The record

Our work, in the open.

Every line below can be re-run by a stranger — and until a result carries its proof, it doesn't get a line.

In one breathIf a line is here, you can re-run it yourself. If it isn't proven, it isn't here.

sealed record
Sealed before launchfingerprint published first
The Open Ledger live
Sealed · public

The sealed challenge

We published several open AI models — one with a hidden trap inside — and dared the world to find it. Before it opened, we locked the answer in by publishing its fingerprint first, so nobody (us included) could quietly change it later. The usual scanners spot none of the traps.

See the challenge
Public

The catalogue of catches

A public list of the backdoored models we've caught — each with proof you can re-run yourself, shown next to how the usual scanners scored it. They miss every one. And where we've missed something, that's on the card too.

Browse the catalogue
In progress

The public exams

We grade ourselves on the same public tests researchers use — BackdoorLLM, ELBA-Bench, TrojAI, TDC2023 — and against the free scanners anyone can download. Scores post here with proof, failures included.

Check the scores yourself
Live

The continuous read

We're always reading the open AI models people actually download and use, and mapping them in a public library. When we find something real, the model's owner hears it first, in private. The record grows here.

The model library the owner hears it first, always · we read the whole field, not one file
The rule: a line shows up here only once its proof does. Silence means nothing's been proven — not that nothing's there.

In one sentence: we read what a model was trained to do — straight from its file — and prove it, or say we can't.