Signs an immutable job
Container, entrypoint and every input are pinned by SHA-256 into a manifest with resource limits, checkpoint rules and an expiry, then signed with the publisher's hotkey.
Verifiable GPU training. Publishers sign the work, miners run it on H100s inside a sandbox, and validators score only what they can prove.
GPUForge is a proposed Bittensor subnet for verifiable GPU training. Anyone can say they have an H100. GPUForge checks the training that actually ran on one, and only verified results count.
Container, entrypoint and every input are pinned by SHA-256 into a manifest with resource limits, checkpoint rules and an expiry, then signed with the publisher's hotkey.
Miners report capabilities, supply hardware-backed attestation where supported, and run the pinned workload in an isolated, least-privilege sandbox.
Validators issue fresh challenges, check attestation, identity, correctness, freshness and throughput, and turn verified results into normalized weights.
No single software measurement proves a physical GPU or exact code execution on a hostile machine, so GPUForge stacks independent evidence layers. Switch layers off and watch the validator's receipt change.
Illustrative model of the documented fail-closed policy. Final scoring rules are still being defined.
Verified GPU attestation plus a verified host trust chain from another approved backend.
GPU-only NVIDIA attestation (NVAT): H100/Hopper, bound nonce, secure boot, debug off, valid signatures and measurements, fresh collateral.
Software discovery is always labelled self_reported. It proves who signed the claim, not that the GPU exists.
Messages use a strict canonical JSON profile: sorted keys, no whitespace, integers only, 64 KiB max. Edit this job manifest: the SHA-256 below is computed live in your browser, and the miner's verdict follows the rules in the repository.
………The SHA-256 is real: it runs over the versioned signing domain plus the canonical unsigned bytes. The signature itself is simulated.
The execution backend accepts only digest-pinned images and a bounded argument vector. Everything else is fixed by the launcher, and a timed-out container is killed and removed.
unconfinedSignatures cover a versioned signing domain, the message type, the protocol version and the canonical payload. Freshness uses bounded block windows, and a durable replay cache fails closed instead of evicting live entries.
What to run and under which limits.
container_digest · input_root · resource_policy · expires_at_blockSelf-reported GPU inventory with a fresh nonce.
gpu_model · gpu_memory_mb · supported_evidence_tiers · nonceA short-lived assignment with a challenge.
manifest_digest · challenge_commitment · deadline_blockSigned commitments to what ran.
attestation_digest · checkpoints · result_digest · work_unitsThe verdict, with reason codes.
accepted · reason_codes · verified_work_units · confidence_tierGPUForge is under active development. There is no supported miner or validator release yet, and interfaces, scoring rules and security assumptions may still change.
A preview of the network, miners, jobs and validators pages we plan to launch with. It runs on simulated data only; no miners are connected.

Your browser couldn't start WebGL, so the 3D tour is off. The rest of the page works normally.