original catalogue record ↗S-1311 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
No individual byline on the page.
Original catalogue record ↗S-1600 / Tier A2026 / gov doc
National Institute of Standards and Technology
NIST Computer Security Resource Center · Last accessed by source map: 2026-09-23
Version: Living glossary. Each entry reproduces definitions from named NIST publications; locators in citing records give the term page and the underlying publication (e.g. NISTIR 8320, NIST SP 800-63-4). Entries read on 2026-09-23: roots_of_trust, trusted_execution_environment, attestation, side_channel_attack, tamper_evident, tamper_resistant, threat_modeling, zero_knowledge_proof, verifier, hash_function.
Original catalogue record ↗S-3122 / Tier B2026 / docs
NVIDIA
NVIDIA documentation · Last accessed by source map: 2026-09-25
Version: Document RN-12817-001_v02, dated April 2026; the newest release notes linked from https://docs.nvidia.com/confidential-computing/ on 2026-09-25.
Catalogue note
Vendor release notes; support only "NVIDIA reports" statements. Lists three generally available confidential modes: single-GPU passthrough on Hopper and Blackwell, Hopper multi-GPU passthrough with protected PCIe (NVLink traffic unencrypted), and Blackwell multi-GPU passthrough (encrypted NVLink). Adds HGX B200 and B300 platforms. No multi-node mode is listed.
Original catalogue record ↗S-0064 / Tier C2026 / blog
J. Carlsmith
Joseph Carlsmith · Last accessed by source map: 2026-09-23
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0014 / Tier C2026 / blog
Gloria Z
MIRI Technical Governance Team · Last accessed by source map: 2026-10-08
Catalogue note
Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0), which gives the author as "Zhao". The page itself (read 2026-09-23, dated 2026-06-18) shows the byline "Aaron Scher" and "Gloria Z", and states that the post was conducted as part of the MIRI Technical Governance Fellowship and "authored solely by Gloria", with thanks to Aaron Scher for guidance. The author is therefore recorded as shown on the page.
Original catalogue record ↗S-1707 / Tier B2026 / docs
Intelligence Security Laboratories · Last accessed by source map: 2026-09-25
Catalogue note
Team page. Lists Gabriel Kulp (Executive Director; before founding ISL, a fellow at RAND working on hardware-enabled governance mechanisms for GPU export controls and on international verification of agreements), Tom Gardiner (Staff Director) and Paul Murley (Technical Director; leads the development and infrastructure teams). No page date. Self-description.
Original catalogue record ↗S-1102 / Tier C2026 / blog
Attestable
Attestable blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's own proposal to combine zero-knowledge inference proofs with proof-of-work accounting. No visible byline or date; the year comes from page metadata and should be checked.
Original catalogue record ↗S-0012 / Tier B2026 / preprint
P. Chantasantitam, A. I. Caulfield, V. Duddu, L. J. Gunn, N. Asokan
arXiv · Last accessed by source map: 2026-10-08
Version: arXiv v3 (2026-04-30) read on 2026-09-25; still a preprint, with code "to be released after peer review".
Catalogue note
Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1105 / Tier B2026 / tech report
Pearl Research Team
Pearl Research Labs · Last accessed by source map: 2026-09-25
Version: First page dated September 2026; 22 pages.
Catalogue note
Developer's own specification of its FP8 proof-of-useful-work protocol; supports only "Pearl reports" statements. The Pearl research page lists this PDF as "The Pearl Protocol: A Proof-of-Useful-Work L1".
Original catalogue record ↗S-1106 / Tier B2026 / tech report
Pearl Research Labs
Pearl Research Labs · Last accessed by source map: 2026-09-25
Catalogue note
Developer's original whitepaper for the integer matrix-multiplication mining scheme; supports only "Pearl reports" statements. No explicit publication date; the year is from the page's copyright notice.
Original catalogue record ↗S-3603 / Tier B2026 / docs
Pearl Research Labs · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: infrastructure and algorithms for AI inference.
Original catalogue record ↗S-1107 / Tier B2026 / code
Pearl Research Labs
GitHub · Last accessed by source map: 2026-09-25
Version: Release v1.2.1 (tag v1.2.1, commit e72ad36, 23 July), still the latest release listed on the releases page on 2026-09-25.
Catalogue note
Contains the reference full node, a vLLM-based GPU miner and a Plonky2/STARKy-based proof-of-work circuit and verifier.
Original catalogue record ↗S-3262 / Tier B2026 / docs
PHYSEC GmbH
PHYSEC website · Last accessed by source map: 2026-09-25
Version: Product page, undated; read on 2026-09-25.
Original catalogue record ↗S-1700 / Tier C2026 / blog
Planet Labs PBC
Business Wire (press release) · Last accessed by source map: 2026-09-25
Catalogue note
Company press release for the quarter ended 31 July 2026, also carried on nasdaq.com. It states that in August 2026 Planet signed a renewal with a "hyperscaler AI developer" for global monitoring of data centres and of semiconductor manufacturing facility construction, using its Pelican high-resolution data, and it gives the company's "About Planet" description. Supports "Planet reports" statements only.
Original catalogue record ↗S-3600 / Tier B2026 / docs
Prime Intellect · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: integrated compute, training, inference and sandbox stack.
Original catalogue record ↗S-1506 / Tier B2026 / preprint
S. Abdelghafar, G. Kulp
arXiv · Last accessed by source map: 2026-09-25
Version: v1, the only version on 2026-09-25, read via the arXiv HTML rendering. The HTML fetch ends before the reference list, and the PDF returned HTTP 429, so the bibliography entries were not read.
Catalogue note
Authors affiliated with Rice University (Abdelghafar) and Intelligence Security Laboratories (Kulp).
Original catalogue record ↗S-3125 / Tier B2026 / docs
Apple
Apple Developer · Last accessed by source map: 2026-09-25
Version: Undated page, read on 2026-09-25. The access was announced at WWDC26 in June 2026 ("What's new in the Foundation Models framework", https://developer.apple.com/videos/play/wwdc2026/241/, which names the PrivateCloudComputeLanguageModel API).
Catalogue note
Apple's description of its own developer programme; supports only "Apple reports" statements. Developers enrolled in the App Store Small Business Program, with fewer than 2 million first-time downloads across their apps and the Private Cloud Compute entitlement assigned to their account, can use Apple Foundation Models on PCC in their apps at no cloud API cost. Developers who exceed the threshold must migrate within six months.
Original catalogue record ↗S-3120 / Tier B2026 / docs
Meta
Meta · Last accessed by source map: 2026-09-25
Version: Version 2, updated 2026-03-16; version 1 was published 2025-06-10.
Catalogue note
Meta's description of its own system; supports only "Meta reports" statements. Private Processing runs WhatsApp's AI requests in confidential VMs on AMD EPYC CPUs with SEV-SNP and NVIDIA Hopper GPUs. The client checks the attestation and transparency proofs, including entries in a third-party transparency log run with Cloudflare, before it connects. The threat model lists physical host attacks, with data-centre security, memory encryption and third-party relays as mitigations.
Original catalogue record ↗S-3571 / Tier C2026 / blog
Pearl Research Labs
Pearl Research Labs · Last accessed by source map: 2026-09-25
Catalogue note
Pearl reports end-to-end serving overhead for its integer proof-of-useful-work kernel against stock serving engines: 5.08% for Llama 70B at DP=4 on four H200 GPUs and 3.9% for DeepSeek V3.2 at DP=8 plus expert parallelism on eight H200 GPUs. The page gives no publication date; year follows its copyright notice. Developer report only.
Original catalogue record ↗S-1500 / Tier B2026 / preprint
X. Jin, M. Duan, Q. Lin, A. Chan, Z. Chen, J. Du, X. Ren
arXiv · Last accessed by source map: 2026-10-08
Version: arXiv v1 (2026-03-06) and v2 (2026-06-26), read via the arXiv HTML renderings on 2026-09-23 and 2026-09-25; the abs page did not render for the fetch tool. v2 keeps the figures the records cite (34% average latency overhead, Table 2 per-step overheads of 24.8–38.0%, F1 0.56 on the unsafe class).
Catalogue note
The paper header names the Trustworthy AI for Good (AI4GOOD) workshop at ICML 2026, with the ICML template's "PMLR 306" line; PMLR volume 306 is set aside for the ICML 2026 main conference (github.com/mlresearch/v306), so the paper is recorded as a workshop paper and tier B preprint. Authors are affiliated with Sahara AI and the University of Southern California.
Original catalogue record ↗S-1101 / Tier C2026 / blog
Attestable
Attestable blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's own description of its zero-knowledge inference prover; supports only "Attestable reports" statements. No byline on the page; the date is taken from the Attestable resources listing. No paper, code or docs are linked.
Original catalogue record ↗S-3563 / Tier C2026 / blog
OpenMined Team
OpenMined · Last accessed by source map: 2026-09-25
Catalogue note
OpenMined's account of PySyft and its role in the 2026 evaluations with Google DeepMind, AVERI, MLCommons and Singapore AISI. It describes the 2024 pilot with public stand-ins separately.
Original catalogue record ↗S-3023 / Tier B2026 / docs
Gensyn
Gensyn documentation · Last accessed by source map: 2026-10-08
Version: Page as viewed on 2026-10-08, giving v0.8.0 as the current release (no release date shown).
Catalogue note
Developer's documentation of its own runtime. Describes three modes: default (standard PyTorch kernels, no determinism guarantee), deterministic (PyTorch deterministic algorithms, reproducible on the same hardware) and reproducible (RepOp kernels, bitwise-identical across supported hardware). Lists reproducible int8 attention, fused gathered-log-probability and MoE expert GEMM kernels; warns that earlier receipts may not re-verify with v0.8.0; states that REE as a whole is not open source. Supports only "Gensyn reports" statements.
Original catalogue record ↗S-3362 / Tier C2026 / blog
D. McCann-Sayles, S. Servan-Schreiber, T. Verma
Tinfoil blog · Last accessed by source map: 2026-09-25
Catalogue note
Tinfoil's description of its own safeguard pipeline: safeguard models that "run exclusively inside secure enclaves" and output only a flag, with the pipeline code public and its enforcement "verifiable through attestation". Updated 16 September 2026. The post does not say explicitly which safeguard components are in the attested measurement. Supports only "Tinfoil reports" statements.
Original catalogue record ↗S-1006 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
No individual byline. Describes the authors' own prototype; performance statements are provider-reported.
Original catalogue record ↗S-3128 / Tier B2026 / docs
AMD
AMD product security bulletin · Last accessed by source map: 2026-10-08
Version: Initial publication 2026-04-14; read in the revision of 2026-09-24.
Catalogue note
AMD's own bulletin on CVE-2025-54510 (Fabricked, S-3127); supports only "AMD reports" statements. Credits Schlüter, Wech and Shinde of ETH Zurich. Rates the issue CVSS 5.9 (medium). Lists platform-initialisation firmware updates for EPYC 7003, 8004, 9004 and 9005 server series released 2025-11-26 to 2025-12-15, and for the embedded series to 2026-04-13.
Original catalogue record ↗S-3606 / Tier B2026 / docs
Singapore AI Safety Hub · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: research and field-building organisation rooted in Singapore.
Original catalogue record ↗S-1405 / Tier B2026 / docs
sovcert.org · Last accessed by source map: 2026-09-23
Catalogue note
Working-group website; content copyright 2025-2026, no page date. Content as read on 2026-09-23; the site could not be reached on 2026-09-25 (connection error). Self-description of the initiative, so it supports "the working group states" statements only. The live site failed again on 2026-10-07 (TLS error). The archived copy of 17 May 2026, read on 2026-10-07, has the same self-description and a timeline ending with the final version presented in January 2026.
Original catalogue record ↗S-3123 / Tier A2026 / peer reviewed
R. Zhang, T. Hornetz, D. Weber, F. Thomas, M. Schwarz
35th USENIX Security Symposium (USENIX Security '26) · Last accessed by source map: 2026-10-08
Version: USENIX Security '26 presentation page (pp. 5691–5709, August 2026). Also read the authors' site (https://stackwarpattack.com/) and paper PDF (https://stackwarpattack.com/stackwarp_usenix26.pdf) on 2026-09-25.
Catalogue note
Independent attack paper (CISPA Helmholtz Center for Information Security). A malicious hypervisor toggles an undocumented MSR bit on a sibling hyperthread to shift an SEV-SNP guest's stack pointer, breaking the guest's integrity; demonstrated on AMD Zen 1 to Zen 5 with simultaneous multithreading enabled, including OpenSSH authentication bypass, sudo privilege escalation and RSA key recovery. CVE-2025-29943; AMD released hot-loadable microcode patches (bulletin AMD-SB-3027), and disabling SMT is an interim mitigation. Proof-of-concept code at https://github.com/cispa/StackWarp.
Original catalogue record ↗S-3380 / Tier C2026 / blog
Machine Intelligence Research Institute
Machine Intelligence Research Institute · Last accessed by source map: 2026-09-25
Catalogue note
MIRI post summarising six papers by its Technical Governance Team (TGT) at the second Workshop on Technical AI Governance Research (TAIGR) at ICML 2026, including S-0020 (marked as the best-paper award winner), S-0037, S-0060 and S-1300. The date is taken from the URL; the page as fetched showed no byline. Self-description; supports "MIRI reports" statements.
Original catalogue record ↗S-0038 / Tier C2026 / blog
N. Cankaya
MIRI Technical Governance Team · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3500 / Tier A2026 / peer reviewed
J. Yao, H. Su, T. Liao, Z. Cheng, H. Zhang, X. Wang, P. Viswanath
Proceedings of the 21st European Conference on Computer Systems (EuroSys 2026), pp. 1515-1532 · Last accessed by source map: 2026-09-25
Version: Full text read from arXiv HTML v4 (6 Jun 2026; v1 15 Oct 2025). Venue, pages and DOI are from the arXiv journal reference. The ACM DOI page could not be read by the fetch tool (HTTP 403).
Catalogue note
Yao, Cheng and Viswanath are at Princeton University, Su and Wang at HKUST (Guangzhou), Liao and Zhang at the University of Illinois Urbana-Champaign. TAO accepts operator-level outputs within bounds that combine IEEE-754 worst-case error bounds with empirical percentile profiles, instead of requiring bitwise equality, and keeps hardware heterogeneity. Disputes are settled by a Merkle-anchored, threshold-guided dispute game whose coordinator is a smart-contract deployment on the Ethereum Holesky testnet. Evaluated on RTX 4090, A100, H100 and RTX 6000 GPUs; reports 0.3% overhead on Qwen3-8B.
Original catalogue record ↗S-1202 / Tier A2026 / peer reviewed
J. Chuang, A. Seto, N. Berrios, S. van Schaik, C. Garman, D. Genkin
2026 IEEE Symposium on Security and Privacy (SP) · Last accessed by source map: 2026-10-08
Version: Read the authors' site and the paper PDF linked from it (https://tee.fail/files/paper.pdf) on 2026-09-23.
Catalogue note
Independent attack paper. Venue confirmed on 2026-09-23: the authors' site lists the 47th IEEE Symposium on Security and Privacy (IEEE S&P '26), co-author C. Garman's publication list gives IEEE Symposium on Security and Privacy (SP) 2026, and the IEEE Computer Society Digital Library lists it among the SP 2026 proceedings articles (https://www.computer.org/csdl/proceedings-article/sp/2026/606500b876/2bojwtctN28; page content not machine-readable, so no DOI is recorded). The site (re-read 2026-09-25) links an Intel security announcement of 2025-10-28 and AMD bulletin AMD-SB-3040; it states that both vendors treat interposer attacks as out of scope and that there are no mitigations on the NVIDIA side. Cited by S-0012 (as TEE.fail) and discussed in S-0014 and the Tinfoil documentation.
Original catalogue record ↗S-2006 / Tier A2026 / gov doc
CTBTO Preparatory Commission
CTBTO · Last accessed by source map: 2026-09-25
Catalogue note
The page is undated; the year is the year it was read.
Original catalogue record ↗S-0031 / Tier C2026 / blog
N. Cankaya
The Datacenter Lie Detector · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0). The post's byline names N. Cankaya only; A. Friedman and M. Baker are thanked for "substantial contributions" (checked 2026-09-23).
Original catalogue record ↗S-2005 / Tier A2026 / gov doc
CTBTO Preparatory Commission
CTBTO · Last accessed by source map: 2026-09-25
Catalogue note
The page is undated; the year is the year it was read.
Original catalogue record ↗S-1313 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Catalogue note
No individual byline on the page.
Original catalogue record ↗S-0071 / Tier B2026 / preprint
A. Basu
arXiv · Last accessed by source map: 2026-09-25
Version: Read arXiv HTML v2 (5 June 2026), which describes itself as under review; v1 was read on 2026-09-23. The arXiv abstract page could not be rendered by the fetch tool.
Catalogue note
Independent measurement study of Pearl's mainnet; the author (NIELIT New Delhi; IIIT Allahabad) is not affiliated with Pearl Research Labs.
Original catalogue record ↗S-3562 / Tier B2026 / docs
Thinking Machines Lab · Last accessed by source map: 2026-09-25
Catalogue note
Company homepage, read 2026-09-25. States: "Thinking Machines Lab is an artificial intelligence research and product company." Lists its models, the Tinker platform and its research blog, Connectionism. Supports "Thinking Machines reports" statements only.
Original catalogue record ↗S-0033 / Tier B2026 / preprint
S. K. Monfared, F. Ganji, D. E. Holcomb, S. Tajik
arXiv · Last accessed by source map: 2026-09-25
Version: v2 (2026-02-12) read on 2026-09-25; no later version or peer-reviewed publication found.
Catalogue note
Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3605 / Tier B2026 / docs
Tinfoil · Last accessed by source map: 2026-09-25
Catalogue note
Official organization page, read 2026-09-25; the year is the access year because the page is undated. Supports the organization's attributed self-description: AI models running inside secure hardware enclaves.
Original catalogue record ↗S-1409 / Tier B2026 / tech report
C. Krawec
Federation of American Scientists · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-1301 / Tier C2026 / blog
Lucid Computing
Lucid Computing (Substack) · Last accessed by source map: 2026-09-25
Catalogue note
Design brief; the post states the design is not yet implemented or red-teamed.
Original catalogue record ↗S-0048 / Tier C2026 / blog
Amodo Design
Amodo Design · Last accessed by source map: 2026-09-25
Version: The URL imported from the Hodgkins bibliography (https://amododesign.com/data-center-power-delivery/) redirects to the notes page above, which was read on 2026-09-23. The page credits "Amodo Design" and names no individual authors; the bibliography's list of three individual authors could not be confirmed on the page.
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1803 / Tier A2026 / peer reviewed
Y. Dittmar, M. J. Stephan, T. Völkl, M. Hollick, J. Classen
Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '26) · Last accessed by source map: 2026-09-25
Version: Read the arXiv HTML v1 (22 May 2026), whose ACM reference format names WiSec '26 (30 June–3 July 2026, Saarbrücken) and prints the DOI above (doi.org returned 403 to the fetch tool, so the DOI was not resolved). Authors at the Hasso Plattner Institute, TU Darmstadt and IMDEA Networks; none at Apple.
Catalogue note
Independent analysis that reverse-engineers PCC's client on macOS 15.5 and iOS 26.2 and queries the production service. Reports that there are no reproducible builds or symbols, request-token handling that departs from Apple's documentation (reusable one-time tokens, skipped signature validation, linkable salts), disclosure to Apple, and that Apple only clarified its documentation. It does not test attestation.
Original catalogue record ↗S-0091 / Tier B2026 / docs
Verifiable Compute Foundation · Last accessed by source map: 2026-10-08
Catalogue note
The foundation's public homepage describes its nonprofit mission and free Bay Area research cluster, operated by Lucid Computing. It reports two H100 nodes operational in a beta launch, with H200, B300 and MI355X hardware scheduled, and lists research access and physical instrumentation. Operational and availability statements are provider-reported. Read from the public HTML's bundled document.
Original catalogue record ↗S-0026 / Tier B2026 / preprint
D. Reuter, L. Marks, A. Carlucci, J. Ng, J. Petrie, J. Hausenloy, A. Karvonen, M. Baker
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-23
Version: Author list and abstract verified on the official ICML 2026 TAIGR workshop poster page on 2026-09-25. The OpenReview full text was inaccessible; only abstract-level claims are used.
Catalogue note
Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1704 / Tier B2026 / tech report
A. Ilhan, C. Withers, H. Gietz, B. Harack
Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-10-08
Version: Research paper dated April 2026. The landing page and the abstract and author block of the PDF (https://aigi.ox.ac.uk/wp-content/uploads/2026/04/Verifiable-Semiconductor-Manufacturing.pdf) were read; the body was not reviewed.
Catalogue note
Affiliations as printed: A. Ilhan (ERA Cambridge; Oxford Hardware AI Governance Lab), C. Withers (Center for a New American Security), H. Gietz (ERA Cambridge), B. Harack (Oxford Martin AI Governance Initiative; Oxford Hardware AI Governance Lab). Listed among the Hardware AI Governance Lab's publications (S-1703).
Original catalogue record ↗S-1501 / Tier B2026 / code
SaharaLabsAI
GitHub · Last accessed by source map: 2026-09-25
Version: main branch as viewed on 2026-09-23, README read via raw.githubusercontent.com. No release tag exists; the main branch head at that time was commit 77a4fdbcf9f7ff196bf577bd42b8817472729126 (from git ls-remote). README re-read on 2026-09-25; the repository page still showed 28 commits and no releases, and the commit list could not be read (robots.txt).
Catalogue note
Code release linked from S-1500. The README describes it as a proof of concept that is not production-ready.
Original catalogue record ↗S-0067 / Tier C2026 / blog
R. Dean
AI 2040 · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0019 / Tier B2026 / preprint
J. Petrie, Y. Mühlhäuser
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25
Version: OpenReview returned a browser check on 2026-09-23 and 2026-09-25, so only the title, authors and abstract were read, on the workshop's ICML 2026 virtual page (https://icml.cc/virtual/2026/78565). No arXiv version found as of 2026-09-25.
Catalogue note
Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1512 / Tier C2026 / blog
T. Milton, S. Reynolds, C. Jacobi, J. Foster
Amodo (Substack) · Last accessed by source map: 2026-09-25
Catalogue note
Byline shown as "Amodo, Thomas Milton, Sam Reynolds, and 2 others"; the post names Connagh Jacobi and Joel Foster as the other contributors. A search-engine listing gave a slightly longer title that includes "AI 2040"; the title here is the post's H1 as fetched.
Original catalogue record ↗S-3080 / Tier A2026 / peer reviewed
G. Liao, T. Wang, S. Zhang, J. Zhang, L. Shi, D. Tao
NDSS Symposium 2026 · Last accessed by source map: 2026-10-08
Version: Published at the NDSS Symposium 2026; the paper page, read on 2026-10-07, gives the title, authors and affiliations and shows no DOI. Preprint arXiv 2508.21393 (DOI 10.48550/arXiv.2508.21393), first posted 29 August 2025; arXiv v3 dated 2 December 2025. The abstract and HTML, read on 2026-09-25, use the title VeriLoRA and state that the paper was accepted for publication at NDSS 2026.
Catalogue note
Proves one LoRA fine-tuning iteration (forward pass, backward pass, parameter update) on a single-sample minibatch for LLaMA-3.2 3B and 11B, LLaMA-2 7B and 13B and OPT 6.7B and 13B on one NVIDIA A100 80 GB GPU. The full text read reports 121.93–249.38 s of proving, 156–554 s of commitment generation and 1.87–3.73 s of verification per step. Code linked from the paper at https://github.com/liaoguofu/zkLoRA (MIT licence, README titled VeriLoRA, built on the zkLLM code base); commit not pinned.
Original catalogue record ↗S-0075 / Tier B2026 / docs
Gensyn
Delphi documentation · Last accessed by source map: 2026-10-08
Version: Documentation as viewed on 2026-10-08; no publication date is given.
Catalogue note
Developer's documentation of its information-market service. States that Delphi runs on Gensyn mainnet and that an open-source judge model runs inside REE to settle markets. Describes receipts that record the model, inputs, output and a cryptographic hash, letting anyone re-run the computation. This supports receipt re-execution, not a documented application of Verde's dispute protocol. Supports only "Gensyn reports" statements.
Original catalogue record ↗S-3121 / Tier C2026 / blog
Trail of Bits
Trail of Bits blog · Last accessed by source map: 2026-10-08
Catalogue note
The auditors' own summary of their pre-launch security review of WhatsApp Private Processing (AMD SEV-SNP with NVIDIA confidential GPUs); the post does not say who commissioned it. Reports 28 issues, eight of high severity, and describes environment variables and ACPI tables loaded outside the attestation measurement, patch levels trusted without checking AMD's certificates, and attestations with no freshness guarantee. Meta resolved 16 issues and partly addressed four before launch; the remaining eight are low or informational. States that the SEV-SNP threat model does not fully protect against advanced physical attacks, so Meta added controls on which CPUs are trusted (TOB-WAPI-10). The full report (https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf, dated August 2025) could not be read by the fetch tool on 2026-09-25; finding severities come from the library entry, S-3124.
Original catalogue record ↗S-1412 / Tier B2026 / preprint
S. Gargiulo, G. Kulp
arXiv · Last accessed by source map: 2026-09-25
Version: v1 (2026-08-31), the version shown on 2026-09-25. Read via the arXiv HTML rendering (arxiv.org/html/2609.00309); the abstract page returned no extractable text to the fetch tool. The paper states that the recordings are released as a Hugging Face dataset; the dataset page returned HTTP 401 on 2026-09-23 and 2026-09-25. Affiliations as shown: S. Gargiulo (Pivotal Research), G. Kulp (Intelligence Security Laboratories).
Original catalogue record ↗S-0025 / Tier B2026 / preprint
P. Peigné, K. Nguyen, P. Wang
arXiv · Last accessed by source map: 2026-09-25
Version: v2 (22 August 2026) read; v1 was posted on 3 June 2026.
Catalogue note
Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1806 / Tier B2026 / code
Zkonduit Inc.
GitHub · Last accessed by source map: 2026-09-25
Version: Main branch as viewed on 2026-09-25 (860 commits); the releases page lists v23.0.5 as the latest release. The root listing showed no licence file; the README carries a no-warranty notice and a contributor licence agreement.
Catalogue note
Developer's own repository; supports "Zkonduit reports" statements about the tool. README: ezkl proves inference of ONNX models with halo2, supports public or private models and data, notes that quantization can make outputs differ slightly from Python, and links the Trail of Bits audit (S-0070).
Original catalogue record ↗S-1814 / Tier C2025 / forum
vLLM project contributors
GitHub (vllm-project/vllm issues) · Last accessed by source map: 2026-09-25
Catalogue note
vLLM developers' tracking issue for batch invariance. Its body states "We have basically support Batch Invariant based on" the Thinking Machines post (S-1009), and lists open work such as performance, NVFP4, AMD testing and speculative decoding. Still open on 2026-09-25.
Original catalogue record ↗S-3221 / Tier C2025 / blog
Anthropic
Anthropic · Last accessed by source map: 2026-09-25
Catalogue note
Developer's announcement of its own security measures. Describes egress bandwidth controls that limit the rate of outbound network traffic from environments holding model weights. Supports "Anthropic reports" statements only.
Original catalogue record ↗S-1005 / Tier B2025 / code
A. Karvonen
GitHub · Last accessed by source map: 2026-09-25
Version: Pinned to commit eecde35 (eecde35f6458d76af86d68afac00594237162cf2, 8 Dec 2025), the head of the main branch per the GitHub API on 2026-09-23; the branch showed 21 commits and no release tags. Unchanged (21 commits, no tags) on 2026-09-25.
Original catalogue record ↗S-0008 / Tier C2025 / forum
AI Security Forum
AI Security Forum · Last accessed by source map: 2026-09-23
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0063 / Tier B2025 / tech report
A. Scher, D. Abecassis, P. Barnett, B. Abeyta
Machine Intelligence Research Institute · Last accessed by source map: 2026-09-25
Version: v3 (2026-05-08) read on 2026-09-25; the Strict and Monitored Thresholds are in §4.
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3261 / Tier A2025 / peer reviewed
M. S. Tabar, J. Kortz, P. Staat, H. Elders-Boll, C. Paar, C. Zenger
18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025) · Last accessed by source map: 2026-10-08
Version: Read via the arXiv HTML (v1) and PDF; the ACM DOI page returned HTTP 403. Venue and author order from the dblp record (conf/wisec/TabarKSEPZ25) and P. Staat's publication list.
Original catalogue record ↗S-3541 / Tier B2025 / preprint
W. Cai, T. Shi, X. Zhao, D. Song
arXiv · Last accessed by source map: 2026-09-25
Version: arXiv v2 (29 September 2025); v1 was posted on 7 April 2025. An OpenReview forum exists (https://openreview.net/forum?id=3DZeEUTwhq) but could not be read by the fetch tool, so no venue or decision is recorded.
Original catalogue record ↗S-0009 / Tier B2025 / preprint
C. Schnabl, D. Hugenroth, B. Marino, A. R. Beresford
ICML 2025 Workshop on Technical AI Governance · Last accessed by source map: 2026-10-08
Version: arXiv v1 (2025-06-30) read on 2026-09-23 and 2026-09-25; no later version or archival publication found. The arXiv comment reads "ICML 2024 Workshop TAIG", and the PDF and HTML carry the ICML 2025 template header ("Proceedings of the 42nd International Conference on Machine Learning ... PMLR 267"). The ICML 2025 virtual site (https://icml.cc/virtual/2025/48334) lists it as a workshop poster at the Workshop on Technical AI Governance, and it was not found in the PMLR 267 volume, so it is recorded as a workshop paper, not a main-conference publication.
Catalogue note
Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0043 / Tier A2025 / peer reviewed
P. Horvath, L. Chmielewski, L. Weissbart, L. Batina, Y. Yarom
34th USENIX Security Symposium · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1611 / Tier B2025 / blog
S. Nassernia
NVIDIA Technical Blog · Last accessed by source map: 2026-09-25
Catalogue note
NVIDIA technical blog post about MLOPart partitioning in CUDA 13.1; supports only "NVIDIA states" statements about its own hardware. Cited for its statement that the Blackwell GPUs in an NVIDIA HGX B200 system "normally have 148 SMs".
Original catalogue record ↗S-3544 / Tier A2025 / gov doc
California State Legislature
Statutes of 2025, Chapter 138 (Business and Professions Code §22757.10 et seq.) · Last accessed by source map: 2026-09-25
Version: Chaptered text, approved by the Governor and filed with the Secretary of State on 29 September 2025. The official page (https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53) disallows the fetch tool, so the chaptered text was read on LegiScan. §22757.11(i) defines a frontier model by training compute greater than 10^26 integer or floating-point operations, including later fine-tuning, reinforcement learning or other material modifications; §22757.12 sets the frontier AI framework and transparency-report duties.
Original catalogue record ↗S-1817 / Tier C2025 / blog
Anthropic, Pattern Labs
Anthropic research · Last accessed by source map: 2026-09-25
Catalogue note
Published in collaboration with Pattern Labs, with a companion report ("Confidential Inference Systems: Design principles and security risks", June 2025). Sketches a small, attested model loader and invoker that decrypts data only inside a trusted environment and passes it to the accelerator, for protecting model weights and user data; states the work is early. Developer's description of its own research; supports "Anthropic reports" statements.
Original catalogue record ↗S-3382 / Tier B2025 / tech report
E. Grunewald, T. Fist
Center for a New American Security (working paper) · Last accessed by source map: 2026-09-25
Catalogue note
CNAS working paper. Affiliations as shown on the CNAS page: E. Grunewald (Institute for AI Policy and Strategy), T. Fist (CNAS). Estimates AI chip smuggling to the PRC in 2024 at 10,000 to several hundred thousand chips, median about 140,000, and recommends software-based location verification and a notification requirement for exports, re-exports and ownership transfers of controlled AI chips.
Original catalogue record ↗S-1807 / Tier C2025 / blog
Lagrange Labs
Lagrange blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's announcement of a zero-knowledge proof of full GPT-2 inference, with GGUF model import, sumcheck techniques and a Basefold commitment that the post says produces large proofs and slow verification. Gives no timings. Supports only "Lagrange reports" statements.
Original catalogue record ↗S-1009 / Tier C2025 / blog
H. He, Thinking Machines Lab
Thinking Machines Lab: Connectionism · Last accessed by source map: 2026-09-25
Catalogue note
Byline reads "Horace He in collaboration with others at Thinking Machines". Code is published at github.com/thinking-machines-lab/batch_invariant_ops (S-1813).
Original catalogue record ↗S-0039 / Tier B2025 / preprint
Z. Chen, S. Chien, P. Qian, N. Zilberman
arXiv · Last accessed by source map: 2026-09-23
Version: Title and author order follow the arXiv listing (abstract-page title, also used on the Oxford Computing Infrastructure Group publications page). The paper's own header in the arXiv HTML (v1 and v2) and PDF reads "Detecting Anomalies in Systems for AI Using Hardware Telemetry", with authors in the order Z. Chen, P. Qian, S. W. D. Chien, N. Zilberman, all University of Oxford; the system is named Reveal. Checked 2026-09-23.
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0016 / Tier B2025 / preprint
A. Karvonen, D. Reuter, R. Rinberg, L. Marks, A. Garriga-Alonso, K. Warr
ICML 2026 Workshop on Technical AI Governance Research · Last accessed by source map: 2026-09-25
Version: arXiv v1 (25 Nov 2025) is the only version as of 2026-09-25. The paper was a poster at the Second Workshop on Technical AI Governance Research at ICML 2026 (https://icml.cc/virtual/2026/78608). Checked 2026-09-25.
Catalogue note
Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3021 / Tier C2025 / blog
EigenCloud
Eigen Labs blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's launch announcement (the blog.eigencloud.xyz address redirects here). States that EigenAI and EigenCompute launched "on mainnet alpha", that the backing stake "is not exposed to slashing risk yet during the alpha phase", that code will be open-sourced so users can verify responses, and that the API first serves gpt-oss-120b-f16. Supports only "Eigen Labs reports" statements.
Original catalogue record ↗S-3160 / Tier B2025 / preprint
J. Petrie
arXiv · Last accessed by source map: 2026-09-25
Version: v1 (2025-09-09), the only version, read on 2026-09-25.
Catalogue note
Design for thousands of redundant on-chip security blocks that each block essential accelerator operations unless they hold a recent, signed authorization. The paper gives gate-count and area estimates and reports no built or measured hardware. A proof-of-concept repository by the same author is S-3161.
Original catalogue record ↗S-3240 / Tier A2025 / peer reviewed
R. Gil-Pons, S. Mauw, R. Trujillo-Rasua
Proceedings of the 22nd International Conference on Security and Cryptography (SECRYPT 2025), pp. 209–220 · Last accessed by source map: 2026-09-25
Version: Read the SciTePress PDF and the arXiv HTML preprint (arXiv 2509.10224); venue, pages and DOI checked against Crossref on 2026-09-25.
Catalogue note
Code at gitlab.com/uniluxembourg/fstm/dcs/satoss/memory-erasure-experiments, per the paper.
Original catalogue record ↗S-0069 / Tier A2025 / gov doc
Executive Office of the President
Federal Register, 90 FR 8237 (document 2025-01901, published 2025-01-28) · Last accessed by source map: 2026-09-23
Version: Signed 2025-01-20. Section 2(ggg) lists Executive Order 14110 of October 30, 2023 (Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence) among the orders revoked.
Original catalogue record ↗S-3561 / Tier B2025 / docs
Zkonduit Inc.
EZKL documentation · Last accessed by source map: 2026-09-25
Catalogue note
Developer's documentation home, read 2026-09-25. Describes EZKL as "a developer-friendly system for verifiable AI and analytics" and carries the notice "© Copyright Zkonduit Inc. 2025". Zkonduit's GitHub organization (github.com/zkonduit) describes itself as "Making ezkl". Supports "Zkonduit reports" statements only.
Original catalogue record ↗S-0066 / Tier C2025 / blog
N. Ammann, D. Dalrymple
Institute for Progress · Last accessed by source map: 2026-09-23
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0035 / Tier B2025 / preprint
J. Petrie, O. Aarne, N. Ammann, D. Dalrymple
arXiv · Last accessed by source map: 2026-09-25
Version: v1 (2025-06-18), still the only version and with no journal reference, read on 2026-09-25.
Catalogue note
Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0034 / Tier B2025 / preprint
J. Petrie
ICML 2025 Workshop on Technical AI Governance · Last accessed by source map: 2026-09-25
Version: Workshop poster. Read via the ICML 2025 virtual-site abstract (https://icml.cc/virtual/2025/48329) on 2026-09-23 and 2026-09-25; the OpenReview page and PDF could not be read.
Catalogue note
Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0010 / Tier A2025 / peer reviewed
A. Dhar, C. Thorens, L. M. Lazier, L. Cavigelli
2025 IEEE Symposium on Security and Privacy · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Trusted execution and attestation" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3543 / Tier A2025 / gov doc
European Commission
European Commission, Communication C(2025) 5045 final · Last accessed by source map: 2026-09-25
Version: The landing page gives the publication date and the entry into application on 2 August 2025. The text (§2.3.1 on the 10^25 FLOP presumption, §2.3.2 on notification within two weeks) was read in the annex PDF on the AI Act Service Desk.
Original catalogue record ↗S-0006 / Tier B2025 / preprint
A. O'Gara, G. Kulp, W. Hodgkins, J. Petrie, V. Immler, A. Aysu, K. Basu, S. Bhasin, S. Picek, A. Srivastava
arXiv · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1502 / Tier B2025 / preprint
R. Levin, V. Cherepanova, A. Hans, A. Schwarzschild, T. Goldstein
arXiv · Last accessed by source map: 2026-09-25
Version: Abstract read on the arXiv abs page; method and setup read via the v1 HTML rendering. Only v1 exists on arXiv (checked 2026-09-25). ML Anthology lists the paper under the ICLR 2025 BuildingTrust workshop (https://mlanthology.org/iclrw/2025/levin2025iclrw-my/); a workshop paper, so tier B is kept.
Original catalogue record ↗S-1003 / Tier B2025 / tech report
Prime Intellect Team, S. Jaghouar, J. Mattern, J. M. Ong, J. Straube, M. Basra, A. Pazdera, K. Thaman, M. Di Ferrante, F. Gabriel, F. Obeid, K. Erdem, M. Keiblinger, J. Hagemann
arXiv · Last accessed by source map: 2026-09-25
Version: Read arXiv v1 (HTML), section 2.3 on TOPLOC and section 2.4 on validation.
Catalogue note
Developer's report on its own training run; TOPLOC statements are provider-reported.
Original catalogue record ↗S-0054 / Tier B2025 / tech report
Y. Bengio, S. Mindermann, D. Privitera, T. Besiroglu, R. Bommasani, S. Casper, Y. Choi, P. Fox, B. Garfinkel, D. Goldfarb, H. Heidari, A. Ho, S. Kapoor, L. Khalatbari, S. Longpre, S. Manning, V. Mavroudis, M. Mazeika, J. Michael, J. Newman, K. Y. Ng, C. T. Okolo, D. Raji, G. Sastry, E. Seger, T. Skeadas, T. South, E. Strubell, F. Tramèr, L. Velasco, N. Wheeler, D. Acemoglu, O. Adekanmbi, D. Dalrymple, T. G. Dietterich, E. W. Felten, P. Fung, P.-O. Gourinchas, F. Heintz, G. Hinton, N. Jennings, A. Krause, S. Leavy, P. Liang, T. Ludermir, V. Marda, H. Margetts, J. McDermid, J. Munga, A. Narayanan, A. Nelson, C. Neppel, A. Oh, G. Ramchurn, S. Russell, M. Schaake, B. Schölkopf, D. Song, A. Soto, L. Tiedrich, G. Varoquaux, A. Yao, Y.-Q. Zhang, F. Albalawi, M. Alserkal, O. Ajala, G. Avrin, C. Busch, A. C. P. de Leon Ferreira de Carvalho, B. Fox, A. S. Gill, A. H. Hatip, J. Heikkilä, G. Jolly, Z. Katzir, H. Kitano, A. Krüger, C. Johnson, S. M. Khan, K. M. Lee, D. V. Ligot, O. Molchanovskyi, A. Monti, N. Mwamanzi, M. Nemer, N. Oliver, J. R. López Portillo, B. Ravindran, R. Pezoa Rivera, H. Riza, C. Rugege, C. Seoighe, J. Sheehan, H. Sheikh, D. Wong, Y. Zeng
International AI Safety Report · Last accessed by source map: 2026-09-23
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1205 / Tier B2025 / preprint
O. Aarne, J. Petrie
arXiv · Last accessed by source map: 2026-09-25
Version: v1 (2025-06-18), still the only version and with no journal reference, read on 2026-09-25.
Catalogue note
The report calls itself the third and final part of the flexHEG series commissioned by ARIA. The arXiv abstract page does not state the series number.
Original catalogue record ↗S-1811 / Tier C2025 / blog
Gensyn
Gensyn news · Last accessed by source map: 2026-09-25
Catalogue note
Developer's announcement of Judge, an AI evaluation service built on Verde and Gensyn's Reproducible Runtime, showcased with a reasoning task framed as a prediction market. Supports only "Gensyn reports" statements.
Original catalogue record ↗S-1411 / Tier C2025 / blog
Epoch AI
Epoch AI · Last accessed by source map: 2026-09-25
Catalogue note
Announcement of Epoch AI's public dataset of large AI data centres, launched as the Frontier Data Centers Hub. Epoch now calls it the AI data centers hub, at epoch.ai/data/ai-data-centers (checked 2026-10-07).
Original catalogue record ↗S-3161 / Tier B2025 / code
J. Petrie
GitHub · Last accessed by source map: 2026-09-25
Version: Pinned to commit 4911839c11d95496255df626f59bdae973713e9d (head of main on 2026-09-25, committed 2026-09-17; first commit 2025-11-10; 131 commits, no releases or tags), obtained through the GitHub API. The README was read at that commit via raw.githubusercontent.com.
Catalogue note
SystemVerilog proof of concept of the security block in S-3160, with Verilator testbenches. Per its README, it gates an example Int8 adder, supports ECDSA (secp256k1) or HSS/LMS signatures, and omits production features including constant-time field arithmetic, a configurable public key and redundant blocks. The repository also has a pynq-z2 folder with an FPGA build script and a Python client; the README reports no FPGA results.
Original catalogue record ↗S-1401 / Tier B2025 / tech report
A. Brass
Institute for AI Policy and Strategy · Last accessed by source map: 2026-09-25
Catalogue note
Two-page IAPS issue brief. The document says "Issue brief written May 2025, full 2024 report by Asher Brass & Onni Aarne"; the IAPS page that presents the brief (iaps.ai/research/location-verification-for-ai-chips) reads "Written By Asher Brass" and is dated May 16 (2025). It reports an H100 prototype with a video demonstration at ping-location.info. The site's technical details are separately recorded in S-3570.
Original catalogue record ↗S-0005 / Tier B2025 / preprint
A. Scher, L. Thiergart
arXiv · Last accessed by source map: 2026-10-08
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3124 / Tier B2025 / docs
Trail of Bits
Trail of Bits publications library · Last accessed by source map: 2026-10-08
Version: Library entry for the review dated August 2025. The full report (https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf) could not be read by the fetch tool on 2026-09-25; the library entry gives the finding titles and severities.
Catalogue note
Independent auditors' summary of their review of WhatsApp Private Processing. Lists 28 issues (8 high, 4 medium, 4 low, 12 informational). The eight high-severity findings include attestation without freshness, the SEV-SNP TCB version not checked against the VCEK certificate, SEV-SNP attestation not bound to Meta-specific machines, CVMs compromised through environment-variable injection, ACPI SSDT injection by a malicious hypervisor, CVM images that cannot be reproduced, and GPU-hosted models that do not verify NVIDIA GPU attestation. The client is not named on the page.
Original catalogue record ↗S-3540 / Tier A2025 / peer reviewed
I. Gao, P. Liang, C. Guestrin
International Conference on Learning Representations (ICLR 2025) · Last accessed by source map: 2026-09-25
Version: arXiv v2 (8 April 2025), marked as the ICLR 2025 camera-ready version; v1 was posted on 26 October 2024. The ICLR 2025 publication was confirmed through the conference's slides page and the ML Anthology entry; the OpenReview forum (https://openreview.net/forum?id=QCDdI7X3f9) was not readable by the fetch tool.
Original catalogue record ↗S-0045 / Tier A2025 / peer reviewed
R. Ding, T. Xu, X. Shen, A. A. Ding, Y. Fei
2025 ACM SIGSAC Conference on Computer and Communications Security (CCS 2025) · Last accessed by source map: 2026-09-23
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3162 / Tier B2025 / blog
D. Reber Jr.
NVIDIA Blog · Last accessed by source map: 2026-09-25
Catalogue note
NVIDIA blog post by David Reber Jr. stating the company's position (the page gives no job title); supports only "NVIDIA states" statements. It states that NVIDIA GPUs "do not and should not have kill switches and backdoors", and distinguishes optional software features controlled by the user from a kill switch hardwired into a chip.
Original catalogue record ↗S-1200 / Tier B2025 / docs
NVIDIA
NVIDIA documentation · Last accessed by source map: 2026-09-25
Version: Document WP-12554-001_v1.3, dated 2025-08-14, as read on 2026-09-23 and 2026-09-25 (still the version linked on 2026-09-25). Linked from https://docs.nvidia.com/confidential-computing/.
Catalogue note
Vendor documentation about NVIDIA's own confidential-computing feature; supports only "NVIDIA reports" statements. Covers the CPU-TEE pairing, device identity and root of trust, SPDM session, bounce buffers, TDISP/IDE, multi-GPU modes, the in-scope and out-of-scope threat lists (pp. 14-15) and performance counters in CC mode (p. 18).
Original catalogue record ↗S-0001 / Tier A2025 / peer reviewed
A. Reuel, B. Bucknall, S. Casper, T. Fist, L. Soder, O. Aarne, L. Hammond, L. Ibrahim, A. Chan, P. Wills, M. Anderljung, B. Garfinkel, L. Heim, A. Trask, G. Mukobi, R. Schaeffer, M. Baker, S. Hooker, I. Solaiman, A. S. Luccioni, N. Rajkumar, N. Moës, J. Ladish, D. Bau, P.-A. Bricman, N. Guha, J. Newman, Y. Bengio, T. South, A. Pentland, S. Koyejo, M. J. Kochenderfer, R. Trager
Transactions on Machine Learning Research · Last accessed by source map: 2026-09-23
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1413 / Tier B2025 / blog
NVIDIA
NVIDIA Blog · Last accessed by source map: 2026-09-25
Catalogue note
NVIDIA's announcement of its own fleet-management service (byline: NVIDIA Newsroom); supports only "NVIDIA states" or "NVIDIA reports" statements. Describes an opt-in, customer-installed service that streams read-only GPU telemetry to an NVIDIA portal, with a client agent slated to be open-sourced, and states that NVIDIA GPUs do not have hardware tracking technology, kill switches and backdoors. It does not describe location verification.
Original catalogue record ↗S-3570 / Tier B2025 / docs
Ulyssean
Ulyssean demonstration site · Last accessed by source map: 2026-09-25
Version: The site gives no publication date. Its text was read from the public JavaScript asset https://ping-location.info/assets/index-sg1kynaJ.js linked by the home page on 2026-09-25. The 2025 IAPS brief (S-1401) links to the demonstration, so 2025 is the latest possible year for its initial publication.
Catalogue note
Ulyssean's account of its H100 and AMD SEV-SNP demonstration, using 38 Google Cloud Run landmarks. It describes the setup and timing method and says the code will be open-sourced after cleanup. It gives no systematic end-to-end location results or error rates. Developer documentation supports attributed claims about this demo.
Original catalogue record ↗S-1001 / Tier B2025 / code
Prime Intellect
GitHub · Last accessed by source map: 2026-09-25
Version: Pinned to release tag v0.1.6 (commit 7ab7bcd, 10 Apr 2025), the latest release listed on the repository's releases page when viewed on 2026-09-23. Still the latest release on GitHub and PyPI on 2026-09-25.
Original catalogue record ↗S-1816 / Tier C2025 / blog
J. Yagnik
Google blog (The Keyword) · Last accessed by source map: 2026-09-25
Catalogue note
Google's announcement of Private AI Compute: Gemini models on Google's TPUs with Titanium Intelligence Enclaves (TIE), and remote attestation and encryption connecting the device to the "hardware-secured sealed cloud environment"; first used by Magic Cue and Recorder on Pixel. Vendor post; supports only "Google reports" statements.
Original catalogue record ↗S-1609 / Tier B2025 / preprint
I. Komargodski, O. Weinstein
arXiv · Last accessed by source map: 2026-09-25
Version: v1 14 April 2025; v4 13 November 2025. Also IACR ePrint 2025/685 (last revised 8 December 2025), listed there as a preprint. v3 listed I. Schen as a third author; v4 and the ePrint version list two. Remark, assumption and open-problem numbers follow the ePrint PDF.
Catalogue note
The construction underlying Pearl (I-0004). Pearl Research Labs lists the paper among its protocol research, and Komargodski gives Pearl Research Labs as his affiliation on S-1010. The paper itself names no company.
Original catalogue record ↗S-1212 / Tier A2025 / peer reviewed
B. Schlüter, S. Shinde
2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) · Last accessed by source map: 2026-10-08
Version: Read the authors' site and the paper PDF linked from it (https://rmpocalypse.github.io/rmpocalypse-CCS2025.pdf) on 2026-09-24. The DOI and venue are from the ACM reference block printed in the PDF.
Catalogue note
Independent attack paper (ETH Zurich). A malicious hypervisor corrupts AMD's Reverse Map Table during SEV-SNP initialisation, with no physical access. Confirmed on Zen 3, Zen 4 and Zen 5 processors. Demonstrates enabling debug on production confidential VMs, faking attestation, register-state replay and code injection. AMD assigned CVE-2025-0033; AMD's bulletin is S-1213.
Original catalogue record ↗S-1213 / Tier B2025 / docs
AMD
AMD product security bulletin · Last accessed by source map: 2026-10-08
Version: Initial publication 2025-10-13; read in the revision last updated 2026-02-23.
Catalogue note
AMD's own bulletin on CVE-2025-0033 (RMPocalypse, S-1212); supports only "AMD reports" statements. Rates the issue CVSS 6.0 (medium) and lists SEV firmware, microcode or platform-initialisation firmware updates for affected EPYC 7003, 8004, 9004 and 9005 server series and embedded series, with release dates from June 2025 to February 2026.
Original catalogue record ↗S-3565 / Tier A2025 / peer reviewed
W. Cai, J. Jiang, L. Qin, J. Cui, S. Kim, J. Huang
ICML 2025, Proceedings of Machine Learning Research 267 · Last accessed by source map: 2026-09-25
Catalogue note
The paper reports all-to-all expert-parallel communication as a bottleneck in both MoE training and inference.
Original catalogue record ↗S-0041 / Tier A2025 / peer reviewed
I. Latif, A. C. Newkirk, M. R. Carbone, A. Munir, Y. Lin, J. Koomey, X. Yu, Z. Dong
IEEE Access, vol. 13, pp. 61740–61747 · Last accessed by source map: 2026-09-23
Version: Published in IEEE Access under a new title. The arXiv preprint (v1 11 December 2024, v2 20 December 2024) is titled "Empirical Measurements of AI Training Power Demand on a GPU-Accelerated Node". The published abstract, checked 2026-09-24, states the 8.4 kW peak and the 18% gap to the rated 10.2 kW that citing records use.
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1404 / Tier B2025 / docs
Sovereignty Certificates Working Group
GitHub (Lucid-Computing/sovereignty-certificate-specification) · Last accessed by source map: 2026-09-25
Version: Status "Draft", version 0.1.0, dated 2025-10-21, "Prepared by: Sovereignty Certificates Working Group". Read from spec/sovereignty-certificates.md on the main branch on 2026-09-23, at commit e65f5c1ba19094430bf586917b4760151759e990 (commit dated 2026-02-09; the repository's v0.1.0 tag points to the earlier commit 1d4bd34a6bff342db4fa4a43d143fe95eaa46b7d). Re-read on 2026-09-25: the repository still shows three commits and no code, and the title block, threat model (§8.1), §7.1.2-7.1.4, §8.3.3-8.3.4 and Annex B read as before.
Catalogue note
Hosted in Lucid Computing's GitHub organization. Documentation about the specifying party's own system, so it supports "the specification states / Lucid reports" statements only.
Original catalogue record ↗S-1004 / Tier C2025 / blog
Prime Intellect
Prime Intellect blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's blog post; describes its use of "TOPLOC v2". Supports only "Prime Intellect reports" statements.
Original catalogue record ↗S-3000 / Tier C2025 / blog
Prime Intellect
Prime Intellect blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's report on its own data-generation run, bylined with first names only. Describes the TOPLOC v2 checks, the reported false-positive rate and verification cost, and the GPUs that took part. Supports only "Prime Intellect reports" statements.
Original catalogue record ↗S-1204 / Tier B2025 / preprint
J. Petrie, O. Aarne
arXiv · Last accessed by source map: 2026-09-25
Version: v3 (2025-06-18), still the latest version, read on 2026-09-25; v1 was submitted 2025-06-03.
Catalogue note
Part II of the three-part flexHEG series, which the report says was commissioned by ARIA. Part I is S-0035 and Part III is S-1205.
Original catalogue record ↗S-1813 / Tier B2025 / code
Thinking Machines Lab
GitHub · Last accessed by source map: 2026-09-25
Version: Main branch as viewed on 2026-09-24 (7 commits). MIT licence.
Catalogue note
Companion library to S-1009. Replaces torch.mm, torch.addmm, torch.log_softmax and torch.mean with batch-invariant kernels through torch.Library, and includes a deterministic vLLM example: 18 unique samples out of 1000 completions without the upstream vLLM change, one unique sample with it.
Original catalogue record ↗S-1000 / Tier A2025 / peer reviewed
J. M. Ong, M. Di Ferrante, A. Pazdera, R. Garner, S. Jaghouar, M. Basra, M. Ryabinin, J. Hagemann
Proceedings of the 42nd International Conference on Machine Learning (PMLR 267), pp. 47196-47211 · Last accessed by source map: 2026-10-08
Version: Full text read from arXiv v2 (30 May 2025, HTML and PDF); PMLR abstract page checked for venue, pages and author list.
Original catalogue record ↗S-1002 / Tier C2025 / blog
Prime Intellect
Prime Intellect blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's announcement of its own method; supports only "Prime Intellect reports" statements. Byline gives first names only.
Original catalogue record ↗S-1012 / Tier C2025 / blog
The SGLang Team
LMSYS Org blog · Last accessed by source map: 2026-09-25
Catalogue note
Developers' post about their own inference engine; performance figures are provider-reported. The post states it was updated on 24 Sep 2025.
Original catalogue record ↗S-1408 / Tier C2025 / blog
N. Cankaya
The Datacenter Lie Detector (Substack) · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-3383 / Tier A2025 / gov doc
U.S. Department of Justice
U.S. Department of Justice, Office of Public Affairs · Last accessed by source map: 2026-09-25
Catalogue note
Separates the guilty pleas of Hsu and Hao Global from charges against Gong and Yuan. The alleged removal and replacement of NVIDIA GPU labels concerns Gong's charged scheme, not the guilty pleas.
Original catalogue record ↗S-1810 / Tier C2025 / blog
O. Ersoy
Gensyn research blog · Last accessed by source map: 2026-09-25
Catalogue note
Developer's post (page shows last modified 4 Sep 2026). States that Verde and RepOps are deployed in Judge, that Verde covers training, fine-tuning and inference, that RepOps gives bitwise-reproducible results across hardware, and that Verde guarantees the output came from the declared model and data, not that the model is correct. Supports only "Gensyn reports" statements.
Original catalogue record ↗S-1809 / Tier B2025 / preprint
A. Arun, A. St. Arnaud, A. Titov, B. Wilcox, V. Kolobaric, M. Brinkmann, O. Ersoy, B. Fielding, J. Bonneau
arXiv · Last accessed by source map: 2026-10-08
Version: v1 (26 Feb 2025) read in HTML. dblp lists only the arXiv version.
Catalogue note
Most authors at Gensyn; Arun and Bonneau at New York University (Bonneau also a16z crypto research). Describes the Verde dispute protocol (correct result if at least one provider is honest) and RepOps; evaluation reports RepOps overheads on T4, RTX 3090 and A100 GPUs for DistilBERT and Llama models (Table 2: Llama-8B on A100 80 GB, 98% inference, 126% LoRA fine-tuning). RepOps supports FP32 and one GPU per setup.
Original catalogue record ↗S-0004 / Tier B2025 / tech report
B. Harack, R. F. Trager, A. Reuel, D. Manheim, M. Brundage, O. Aarne, A. Scher, Y. Pan, J. Xiao, K. Loke, S. N. Adan, G. Bas, N. A. Caputo, J. C. Morse, J. Ahuja, I. Duan, J. Egan, B. Bucknall, B. Rosen, R. Araujo, V. Boulanin, R. Lall, F. Barez, S. Alvira, C. Katzke, A. Atamli, A. Awad
Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0002 / Tier B2025 / tech report
M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim
RAND Corporation · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Research agendas and surveys" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0015 / Tier B2025 / preprint
R. Rinberg, A. Karvonen, A. Hoover, D. Reuter, K. Warr
arXiv · Last accessed by source map: 2026-09-25
Version: arXiv v1 4 Nov 2025, v2 10 Dec 2025, v3 12 Mar 2026; v3 read. No journal or conference version found as of 2026-09-25.
Catalogue note
Listed under "Inference verification" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1211 / Tier A2025 / peer reviewed
A. Seto, O. K. Duran, S. Amer, J. Chuang, S. van Schaik, D. Genkin, C. Garman
2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) · Last accessed by source map: 2026-10-08
Version: Read the authors' site and the paper PDF linked from it (https://wiretap.fail/files/wiretap.pdf) on 2026-09-24. The DOI and venue are from the ACM reference block printed in the PDF; the ACM Digital Library page could not be fetched.
Catalogue note
Independent attack paper (Purdue University, Georgia Tech). DDR4 memory-bus interposer built for under $1000 (bill of materials $857) that records bus traffic. Recovers the ECDSA attestation key of Intel SGX's Quoting Enclave from a Xeon Scalable server in fully trusted status and forges SGX DCAP quotes. The site states that Intel considers the attack outside the SGX threat model and that there are no mitigations besides physical security. Several authors also wrote TEE.fail (S-1202).
Original catalogue record ↗S-3060 / Tier A2025 / peer reviewed
W. Qu, Y. Sun, X. Liu, T. Lu, Y. Guo, K. Chen, J. Zhang
34th USENIX Security Symposium (USENIX Security 25), pp. 2045–2063 · Last accessed by source map: 2026-09-25
Version: Proceedings paper read from the USENIX PDF (usenixsecurity25-qu-zkgpt.pdf). Code archived on Zenodo, DOI 10.5281/zenodo.14727819 (v1, 23 January 2025, CC BY 4.0).
Catalogue note
National University of Singapore and Hong Kong University of Science and Technology. Proves GPT-2 inference with GKR, Lasso lookups and Hyrax commitments, made non-interactive with Fiat–Shamir; Table 3 reports 21.8 s proving (32 threads), 0.35 s verification and a 101 KB proof on a 16-core Xeon server with 200 GB of memory.
Original catalogue record ↗S-0070 / Tier B2025 / tech report
F. Casal, T. Hess, L. Bourtoule, S. Hussain, G. Larregay
Trail of Bits (prepared for Zkonduit Inc.) · Last accessed by source map: 2026-09-23
Version: Final report of 12 March 2025. Review of 6–27 January 2025 (11 engineer-weeks) of ezkl at commit bdcba5ca61ada24f17dd754e6e3c71d0a1ef72d9 and two halo2-solidity-verifier pull requests; fix review 3–4 March 2025 (Appendix D).
Catalogue note
Independent security audit of the ezkl zero-knowledge inference library, commissioned by its developer. Reports 34 findings (8 high severity), including circuit soundness issues and quantization-activated model backdoors. Appendix D's limited fix review marks 29 resolved (including all 8 high-severity issues), 3 partially resolved and 2 unresolved. It says some contract fixes were in private repositories and had not been merged into public repositories at review time.
Original catalogue record ↗S-0073 / Tier A2024 / peer reviewed
Z. Yang, K. Adamek, W. Armour
SC24: International Conference for High Performance Computing, Networking, Storage and Analysis · Last accessed by source map: 2026-09-25
Version: Published in the SC24 proceedings (presented 2024-11-19; DOI 10.1109/SC41406.2024.00028). The arXiv preprint is titled "Part-time Power Measurements: nvidia-smi's Lack of Attention" (v1 2023-12-05, v3 2024-12-12). The arXiv v3 abstract and HTML were read on 2026-09-25; the SC24 programme abstract was read the same day and states the 25% sampling finding. The IEEE and ACM pages could not be read.
Catalogue note
Micro-benchmark study of nvidia-smi power readings on over 70 NVIDIA GPUs across 12 architecture generations. States that nvidia-smi uses NVML (§2.4), that on A100 and H100 GPUs only 25% of runtime is sampled for power, and that the reading's error is ±5% (within ±5% in most cases, §4.2) rather than the ±5 W NVIDIA claims.
Original catalogue record ↗S-2011 / Tier C2024 / blog
G. Essix
NTI · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-0053 / Tier B2024 / preprint
G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle
arXiv · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0). Also listed on the Oxford Martin AI Governance Initiative's publications page (https://aigi.ox.ac.uk/publications/computing-power-and-the-governance-of-artificial-intelligence/, read 2026-09-24). Also presented as a GovAI research paper (https://www.governance.ai/research-paper/computing-power-and-the-governance-of-artificial-intelligence, read 2026-09-24).
Original catalogue record ↗S-0046 / Tier A2024 / peer reviewed
Y. Gao, H. Qiu, Z. Zhang, B. Wang, H. Ma, A. Abuadbba, M. Xue, A. Fu, S. Nepal
2024 IEEE Symposium on Security and Privacy · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1314 / Tier B2024 / preprint
A. Douillard, Q. Feng, A. A. Rusu, R. Chhaparia, Y. Donchev, A. Kuncoro, M. Ranzato, A. Szlam, J. Shen
ICML 2024 Workshop on Advancing Neural Network Training (WANT) · Last accessed by source map: 2026-09-25
Version: v1 submitted 14 November 2023; v3 revised 23 September 2024. Poster at the 2nd Workshop on Advancing Neural Network Training (WANT@ICML 2024), per the ICML 2024 page (https://icml.cc/virtual/2024/37144), checked 2026-09-24.
Original catalogue record ↗S-0055 / Tier A2024 / peer reviewed
U. Anwar, A. Saparov, J. Rando, D. Paleka, M. Turpin, P. Hase, E. S. Lubana, E. Jenner, S. Casper, O. Sourbut, B. L. Edelman, Z. Zhang, M. Günther, A. Korinek, J. Hernandez-Orallo, L. Hammond, E. Bigelow, A. Pan, L. Langosco, T. Korbak, H. Zhang, R. Zhong, S. Ó hÉigeartaigh, G. Recchia, G. Corsi, A. Chan, M. Anderljung, L. Edwards, A. Petrov, C. Schroeder de Witt, S. R. Motwani, Y. Bengio, D. Chen, P. H. S. Torr, S. Albanie, T. Maharaj, J. Foerster, F. Tramèr, H. He, A. Kasirzadeh, Y. Choi, D. Krueger
Transactions on Machine Learning Research · Last accessed by source map: 2026-09-23
Version: Published in TMLR (2024); arXiv preprint 2404.09932. Venue and author list checked 2026-09-24 against the ML Anthology record of the TMLR paper, which gives "Sumeet Ramesh Motwani" (the arXiv metadata reads "Motwan").
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0058 / Tier B2024 / tech report
L. Heim, T. Fist, J. Egan, S. Huang, S. Zekany, R. Trager, M. Osborne, N. Zilberman
Oxford Martin AI Governance Initiative · Last accessed by source map: 2026-09-25
Version: Oxford Martin AI Governance Initiative policy paper dated 13 March 2024; also on arXiv (v1 13 March 2024, v2 26 March 2024), with no journal reference as of 2026-09-25.
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0057 / Tier B2024 / tech report
G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman
RAND Corporation · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0042 / Tier B2024 / preprint
T. Gregersen, P. Patel, E. Choukse
SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis (Sustainable Supercomputing workshop), pp. 1872–1877 · Last accessed by source map: 2026-09-23
Version: Workshop paper at Sustainable Supercomputing at SC24 (IEEE Xplore document 10820679); kept at tier B as a workshop paper. The URL points to the arXiv version. Venue, pages and DOI from Crossref, checked 2026-09-24.
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3300 / Tier C2024 / blog
L. Heim, K. Pilz
Lennart Heim's blog · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-1400 / Tier B2024 / tech report
A. Brass, O. Aarne
Institute for AI Policy and Strategy · Last accessed by source map: 2026-09-25
Catalogue note
The IAPS page links the full report PDF (static1.squarespace.com/static/64edf8e7f2b10d716b5ba0e1/t/6670467ebe2a477eb1554f40/1718634112482/Location%2BVerification%2Bfor%2BAI%2BChips.pdf), which was read on 2026-09-23. The PDF text as fetched shows no byline or date. The current IAPS landing page presents the May 2025 issue brief by Asher Brass. Authors are taken from the IAPS issue brief (S-1401), which names Asher Brass and Onni Aarne and refers to a "full 2024 report", and from citations in S-1402 and S-0007. S-1402 cites it as April 2024; the month is not confirmed on the IAPS page itself.
Original catalogue record ↗S-1815 / Tier C2024 / blog
C. Su
NVIDIA Blog · Last accessed by source map: 2026-09-25
Catalogue note
NVIDIA's announcement that Azure NCC H100 v5 confidential VMs are generally available in the Azure East US2 and West Europe regions. Vendor post; supports only "NVIDIA reports" statements.
Original catalogue record ↗S-3081 / Tier A2024 / peer reviewed
M. Srivastava, S. Arora, D. Boneh
Advances in Neural Information Processing Systems 37 (NeurIPS 2024) · Last accessed by source map: 2026-09-25
Version: arXiv v3 (25 November 2024) read in HTML; v1 posted 14 March 2024. Venue from the arXiv comments field and the code README. The NeurIPS proceedings page was not read.
Catalogue note
Code at https://github.com/meghabyte/verifiable-training (not pinned). Exact FP32 replication of ResNet-50 (CIFAR-10) training and GPT-2 fine-tuning across NVIDIA A40, Titan XP and RTX 2080 Ti; trainer overhead 1.2–1.4×, auditor 1.3–1.7×; assumes one of n auditors is honest.
Original catalogue record ↗S-1509 / Tier C2024 / forum
R. Greenblatt
AI Alignment Forum · Last accessed by source map: 2026-09-25
Catalogue note
Posted under the username ryan_greenblatt.
Original catalogue record ↗S-1800 / Tier C2024 / blog
Apple Security Engineering and Architecture (SEAR)
Apple Security Research blog · Last accessed by source map: 2026-09-25
Catalogue note
Byline: SEAR with Apple's User Privacy, Core Operating Systems, Services Engineering, and Machine Learning and AI teams. Apple's description of its own system; supports only "Apple reports" statements. Covers the five core requirements, Apple silicon servers with the Secure Enclave and Secure Boot, the rule that devices wrap request keys only to nodes whose attested measurements match a release in the public transparency log, publication of production images within 90 days of log inclusion, integrity protection of code and model assets, and a threat model that includes attackers with physical access to a node.
Original catalogue record ↗S-3542 / Tier A2024 / gov doc
European Parliament, Council of the European Union
Official Journal of the European Union, OJ L, 2024/1689 · Last accessed by source map: 2026-09-25
Version: The fetch tool could not render the articles on EUR-Lex, so Articles 51, 52 and 113 were read on the European Commission's AI Act Service Desk (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-51, article-52 and article-113). Article 51(2) presumes high-impact capabilities above 10^25 FLOP of cumulative training compute; Article 52(1) requires notification of the Commission within two weeks; Article 113(b) applies Chapter V from 2 August 2025.
Original catalogue record ↗S-0056 / Tier B2024 / tech report
O. Aarne, T. Fist, C. Withers
Center for a New American Security · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1610 / Tier B2024 / tech report
S. Nevo, D. Lahav, A. Karpur, Y. Bar-On, H. A. Bradley, J. Alstott
RAND Corporation · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-1801 / Tier C2024 / blog
Apple Security Engineering and Architecture (SEAR)
Apple Security Research blog · Last accessed by source map: 2026-09-25
Catalogue note
Apple's announcement of its PCC research resources: the PCC Security Guide, the Virtual Research Environment (runs PCC node software in a VM on an Apple silicon Mac; lists and inspects releases, checks the transparency log, runs inference against demonstration models), source code for CloudAttestation, Thimble, splunkloggingd and srd_tools under a limited-use licence (github.com/apple/security-pcc), and PCC bounty categories of up to $1,000,000. Supports only "Apple reports" statements. The Security Guide itself (security.apple.com/documentation/private-cloud-compute) needs JavaScript and was not read.
Original catalogue record ↗S-0032 / Tier A2024 / peer reviewed
S. Bursuc, R. Gil-Pons, S. Mauw, R. Trujillo-Rasua
2024 IEEE 37th Computer Security Foundations Symposium (CSF 2024) · Last accessed by source map: 2026-09-25
Version: The record previously pointed to the arXiv extended version, "Software-Based Memory Erasure with relaxed isolation requirements: Extended Version" (https://arxiv.org/abs/2401.06626); section locators in citing records refer to that version. Venue and DOI from the Crossref record for the CSF 2024 paper, checked 2026-09-24.
Catalogue note
Listed under "Network and memory telemetry" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0022 / Tier A2024 / peer reviewed
S. Waiwitlikhit, I. Stoica, Y. Sun, T. Hashimoto, D. Kang
41st International Conference on Machine Learning (ICML 2024) · Last accessed by source map: 2026-10-08
Catalogue note
Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0024 / Tier B2024 / preprint
T. South, A. Camuto, S. Jain, S. Nguyen, R. Mahari, C. Paquin, J. Morton, A. Pentland
arXiv · Last accessed by source map: 2026-09-25
Version: v2 (22 May 2024) read; no journal or conference version is listed on arXiv as of 2026-09-25.
Catalogue note
Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3381 / Tier C2024 / blog
A. Aguirre, R. Millet
Future of Life Institute · Last accessed by source map: 2026-09-25
Version: The page shows publication on 2024-07-23 and an update on 2025-05-20.
Catalogue note
FLI (Aguirre) and Mithril Security (Millet) describe AICert, a proof of concept that uses Trusted Platform Modules to bind a model's weights to its training code and data, and state its limits (fine-tuning only, no third-party audit, no detection of poisoned models or datasets). Code at https://github.com/mithril-security/aicert, whose README warns that AICert is still under development and not for production use (read 2026-09-25). Supports "FLI reports" statements only.
Original catalogue record ↗S-0062 / Tier B2024 / preprint
A. R. Wasil, T. Reed, J. W. Miller, P. Barnett
arXiv · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1110 / Tier A2024 / peer reviewed
K. Abbaszadeh, C. Pappas, J. Katz, D. Papadopoulos
2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330 · Last accessed by source map: 2026-10-08
Version: Read the IACR ePrint version (last revised 22 July 2024). Venue and DOI from the HKUST research portal record. On 2026-10-08 the abstract and indexed paper excerpts were re-read; direct PDF downloads were not reachable.
Catalogue note
Describes the Kaizen zkPoT system.
Original catalogue record ↗S-1108 / Tier B2024 / code
H. Sun
GitHub; archived on Zenodo · Last accessed by source map: 2026-10-08
Version: Tag ae-alpha (Zenodo release of 3 September 2024, after CCS 2024 artifact evaluation). The GitHub repository was archived read-only on 10 July 2025; the README read at access is from main.
Original catalogue record ↗S-0023 / Tier A2024 / peer reviewed
H. Sun, J. Li, H. Zhang
2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024) · Last accessed by source map: 2026-10-08
Catalogue note
Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0021 / Tier A2024 / peer reviewed
B.-J. Chen, S. Waiwitlikhit, I. Stoica, D. Kang
19th European Conference on Computer Systems (EuroSys 2024) · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Zero-knowledge proofs" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0047 / Tier A2023 / peer reviewed
R. Joud, P.-A. Moëllic, S. Pontié, J.-B. Rigaud
21st International Conference on Smart Card Research and Advanced Applications (CARDIS 2022), LNCS 13820, pp. 45–65 · Last accessed by source map: 2026-09-23
Version: The CARDIS 2022 proceedings (LNCS 13820) were published in 2023 (online 29 January 2023); the year is the proceedings year. Venue, pages and DOI from the Springer chapter page, checked 2026-09-24.
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1201 / Tier C2023 / blog
E. Apsey, P. Rogers, M. O'Connor, R. Nertney
NVIDIA Technical Blog · Last accessed by source map: 2026-09-25
Catalogue note
NVIDIA engineers describing the H100 confidential-computing launch: on-die root of trust, fused device identity key, SPDM attestation, and performance at launch. Supports only "NVIDIA reports" statements.
Original catalogue record ↗S-1203 / Tier C2023 / blog
Future of Life Institute
Future of Life Institute · Last accessed by source map: 2026-09-25
Catalogue note
Describes an FLI and Mithril Security proof-of-concept built on BlindAI and Intel SGX (code at https://github.com/mithril-security/blindai_drm_fli). The page shows a modification date of 2024-07-31.
Original catalogue record ↗S-0051 / Tier A2023 / peer reviewed
T. Mosavirik, P. Schaumont, S. Tajik
IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(1), 301–325 · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Tamper resistance and detection" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0061 / Tier B2023 / tech report
R. Trager, B. Harack, A. Reuel, A. Carnegie, L. Heim, L. Ho, S. Kreps, R. Lall, O. Larter, S. Ó hÉigeartaigh, S. Staffell, J. J. Villalobos
Centre for the Governance of AI · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Motivations and policy proposals" in the Hodgkins bibliography (CC BY 4.0). Also listed on the Oxford Martin AI Governance Initiative's publications page (https://aigi.ox.ac.uk/publications/international-governance-of-civilian-ai-a-jurisdictional-certification-approach/, read 2026-09-24). Also presented as a GovAI research paper (https://www.governance.ai/research-paper/international-governance-of-civilian-ai, read 2026-09-24).
Original catalogue record ↗S-2001 / Tier B2023 / preprint
M. Baker
arXiv · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-2008 / Tier A2023 / gov doc
Organisation for the Prohibition of Chemical Weapons
OPCW · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-0027 / Tier A2023 / peer reviewed
C. Fang, H. Jia, A. Thudi, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, V. Chandrasekaran, N. Papernot
8th IEEE European Symposium on Security and Privacy (EuroS&P 2023) · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Proof of learning and training" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1603 / Tier B2023 / tech report
H. Birkholz, D. Thaler, M. Richardson, N. Smith, W. Pan
Internet Engineering Task Force (RATS Working Group) · Last accessed by source map: 2026-09-25
Version: IETF Informational RFC, January 2023. Not a Standards Track specification; the header states it represents the consensus of the IETF community. Recorded as a technical report (tier B) rather than a standard for that reason.
Original catalogue record ↗S-1306 / Tier A2023 / peer reviewed
A. Ivanov, B. Rothenberger, A. Dethise, M. Canini, T. Hoefler, A. Perrig
2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 485–499 · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-0030 / Tier A2023 / peer reviewed
D. Choi, Y. Shavit, D. K. Duvenaud
Advances in Neural Information Processing Systems 36 (NeurIPS 2023) · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Proof of learning and training" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0029 / Tier B2023 / preprint
Y. Shavit
arXiv · Last accessed by source map: 2026-09-25
Version: Read arXiv v2 (30 May 2023).
Catalogue note
Listed under "Proof of learning and training" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1109 / Tier A2022 / peer reviewed
R. Zhang, J. Liu, Y. Ding, Z. Wang, Q. Wu, K. Ren
2022 IEEE Symposium on Security and Privacy (SP), pp. 1408-1422 · Last accessed by source map: 2026-09-25
Catalogue note
Read the arXiv version. Venue per the authors' code repository README (github.com/ZhangRui98/Adversarial-examples-for-Proof-of-Learning). The DOI resolves to IEEE Xplore document 9833596; OpenAlex gives the title, authors, venue and pages for it (checked 2026-09-25).
Original catalogue record ↗S-0052 / Tier A2022 / peer reviewed
P. Staat, J. Tobisch, C. Zenger, C. Paar
2022 IEEE Symposium on Security and Privacy · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Tamper resistance and detection" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1604 / Tier B2022 / tech report
Confidential Computing Consortium
Confidential Computing Consortium · Last accessed by source map: 2026-09-25
Version: The document gives its date as December 2022.
Original catalogue record ↗S-1606 / Tier B2022 / tech report
D. Benarroch, L. Brandão, M. Maller, E. Tromer
ZKProof · Last accessed by source map: 2026-09-25
Version: Version 0.3 (17 July 2022). The listed persons are the editors of a community document.
Original catalogue record ↗S-1111 / Tier B2021 / code
CleverHans Lab
GitHub · Last accessed by source map: 2026-09-25
Version: Default branch at commit c286c7c0d2b45d80b4b6a7b0c2995690034927ff (19 October 2021), the latest commit at access (confirmed through the GitHub API by the verifier on 2026-09-23).
Original catalogue record ↗S-0028 / Tier A2021 / peer reviewed
H. Jia, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, A. Thudi, V. Chandrasekaran, N. Papernot
2021 IEEE Symposium on Security and Privacy (SP), pp. 1039-1056 · Last accessed by source map: 2026-09-25
Version: Read the arXiv version (v1, 9 March 2021). DOI and pages from OpenAlex, checked 2026-09-25.
Catalogue note
Listed under "Proof of learning and training" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-0040 / Tier A2020 / peer reviewed
A. Gangwal, S. G. Piazzetta, G. Lain, M. Conti
Cryptology and Network Security – CANS 2020, LNCS 12579, pp. 344–364 · Last accessed by source map: 2026-09-25
Version: arXiv preprint first posted in 2019 (1909.00268); published at the 19th International Conference on Cryptology and Network Security (CANS 2020). The year is the proceedings year. Venue, pages and DOI from the Springer chapter page, checked 2026-09-24.
Catalogue note
Listed under "Power telemetry and side-channel attacks" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1315 / Tier A2019 / peer reviewed
V. Immler, J. Obermaier, K. K. Ng, F. X. Ke, J. Lee, Y. P. Lim, W. K. Oh, K. H. Wee, G. Sigl
IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019(1), 51–96 · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-1601 / Tier A2018 / gov doc
A. Regenscheid
National Institute of Standards and Technology · Last accessed by source map: 2026-09-25
Version: Final publication. Full text read at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-193.pdf
Original catalogue record ↗S-0049 / Tier A2018 / peer reviewed
J. Obermaier, V. Immler
Journal of Hardware and Systems Security · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Tamper resistance and detection" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-1608 / Tier B2017 / preprint
M. Ball, A. Rosen, M. Sabin, P. N. Vasudevan
IACR Cryptology ePrint Archive 2017/203 · Last accessed by source map: 2026-09-25
Version: The ePrint page describes it as a major revision of an IACR publication in CRYPTO 2018.
Original catalogue record ↗S-1602 / Tier B2017 / docs
Trusted Computing Group
Trusted Computing Group · Last accessed by source map: 2026-09-25
Version: Version 1.1, Revision 1.00 (11 May 2017). Full text read at https://trustedcomputinggroup.org/wp-content/uploads/TCG-Glossary-V1.1-Rev-1.0.pdf
Original catalogue record ↗S-1607 / Tier A2015 / peer reviewed
S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak
CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796) · Last accessed by source map: 2026-09-25
Version: The ePrint version states it is a minor revision of the CRYPTO 2015 publication.
Original catalogue record ↗S-1316 / Tier B2015 / tech report
H. A. Smartt, Z. N. Gastelum
Sandia National Laboratories, SAND2015-4251C · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-2007 / Tier A2014 / peer reviewed
A. Glaser, B. Barak, R. J. Goldston
Nature 510, 497–502 · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-0050 / Tier B2012 / tech report
IBM Corporation
NIST Cryptographic Module Validation Program · Last accessed by source map: 2026-09-25
Catalogue note
Listed under "Tamper resistance and detection" in the Hodgkins bibliography (CC BY 4.0).
Original catalogue record ↗S-3260 / Tier A2011 / gov doc
National Institute of Standards and Technology
NIST Cryptographic Module Validation Program · Last accessed by source map: 2026-09-25
Version: Living certificate page. Read on 2026-09-25: initial validation 2011-02-24, last update 2012-12-21, overall Level 4, status Historical (reason given: RNG transition under SP 800-131A Rev. 1), so the module should not be included by federal agencies in new procurements.
Original catalogue record ↗S-0074 / Tier B2010 / tech report
A. Perrig, L. van Doorn
Technical note (CyLab, Carnegie Mellon University) · Last accessed by source map: 2026-10-08
Version: Dated 11 August 2010. Read the copy hosted by ETH Zurich's network security group on 2026-10-07; the copy on sparrow.ece.cmu.edu refuses automated access. Some later papers cite it as April 2010.
Catalogue note
Reply to S-1308 by two designers of SWATT and ICE (Perrig at CyLab/CMU, van Doorn at AMD). Supports attributed statements only. Castelluccia et al. answered in a 2010 note; no public full text was found.
Original catalogue record ↗S-1304 / Tier A2010 / peer reviewed
D. Perito, G. Tsudik
Computer Security – ESORICS 2010, LNCS 6345, pp. 643–662 · Last accessed by source map: 2026-09-25
Catalogue note
Also available as IACR ePrint 2010/217 (https://eprint.iacr.org/2010/217), which was also read. Pages confirmed in Crossref on 2026-09-25.
Original catalogue record ↗S-1308 / Tier A2009 / peer reviewed
C. Castelluccia, A. Francillon, D. Perito, C. Soriente
Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), pp. 400–409 · Last accessed by source map: 2026-09-25
Version: Read the authors' PDF hosted by EURECOM; the ACM page could not be fetched, and the DOI, title and pages were confirmed in Crossref on 2026-09-25.
Original catalogue record ↗S-1307 / Tier A2004 / peer reviewed
A. Seshadri, A. Perrig, L. van Doorn, P. Khosla
IEEE Symposium on Security and Privacy 2004, pp. 272–282 · Last accessed by source map: 2026-09-25
Catalogue note
Venue confirmed from the ETH Zurich Network Security Group publication list; pages and DOI from Crossref, checked 2026-09-25.
Original catalogue record ↗S-0072 / Tier A2003 / standard
E. Rescorla, B. Korver, Internet Architecture Board
Internet Engineering Task Force · Last accessed by source map: 2026-09-25
Version: IETF Best Current Practice (BCP 72), July 2003. Section 3, "The Internet Threat Model", defines a threat model and states its purpose. The RFC Editor lists it as updated by RFC 8996 (deprecating TLS 1.0 and 1.1) and RFC 9416 (transient numeric identifiers); neither changes Section 3.
Original catalogue record ↗S-2009 / Tier B2003 / tech report
Nuclear Threat Initiative
NTI · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-1605 / Tier A2001 / standard
National Institute of Standards and Technology
National Institute of Standards and Technology · Last accessed by source map: 2026-09-25
Version: Published 25 May 2001 (Change Notice 2, 3 December 2002). The CSRC page lists it as superseded by FIPS 140-3. Full text read at https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf
Original catalogue record ↗S-1318 / Tier A2001 / peer reviewed
R. G. Johnston
The Nonproliferation Review, Spring 2001, pp. 102–114 · Last accessed by source map: 2026-10-08
Original catalogue record ↗S-1317 / Tier B1996 / tech report
R. G. Johnston, A. R. E. Garcia
Los Alamos National Laboratory, LA-UR-96-3827 · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-2002 / Tier A1987 / gov doc
R. Reagan
Ronald Reagan Presidential Library and Museum · Last accessed by source map: 2026-09-25
Original catalogue record ↗S-2003 / Tier A1972 / gov doc
United States of America, Union of Soviet Socialist Republics
United Nations Treaty Series, vol. 944, No. 13446 · Last accessed by source map: 2026-09-25
Catalogue note
Article XII covers national technical means of verification and non-interference with them.
Original catalogue record ↗