Artifact
nanogpt-provenance
A verifier re-derives a training run bit-for-bit; cross-hardware re-derivation stays UNKNOWN, not claimed.
What it establishes
A tamper-evident provenance record with a verifier that re-derives a training run's result bit-for-bit from recorded inputs and reports VERIFIED, TAMPERED or UNKNOWN, never silently upgrading UNKNOWN.
What it does not establish
Cross-hardware re-derivation, which is untested and reported UNKNOWN. It does not establish code correctness, buggy-but-faithful code still verifies, nor result quality nor accountability.
Method
The verifier re-runs training from the recorded configuration and compares the trajectory and final loss bit-for-bit under a matching numeric environment; a 12-case negative-control suite triggers each verdict state with a real tamper.
Results
On one machine, VERIFIED with final loss 0.10635284871660042 and fingerprint c6da865d, 12 of 12 controls; a re-derivation mismatch under a foreign environment returns UNKNOWN, not TAMPERED.
What has to be trusted
SHA-256 collision-resistance; the verifier's own CPython, NumPy, operating system and CPU; and that the verifier's numeric environment reproduces the record's, which is the weakest link.
Prior work
Provenance and reproducible builds; tamper-evident logs. The contribution is re-derivation rather than integrity-recheck, with an honest UNKNOWN exactly where reproducibility ends.