Skip to content

AxiomLimit · AI inference · for a technical reader

Where deletion receipts can be fooled: the lab’s exact wording

The lab’s own sentences and figures for this result, word for word, in its working terms, with its limits in plain words where the lab’s text cannot be reprinted. The plain account is on the result’s page; it says the same things in plain words.

The lab’s plain-English sentence

…the lab wrote two checkers for a "deletion receipt" (a signed note saying the data was destroyed) and, on a small setup built over an ordinary shared file rather than an AI serving system, showed six concrete ways such a receipt can check out while the data is still recoverable or was never deleted

  • including one where both of its checkers accept a receipt from a colluding auditor when nothing was erased

In the lab’s words

the campaign publishes six demonstrated limits

The limit to read first, in the lab’s words

SIM-ONLY over an mmap file

Part of the lab’s record (claim and limits) is not reprinted here because it names internal files this site does not publish or uses internal working terms.

All resultsFormal statements

How we show numbers

Every number on this site links to the file it comes from. How each result is checked

  • We never show a number before its file has loaded.
  • A question we have not checked yet is marked as unchecked.
  • A check that found nothing says so.
  • A file with no value for a question says so.
  • A number whose file is missing or has changed is not shown.
  • Two files that disagree about what a number describes are both flagged.
  • A number from too few samples shows its sample size.
  • Two files that give different values are both shown.
  • A file we cannot publish is listed by its fingerprint only.
  • A measurement more than a week old shows its age.
  • A question that does not apply to a page is left off it.
  • A measurement whose program failed is shown as failed.