The requirement of capturing evidence that can uniquely identify each ML workload (as in, every forward pass) is what I settled on. The reasoning behind this is that with this evidence, you can —in principle— screen for any governance objective. Do you think this is trying too much?
No and Yes. I believe the current trust environment calls for a 'defense-in-depth' strategy, and we need our perimeter defenses urgently. A near-term defense doesn't need to conclusively verify a workload, it needs to produce enough signal to throw up... (read more)
No and Yes. I believe the current trust environment calls for a 'defense-in-depth' strategy, and we need our perimeter defenses urgently. A near-term defense doesn't need to conclusively verify a workload, it needs to produce enough signal to throw up... (read more)