How would this work technically? . . . Ideally this compliance check would be bundled into the closed-source driver powering NVIDIA GPUs
Even better would be having the technology built right into Nvidia’s chips—like Apple has technology built into its A-series and M-series chips that prevent software not signed by Apple from running on them. This technology is called remote attestation or (more recently) trusted computing or sometimes “confidential computing” (although this latter term assumes a particular application of the tech).
How would you get NVIDIA to implement this? . . .Why would they implement a feature that constrains the sort of models which can run on their GPUs?
Nvidia has implemented it (in hardware) in some of its GPUs, and there are companies that use Nvidia’s GPUs to host open-weights models in such a way that (if the technology has been designed and implemented correctly—i.e., without any security holes) the hosting company cannot eavesdrop on the communications between the customer and the model. (The same basic technology—remote attestation—can be used for the purpose you want.) tinfoil.sh is one such company. I used Tinfoil just yesterday to have a enhanced-confidentiality chat with Kimi K3.
This post from 2 months ago gives an overview of the technology.
In a recent comment an expert on this technology (remote attestation) states that Nvidia’s implementation of the technology probably hasn’t been tested much yet, so there’s a good chance that there is some flaw in it that could be exploited with enough labor by experts. This is in contrast to Apple’s implementation, which is many years old at this point and has been looking quite solid for years. Nobody for example has published a jailbreak for a recent iPhone running a recent version of iOS and even though there is a lot of interest in iPhone jailbreaks and a lot of glory for anyone who manages to publish one.
Even better would be having the technology built right into Nvidia’s chips—like Apple has technology built into its A-series and M-series chips that prevent software not signed by Apple from running on them. This technology is called remote attestation or (more recently) trusted computing or sometimes “confidential computing” (although this latter term assumes a particular application of the tech).
Nvidia has implemented it (in hardware) in some of its GPUs, and there are companies that use Nvidia’s GPUs to host open-weights models in such a way that (if the technology has been designed and implemented correctly—i.e., without any security holes) the hosting company cannot eavesdrop on the communications between the customer and the model. (The same basic technology—remote attestation—can be used for the purpose you want.) tinfoil.sh is one such company. I used Tinfoil just yesterday to have a enhanced-confidentiality chat with Kimi K3.
This post from 2 months ago gives an overview of the technology.
In a recent comment an expert on this technology (remote attestation) states that Nvidia’s implementation of the technology probably hasn’t been tested much yet, so there’s a good chance that there is some flaw in it that could be exploited with enough labor by experts. This is in contrast to Apple’s implementation, which is many years old at this point and has been looking quite solid for years. Nobody for example has published a jailbreak for a recent iPhone running a recent version of iOS and even though there is a lot of interest in iPhone jailbreaks and a lot of glory for anyone who manages to publish one.