Package anchor
Weight Integrity
Question: Is this the intended model-weight artifact and has its integrity been preserved?
Model Weight Integrity & Trust/Governance · package anchor
A semantic anchor for the integrity, provenance, attestation, controlled movement, and verifiable use of machine-learning model weights.
Model weights can be high-value artifacts that are replicated, moved between environments, deployed, modified, substituted, exposed, or used for inference. This package supplies bounded public identities for discussing distinct security and governance questions around those artifacts.
Five-domain architecture
These identities are an LJP semantic organization, not a standards-defined lifecycle or universal implementation architecture. Each remains an independent identity.
Package anchor
Question: Is this the intended model-weight artifact and has its integrity been preserved?
Origin and lineage identity
Question: Where did this model-weight artifact originate and what is its relevant lineage or custody history?
Evidence and attestation identity
Question: What evidence or claims support assertions about the artifact or its relevant state and context?
Controlled-movement identity
Question: How is movement or export of the artifact across boundaries controlled?
Emerging verification and use identity
Question: What machine-evaluable evidence can support claims about inference execution or use of an intended model artifact?
Relationship model
Evidence boundary
| Identity | Evidence class | Authoritative basis | Boundary |
|---|---|---|---|
| Weight Integrity | C | RAND model-weight security research; public security practice | The exact LJP identity is not a standard. |
| Weight Provenance | C | C2PA AI/ML guidance | Provenance context does not establish this package role as a standard. |
| Weight Attestation | C | RFC 9334 attestation architecture | The compound identity is an LJP application, not a ratified term. |
| Weight Egress | C | Public model-weight security practice | Does not imply an LJP enforcement service. |
| Machine-Verifiable Inference | B | emerging verifiable-ML research | Not an adopted universal standard. |
Buyer walkthrough
Which artifact is protected, can provenance and integrity be evaluated, and how is movement bounded?
Which model artifact is deployed, what evidence accompanies it, and how are deployment boundaries governed?
What supports a claim about an artifact, what is independently inspectable, and what remains operational assertion?
Where are controls enforced, which systems remain replaceable, and which semantic identities persist across implementations?
Adjacent governance identities
These independent PKG7 identities are adjacent context, not components of the five-domain model-weight architecture.
Evaluation
Resources
RAND research and public model-security practices.
RFC 9334 provides its own general evidence and attestation architecture.
Verifiable-ML research frames an emerging technical direction.