GPUFORGE SN47
Explorer demo Explore ↓
Bittensor · Subnet 47

GPUFORGE

Verifiable GPU training. Publishers sign the work, miners run it on H100s inside a sandbox, and validators score only what they can prove.

How verification works
01 Publish02 Execute03 Verify04 Weight
Scroll to run the protocol · drag to orbit
00 · What GPUForge is

Score the work, not the claim.

GPUForge is a proposed Bittensor subnet for verifiable GPU training. Anyone can say they have an H100. GPUForge checks the training that actually ran on one, and only verified results count.

Publisher

Signs an immutable job

Container, entrypoint and every input are pinned by SHA-256 into a manifest with resource limits, checkpoint rules and an expiry, then signed with the publisher's hotkey.

  • JobManifest
  • @sha256 only
  • expires_at_block
Miner

Runs it on H100 hardware

Miners report capabilities, supply hardware-backed attestation where supported, and run the pinned workload in an isolated, least-privilege sandbox.

  • CapabilityClaim
  • NVAT evidence
  • ExecutionEvidence
Validator

Verifies, then weights

Validators issue fresh challenges, check attestation, identity, correctness, freshness and throughput, and turn verified results into normalized weights.

  • WorkLease
  • ValidationReceipt
  • weights
0protocol stages, from signed job to published weight
0typed, signed message types in protocol v1
64KiBmaximum canonical message size
0points for evidence that is missing, stale or inconsistent
01 · Verification model

Layered evidence. Fail closed.

No single software measurement proves a physical GPU or exact code execution on a hostile machine, so GPUForge stacks independent evidence layers. Switch layers off and watch the validator's receipt change.

Scenario
ACCEPTED Tier A
minimum_evidence_tier

          

Illustrative model of the documented fail-closed policy. Final scoring rules are still being defined.

A

Tier A

Verified GPU attestation plus a verified host trust chain from another approved backend.

B

Tier B

GPU-only NVIDIA attestation (NVAT): H100/Hopper, bound nonce, secure boot, debug off, valid signatures and measurements, fresh collateral.

—

Self-reported

Software discovery is always labelled self_reported. It proves who signed the claim, not that the GPU exists.

02 · Canonical encoding

Change one byte. Break the seal.

Messages use a strict canonical JSON profile: sorted keys, no whitespace, integers only, 64 KiB max. Edit this job manifest: the SHA-256 below is computed live in your browser, and the miner's verdict follows the rules in the repository.

current block—
ACCEPTsignature matches canonical bytes
signed fingerprint…
current fingerprint…
canonical size…

The SHA-256 is real: it runs over the versioned signing domain plus the canonical unsigned bytes. The signature itself is simulated.

03 · Container isolation

Publisher code is untrusted input.

The execution backend accepts only digest-pinned images and a bounded argument vector. Everything else is fixed by the launcher, and a timed-out container is killed and removed.

  • LimitsPID · CPU · RAM · GPU · wall-time quotas
  • Privilegesnon-root user · capabilities dropped · no-new-privileges
  • Filesystemread-only root · bounded noexec, nosuid, nodev tmpfs
  • Network & IPCdefault-deny networking · IPC disabled
  • Kernel policyoperator seccomp / AppArmor, never unconfined
Refused at the door
host mountsraw devices:latest tagsruntime flagshost env varswallet pathscontainer socketsopen network
04 · Protocol v1

Five messages. Every one signed.

Signatures cover a versioned signing domain, the message type, the protocol version and the canonical payload. Freshness uses bounded block windows, and a durable replay cache fails closed instead of evicting live entries.

publisher

JobManifest

What to run and under which limits.

container_digest · input_root · resource_policy · expires_at_block
miner

CapabilityClaim

Self-reported GPU inventory with a fresh nonce.

gpu_model · gpu_memory_mb · supported_evidence_tiers · nonce
validator

WorkLease

A short-lived assignment with a challenge.

manifest_digest · challenge_commitment · deadline_block
miner

ExecutionEvidence

Signed commitments to what ran.

attestation_digest · checkpoints · result_digest · work_units
validator

ValidationReceipt

The verdict, with reason codes.

accepted · reason_codes · verified_work_units · confidence_tier
05 · Where it stands

Built in the open, gated on proof.

GPUForge is under active development. There is no supported miner or validator release yet, and interfaces, scoring rules and security assumptions may still change.

In the codebase today

  • Canonical protocol encoding, v1
  • Message authentication & block-window freshness
  • Bounded, fail-closed replay cache
  • Offline publisher packaging & signing
  • Content-addressed artifact integrity
  • Privacy-preserving capability discovery
  • Opt-in NVIDIA attestation adapter
  • Feature-gated Linux container backend

Gates before any network release

  • Complete protocol
  • Hardened sandbox
  • Adversarial test suite
  • Testnet acceptance criteria
Explorer design demo →

A preview of the network, miners, jobs and validators pages we plan to launch with. It runs on simulated data only; no miners are connected.

Not ready for miners, validators or production workloads. Don't run untrusted training jobs or use production wallet credentials with the current code.
GPUForge logo

Your browser couldn't start WebGL, so the 3D tour is off. The rest of the page works normally.