danivilardell.bsky.social @danivilardell.bsky.social · 03/06/2026Our paper with formal analysis and code: arxiv.org/pdf/2606.03771 H/T to my co-authors Sam Breckenridge, Derek Leung, Andrés Fábrega, James Austgen, Farinaz Koushanfar, and Prof. Ari Juelsarxiv.org 021
danivilardell.bsky.social @danivilardell.bsky.social · 03/06/20265/ But LLMs open new attack surfaces. We formalize two: - A malicious prover could try to game a credential by manipulating their data (e.g. strategic purchases to inflate expertise). - A malicious model could try to leak private info, hiding a sensitive bit in output that looks benign. 110
danivilardell.bsky.social @danivilardell.bsky.social · 03/06/20264/ This also enables a new type of credentials: verifiable software audits. A company can prove its proprietary code satisfies a property — say, deleting payment-card numbers after processing — without revealing the source. 110
danivilardell.bsky.social @danivilardell.bsky.social · 03/06/20263/ 𝜋Creds use an LLM running inside a TEE to issue credentials over that unstructured data. That way, you can prove the richer claims, like real expertise in a product category from your purchase history, while the sensitive purchase transcript data remains private. 110
danivilardell.bsky.social @danivilardell.bsky.social · 03/06/20262/ Today's private credentials only handle simple predicates over structured data ("over 18," "balance > X"). But the richest signals (purchase histories, medical records, emails) are unstructured, and the interesting claims need semantic reasoning. So that information goes unused. 110
danivilardell.bsky.social @danivilardell.bsky.social · 03/06/20261/ Privacy-preserving credentials can prove you're over 18, but not much else. Our new research changes that. 𝜋Creds introduces verifiable credentials generated by trusted LLM inference over authenticated. 252