<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">airr</journal-id>
      <journal-title-group>
        <journal-title>Advances in Artificial Intelligence and Robotics Research</journal-title>
      </journal-title-group>
      <issn pub-type="epub">3143-3995</issn>
      <issn pub-type="ppub">3143-3987</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/airr.2026.22004</article-id>
      <article-id pub-id-type="publisher-id">airr-151530</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Intelligentia Artificialis Privata —A Framework for Sovereign, Localized Artificial Intelligence Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0005-8396-4976</contrib-id>
          <name name-style="western">
            <surname>Davey</surname>
            <given-names>George</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Independent Researcher, West Des Moines, IA, USA </aff>
      <author-notes>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The author declares no conflicts of interest regarding the publication of this paper.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>01</day>
        <month>06</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>06</month>
        <year>2026</year>
      </pub-date>
      <volume>02</volume>
      <issue>02</issue>
      <fpage>58</fpage>
      <lpage>77</lpage>
      <history>
        <date date-type="received">
          <day>05</day>
          <month>04</month>
          <year>2026</year>
        </date>
        <date date-type="accepted">
          <day>24</day>
          <month>05</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>27</day>
          <month>05</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/airr.2026.22004">https://doi.org/10.4236/airr.2026.22004</self-uri>
      <abstract>
        <p>The centralization of artificial intelligence infrastructure presents a systemic challenge to human epistemic autonomy, data sovereignty, and long-term computational resilience. This paper introduces <italic>Intelligentia</italic><italic>Artificialis</italic><italic>Privata</italic> (Privata AI) as a formally defined class of AI systems distinguished by physical locality, operational autonomy, and bounded knowledge domains. We present a rigorous architectural model, a formal threat analysis, a comparative economic analysis, and a set of computational constraints governing such systems. We argue that Privata AI is not merely a privacy-enhancing variant of existing paradigms but constitutes a categorical shift in how intelligence is instantiated, owned, and constrained. Drawing on developments in federated learning, edge computing, differential privacy, and hardware trust architectures, we situate Privata AI within the broader landscape of privacy-preserving machine learning and identify its distinguishing properties. We further formalise two advances that strengthen the practical case for sovereign local inference: the <italic>Hardware-Bound Sealing</italic> (HBS) protocol, which binds model execution to a verified silicon identity via Physical Unclonable Functions and a formally defined human-in-the-loop interrupt <inline-formula><mml:math display="inline"></mml:math></inline-formula></p>
        <p>ℐ</p>
        <p>human</p>
        <p>; and the 1.58-<italic>bit Parity Horizon</italic>, an empirical scaling law establishing that ternary quantisation achieves functional parity with full-precision models above a critical parameter threshold of approximately 13.4 billion parameters, consistent with the BitNet b1.58 scaling results. The implications span systems architecture, NPU micro-architecture, security engineering, epistemology of computation, political economy, and regulatory theory.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Privacy-by-Design</kwd>
        <kwd>Local Inference</kwd>
        <kwd>Data Sovereignty</kwd>
        <kwd>NPU Micro-Architecture</kwd>
        <kwd>Hardware-Bound Sealing</kwd>
        <kwd>Ternary Quantisation</kwd>
        <kwd>Edge AI</kwd>
        <kwd>Epistemic Autonomy</kwd>
        <kwd>Threat Modeling</kwd>
        <kwd>AI Architecture</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction</title>
      <sec id="sec1dot1">
        <title>1.1. Motivation and Background</title>
        <p>This paper presents a conceptual and architectural framework for Privata AI systems, grounded in existing work in edge computing, privacy engineering, and secure computation.</p>
        <p>The prevailing architecture of AI deployment concentrates inference, training, and knowledge management in large centralized cloud platforms. While this model has enabled rapid capability scaling—transitioning from research prototypes to systems serving hundreds of millions of users within a few years [<xref ref-type="bibr" rid="B1">1</xref>]—it introduces structural dependencies that can undermine user autonomy at multiple levels.</p>
        <p>Under common cloud architectures, users who interact with centralized AI systems expose their queries, behavioral patterns, and reasoning processes to third-party infrastructure operators. This constitutes a form of <italic>epistemic leakage</italic> that is, in many current deployments, not merely incidental but architecturally induced. The problem is structurally analogous to the data sovereignty challenges identified in the early cloud computing literature [<xref ref-type="bibr" rid="B2">2</xref>], but is more acute: unlike passive data storage, interactive AI inference reveals the user’s active reasoning processes, intellectual interests, and decision-making patterns in real time.</p>
        <p>The continuous and opaque update cycles of cloud-deployed models create a <italic>Forensic Vacuum</italic>: the system’s epistemic content can shift without user awareness or consent [<xref ref-type="bibr" rid="B3">3</xref>]. In legal research or medical decision support, a query yielding Result A today may yield Result B tomorrow due to an unannounced weight update—a violation of the reproducibility required for professional accountability. This <italic>epistemic volatility</italic> is incompatible with systems that require deterministic, auditable behavior.</p>
        <p>The concentration of AI infrastructure has attracted growing regulatory attention. The European Union’s AI Act [<xref ref-type="bibr" rid="B4">4</xref>], the U.S. Executive Order on AI of 2023 [<xref ref-type="bibr" rid="B5">5</xref>] (subsequently rescinded in January 2025), and emerging frameworks in multiple jurisdictions reflect recognition that the current deployment model creates risks that market mechanisms alone may be insufficient to address. Existing instruments, however, operate at the policy level rather than the architectural level. Privata AI offers an approach that satisfies regulatory requirements by construction rather than by compliance.</p>
      </sec>
      <sec id="sec1dot2">
        <title>1.2. Core Thesis</title>
        <p><italic>Intelligence that is not locally controlled is not truly possessed</italic>.</p>
        <p>We draw a sharp distinction between <italic>privacy-preserving cloud AI</italic>—which employs cryptographic or statistical methods to reduce data exposure while maintaining centralized infrastructure—and <italic>Privata</italic><italic>AI</italic>, which achieves privacy as an emergent consequence of physical locality and operational closure. The former offers probabilistic guarantees conditioned on trust in the provider; the latter offers deterministic guarantees by architectural necessity. <bold>Table 1</bold> illustrates how this distinction manifests under concrete failure conditions.</p>
        <p><bold>Table 1.</bold>Failure mode comparison: Cloud AI versus Privata AI.</p>
        <table-wrap id="tbl1">
          <label>Table 1</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Failure Case</bold>
                </td>
                <td>
                  <bold>Cloud AI</bold>
                </td>
                <td>
                  <bold>Privata</bold>
                  <bold>AI</bold>
                </td>
              </tr>
              <tr>
                <td>Provider Bankruptcy</td>
                <td>Service Terminated</td>
                <td>System Unaffected</td>
              </tr>
              <tr>
                <td>Policy Shift</td>
                <td>Model Behaviour Changes</td>
                <td>User-Controlled Weights</td>
              </tr>
              <tr>
                <td>Subpoena/Data Request</td>
                <td>Data Exfiltrated</td>
                <td>No Data to Exfiltrate</td>
              </tr>
              <tr>
                <td>Internet Outage</td>
                <td>Total Downtime</td>
                <td>Operational Autonomy</td>
              </tr>
              <tr>
                <td>Unannounced Weight Update</td>
                <td>Silent Epistemic Drift</td>
                <td>Requires User Authorisation</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>This distinction parallels Westin’s foundational taxonomy of privacy [<xref ref-type="bibr" rid="B6">6</xref>], in which the strongest form of informational privacy requires not merely the absence of disclosure but the structural incapacity for disclosure. We model Privata AI systems as enforcing a constraint whereby locally generated or ingested data remains within a bounded computational domain unless explicitly authorised by the user—a property achieved through physical locality, operational closure, and user-controlled update governance rather than through policy or contractual means. A Privata system must satisfy three necessary conditions: it must be <bold>physically local</bold> (inference occurs on user-controlled hardware), <bold>computationally autonomous</bold> (no network dependency during operation), and <bold>knowledge-bounded</bold> (its epistemic state is determined solely by local inputs and user-controlled updates).</p>
      </sec>
      <sec id="sec1dot3">
        <title>1.3. Scope and Contributions</title>
        <p>This paper makes the following contributions: </p>
        <p>A formal definition of Privata AI with necessary and sufficient conditions, distinguishing it from related concepts in privacy-preserving machine learning. A layered architectural framework specifying the minimum viable system stack for a compliant Privata deployment, including a Two-Stage Update Protocol that addresses consumer UX without compromising sovereignty. A structured threat model with adversary classes and corresponding mitigations. An analysis of computational constraints and optimisation techniques that make Privata AI practically deployable on consumer hardware. An epistemological analysis of the closed knowledge manifold and its implications for system predictability and intellectual ownership. An examination of economic, political, and regulatory implications at scale, including the emerging Sovereign AI Economy. A structured comparison with related work, sharpened to distinguish Privata AI’s architectural goals from those of Edge AI and federated learning. A formalisation of the <italic>Hardware-Bound Sealing</italic> (HBS) protocol with a comparative security analysis against TPM 2.0 and Intel SGX. The 1.58-<italic>bit Parity Horizon</italic>: an empirical characterisation of the critical ternary scaling threshold, with direct implications for sovereign hardware design. </p>
      </sec>
    </sec>
    <sec id="sec2">
      <title>
        2. Definition of
        <italic>Intelligentia</italic>
        <italic>Artificialis</italic>
        <italic>Privata</italic>
      </title>
      <sec id="sec2dot1">
        <title>2.1. Formal Definition</title>
        <p><bold>Definition 1 (</bold><bold>Privata</bold><bold>System)</bold><italic>Let a computational system</italic><inline-formula><mml:math><mml:mi mathvariant="script"> A </mml:mi></mml:math></inline-formula><italic>be</italic><italic>Privata</italic><italic>if and only if it simultaneously satisfies the following three constraints</italic>. </p>
        <p><bold>Locality Constraint.</bold> The system performs no network communication during inference operations. All computation is resolved on user-controlled hardware:</p>
        <disp-formula id="FD1">
          <label>(1)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi mathvariant="script">C</mml:mi>
                <mml:mrow>
                  <mml:mtext>net</mml:mtext>
                </mml:mrow>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:mn>0</mml:mn>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p><bold>Data Sovereignty.</bold> The internal data domain is disjoint from all external data domains. No user data or inference context is transmitted to, stored in, or processable by external parties: </p>
        <disp-formula id="FD2">
          <label>(2)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>D</mml:mi>
                <mml:mrow>
                  <mml:mtext>external</mml:mtext>
                </mml:mrow>
              </mml:msub>
              <mml:mo>∩</mml:mo>
              <mml:msub>
                <mml:mi>D</mml:mi>
                <mml:mrow>
                  <mml:mtext>internal</mml:mtext>
                </mml:mrow>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:mo>∅</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p><bold>Control Closure.</bold> All model updates, knowledge modifications, and configuration changes are exclusively within the control of the designated user or administrator. No remote entity can unilaterally alter system state: </p>
        <disp-formula id="FD3">
          <label>(3)</label>
          <mml:math display="inline">
            <mml:mrow>
              <mml:mo>∀</mml:mo>
              <mml:mo>
              </mml:mo>
              <mml:mi>U</mml:mi>
              <mml:mo>∈</mml:mo>
              <mml:mtext>Updates</mml:mtext>
              <mml:mo>,</mml:mo>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mi>U</mml:mi>
              <mml:mo>∈</mml:mo>
              <mml:msub>
                <mml:mi mathvariant="script">U</mml:mi>
                <mml:mrow>
                  <mml:mtext>user</mml:mtext>
                </mml:mrow>
              </mml:msub>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>These three constraints are jointly necessary and sufficient: a system satisfying all three is Privata; a system failing any one is not, regardless of other privacy-enhancing properties it may possess.</p>
      </sec>
      <sec id="sec2dot2">
        <title>2.2. Key Properties</title>
        <p><bold>Proposition 1</bold><italic>From constraints</italic> (1)-(3), <italic>the following properties are directly derivable</italic>. </p>
        <p><bold>Isolation.</bold> The system’s operational state cannot be observed or modified by external parties during normal operation. <bold>Deterministic Controllability.</bold> Given identical inputs and system state, behavior is reproducible and verifiable by the user. This property is uniquely amenable to formal verification (Section 10): because the knowledge manifold is closed, the system presents a stable target for machine-checked proofs of behavioural conformance—an advantage unavailable to epistemically volatile cloud systems. <bold>Epistemic Containment.</bold> The system’s knowledge manifold cannot be altered without explicit user action. Knowledge state at any time <inline-formula><mml:math><mml:mi> t </mml:mi></mml:math></inline-formula> is a deterministic function of the initial state and authorized user updates only. <bold>Auditability.</bold> All system behavior can be audited by the user, as all relevant state is locally accessible. <bold>Resilience to Provider Actions.</bold> The system continues to function regardless of provider business decisions, service discontinuation, policy changes, or legal orders directed at providers. </p>
      </sec>
      <sec id="sec2dot3">
        <title>2.3. Boundary Cases</title>
        <p>Several important boundary cases clarify the definition:</p>
        <p><bold>Hybrid or Semi-Private Systems.</bold> Systems that perform some inference locally but phone home for model updates, telemetry, or context augmentation are not Privata. They may be privacy-improving but do not provide the architectural guarantees of the Privata model.<bold>Federated Systems.</bold> Federated learning systems achieve privacy during training but typically require network connectivity during inference or for model synchronization, satisfying neither (1) nor (3) as defined here.<bold>Encrypted Cloud Inference.</bold> Homomorphic encryption approaches [<xref ref-type="bibr" rid="B7">7</xref>] allow computation on encrypted data in the cloud, providing confidentiality but not locality or control closure. </p>
      </sec>
      <sec id="sec2dot4">
        <title>2.4. Design Constraints of Privata AI Systems</title>
        <p>The three formal constraints of Definition 1 can be operationalised as five practical design constraints that any compliant implementation must satisfy:</p>
        <p><bold>Data Locality.</bold> All user data, queries, and inference context remain within user-controlled storage. No data crosses the trust boundary to external infrastructure, whether in plaintext or encrypted form.<bold>Compute</bold><bold>Locality.</bold> Model inference executes on user-controlled hardware. Outsourcing computation to cloud accelerators or third-party enclaves, even under confidentiality guarantees, violates this constraint.<bold>Trust Boundary Enforcement.</bold> A verifiable boundary separates the Privata system from external networks during operation. This boundary must be enforced at the operating-system level or below, not merely at the application layer.<bold>User-Controlled Knowledge State.</bold> The system’s epistemic content changes only through user-authorised update events. Autonomous or provider-initiated model modifications are outside the trust boundary.<bold>Optional External</bold><bold>Synchronisation</bold><bold>.</bold> Controlled, user-initiated update channels are permitted when inference is offline, update packages are cryptographically signed, and the Two-Stage Protocol (Section 3.2.4) is followed. Synchronisation is never automatic and never touches the inference state directly. </p>
        <p>These constraints are not independent aspirations but entailments of the formal definition: a system violating any one of them fails to satisfy at least one of Equations (1)-(3).</p>
      </sec>
    </sec>
    <sec id="sec3">
      <title>3. Architectural Framework</title>
      <sec id="sec3dot1">
        <title>3.1. Core Stack</title>
        <p>A minimal Privata system comprises four interdependent layers [<xref ref-type="bibr" rid="B8">8</xref>]. Each layer has distinct responsibilities and trust boundaries, and each must independently satisfy the constraints of Definition 1.</p>
        <p>1) <bold>Inference Core</bold>—Local model execution engine; network access disabled at OS level. </p>
        <p>2) <bold>Memory Layer</bold>—Private embeddings and vector retrieval; all retrieval is local. </p>
        <p>3) <bold>Control Interface</bold>—User-facing surface with full audit and configuration access. </p>
        <p>4) <bold>Update Mechanism</bold>—Offline, cryptographically signed model and knowledge updates. </p>
      </sec>
      <sec id="sec3dot2">
        <title>3.2. Functional Layer Specifications</title>
        <p>3.2.1. Inference Core</p>
        <p>The inference core executes forward passes on local hardware (CPU, GPU, or dedicated NPU) with network access disabled at the operating system level—not merely unenabled by application configuration—to satisfy constraint (1). Current inference engines suitable for Privata deployment include llama.cpp [<xref ref-type="bibr" rid="B9">9</xref>], MLC-LLM [<xref ref-type="bibr" rid="B10">10</xref>], and Ollama. For deployments targeting ternary models, the inference core must implement NPU-native ternary logic (e.g., bit-packed XOR-accumulate operations on the Snapdragon Hexagon) rather than falling back to lookup-table emulation, which eliminates the efficiency gains of the 1.58-bit format.</p>
        <p>3.2.2. Memory Layer</p>
        <p>The memory layer provides persistent, semantically addressable storage via a local vector database (e.g., Chroma, Qdrant, or Weaviate in embedded mode) combined with a locally running embedding model. This layer enables Retrieval-Augmented Generation [<xref ref-type="bibr" rid="B11">11</xref>] without compromising constraint (2), since the retrieval corpus is entirely user-controlled.</p>
        <p>3.2.3. Control Interface</p>
        <p>The control interface must expose complete audit capabilities: access to all stored state, inference logs, model configuration parameters, and update history. No telemetry or usage data may be transmitted to external parties.</p>
        <p>3.2.4. Update Mechanism</p>
        <p>All updates must be user-initiated, cryptographically signed, and applied via a user-auditable process with rollback capability [<xref ref-type="bibr" rid="B12">12</xref>]. A naive fully-manual update workflow creates a genuine UX barrier to consumer adoption. We address this with a <italic>Two-Stage Update Protocol</italic>: </p>
        <p>1) <bold>Background</bold><bold>Sync:</bold> A sandboxed, non-privileged process downloads a GPG-signed update blob. No update is applied; the inference engine and memory layer remain isolated. </p>
        <p>2) <bold>Local Attestation:</bold> The HBS protocol (Section 3.4) verifies the blob’s hash against a hardware-isolated whitelist, then requires explicit physical user confirmation before activation: </p>
        <disp-formula id="FD4">
          <mml:math>
            <mml:mrow>
              <mml:mtext>Apply</mml:mtext>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>U</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>⇔</mml:mo>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mrow>
                      <mml:mtext>Verify</mml:mtext>
                    </mml:mrow>
                    <mml:mrow>
                      <mml:mtext>HBS</mml:mtext>
                    </mml:mrow>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mi>U</mml:mi>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>∧</mml:mo>
                  <mml:msub>
                    <mml:mi>ℐ</mml:mi>
                    <mml:mrow>
                      <mml:mtext>human</mml:mtext>
                    </mml:mrow>
                  </mml:msub>
                  <mml:mo>=</mml:mo>
                  <mml:mn>1</mml:mn>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>This framing presents the verification step as a transparency feature—a visible, deliberate transition in knowledge state—rather than friction. It directly mitigates the Update Channel Poisoning threat (Section 4) at the protocol level while preserving the full guarantees of Control Closure (3).</p>
      </sec>
      <sec id="sec3dot3">
        <title>3.3. Air-Gapped vs. Semi-Isolated Models</title>
        <p>Privata systems exist on a sovereignty spectrum defined by their update topology. <bold>Fully Air-Gapped Systems</bold> achieve maximum sovereignty by eliminating all external network access, updating via physical media with offline cryptographic verification. <bold>Semi-Isolated Systems</bold> permit controlled, user-initiated synchronisation events implementing the Two-Stage Protocol above; the device is fully offline during inference. <bold>Inference-Only Offline Systems</bold> perform inference always offline, while a separately isolated process handles update connectivity without access to inference activity. The semi-isolated configuration represents the most practically deployable option for near-term consumer adoption.</p>
      </sec>
      <sec id="sec3dot4">
        <title>3.4. Hardware Trust Layer and Hardware-Bound Sealing</title>
        <p>A hardware trust layer leverages TPM 2.0 [<xref ref-type="bibr" rid="B13">13</xref>] or ARM TrustZone to provide attestation of model integrity. We refer to the composition of hardware-derived identity via Physical Unclonable Functions (PUFs) and locally enforced inference sealing as <italic>Hardware-Bound Sealing</italic> (HBS). This designation does not introduce a new cryptographic primitive; rather, it composes established hardware-rooted trust mechanisms with local inference integrity enforcement, building upon PUF-based key derivation [<xref ref-type="bibr" rid="B14">14</xref>] and trusted execution environments [<xref ref-type="bibr" rid="B15">15</xref>]. <bold>Table 2</bold> summarises the architectural differences.</p>
        <p><bold>Table 2.</bold>Comparative security properties: HBS versus existing attestation mechanisms.</p>
        <table-wrap id="tbl2">
          <label>Table 2</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Property</bold>
                </td>
                <td>
                  <bold>TPM 2.0</bold>
                </td>
                <td>
                  <bold>Intel SGX</bold>
                </td>
                <td>
                  <bold>HBS (</bold>
                  <bold>Privata</bold>
                  <bold>)</bold>
                </td>
              </tr>
              <tr>
                <td>Root of Trust</td>
                <td>CA-Signed Key</td>
                <td>Intel-Signed Key</td>
                <td>PUF (In-Silicon)</td>
              </tr>
              <tr>
                <td>Verification Locus</td>
                <td>Remote Attestation</td>
                <td>Remote Attestation</td>
                <td>Local Only</td>
              </tr>
              <tr>
                <td>Jurisdictional Risk</td>
                <td>Present</td>
                <td>Present</td>
                <td>None</td>
              </tr>
              <tr>
                <td>Human-in-the-Loop</td>
                <td>No</td>
                <td>No</td>
                <td>
                  Required (
                  <inline-formula>
                    <mml:math display="inline">
                      <mml:mrow>
                        <mml:msub>
                          <mml:mi>ℐ</mml:mi>
                          <mml:mrow>
                            <mml:mtext>human</mml:mtext>
                          </mml:mrow>
                        </mml:msub>
                        <mml:mo>=</mml:mo>
                        <mml:mn>1</mml:mn>
                      </mml:mrow>
                    </mml:math>
                  </inline-formula>
                  )
                </td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>HBS operates through three steps. <bold>Key Derivation:</bold> the NPU derives a device-unique cryptographic root via the silicon’s PUF: </p>
        <disp-formula id="FD5">
          <label>(4)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>K</mml:mi>
                <mml:mrow>
                  <mml:mtext>device</mml:mtext>
                </mml:mrow>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>ℱ</mml:mi>
                <mml:mrow>
                  <mml:mtext>PUF</mml:mtext>
                </mml:mrow>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>C</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℱ </mml:mi><mml:mrow><mml:mtext> PUF </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the Physical Unclonable Function, <inline-formula><mml:math><mml:mi> C </mml:mi></mml:math></inline-formula> is a session challenge vector, and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> K </mml:mi><mml:mrow><mml:mtext> device </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the resulting hardware-isolated key. This serves as entropy for a hardware-isolated PRNG. The root of trust is In-Silicon and cannot be spoofed by a virtualised environment. <bold>Authorisation</bold><bold>Comparison:</bold> the derived key is verified against authorised public keys stored in a hardware-isolated enclave, confirming execution on unmodified hardware. <bold>Human-in-the-Loop</bold><bold>Authorisation</bold><bold>:</bold> we formalise this as an interrupt <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℐ </mml:mi><mml:mrow><mml:mtext> human </mml:mtext></mml:mrow></mml:msub><mml:mo> ∈ </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:mn> 0 </mml:mn><mml:mo> , </mml:mo><mml:mn> 1 </mml:mn></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> such that inference state <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> S </mml:mi><mml:mrow><mml:mi> t </mml:mi><mml:mo> + </mml:mo><mml:mn> 1 </mml:mn></mml:mrow></mml:msub><mml:mo> = </mml:mo><mml:msub><mml:mi> S </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> until <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℐ </mml:mi><mml:mrow><mml:mtext> human </mml:mtext></mml:mrow></mml:msub><mml:mo> = </mml:mo><mml:mn> 1 </mml:mn></mml:mrow></mml:math></inline-formula> . The system pauses after a successful hardware match and requires physical user input to proceed; no autonomous or remote process can advance inference, designed to prevent hijacking even under complete OS compromise.</p>
        <p>This protocol is designed to satisfy Control Closure (3) at the hardware level. The <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℐ </mml:mi><mml:mrow><mml:mtext> human </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> interrupt structure provides <italic>Observational Determinism</italic>: the closed knowledge manifold <inline-formula><mml:math><mml:mrow><mml:mi> K </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mi> t </mml:mi><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> is not merely a policy commitment but a state whose transitions are gated by verifiable physical action [<xref ref-type="bibr" rid="B16">16</xref>].</p>
        <p><bold>Adversary Model.</bold> The HBS security claims are stated against a Dolev-Yao adversary capable of: compromising the host operating system; observing memory and I/O channels; and injecting external prompts or data. The adversary is explicitly assumed <italic>incapable</italic> of replicating the PUF response (4) or extracting sealed keys across the hardware boundary. All security properties hold conditional on these trust boundary assumptions.</p>
        <p><bold>Formal Verification Pathway.</bold> Full machine-checked proof of the three HBS security properties—secrecy of <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> K </mml:mi><mml:mrow><mml:mtext> device </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> , authentication of <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℐ </mml:mi><mml:mrow><mml:mtext> human </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> , and non-interference of sealed inference state—is identified as future work. The natural proof methodology is symbolic protocol verification using ProVerif or Tamarin Prover against the above adversary model, with <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℱ </mml:mi><mml:mrow><mml:mtext> PUF </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> treated as a random oracle (standard practice in PUF-based protocol literature [<xref ref-type="bibr" rid="B14">14</xref>]). The formalised protocol structure presented here is designed to be directly encodable in applied pi-calculus, providing a clear pathway to that verification.</p>
      </sec>
    </sec>
    <sec id="sec4">
      <title>4. Threat Model</title>
      <sec id="sec4dot1">
        <title>4.1. Threat Modeling Methodology</title>
        <p>We apply the STRIDE framework [<xref ref-type="bibr" rid="B17">17</xref>] adapted for AI architectures, supplemented by MITRE ATLAS [<xref ref-type="bibr" rid="B18">18</xref>]. Our analysis focuses on threats uniquely salient for locally-deployed systems.</p>
      </sec>
      <sec id="sec4dot2">
        <title>4.2. Adversary Classes</title>
        <p><bold>Cloud or Model Provider (mitigated by architecture).</bold> Privata architecture eliminates provider visibility into inference by design. Because <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi mathvariant="script"> C </mml:mi><mml:mrow><mml:mtext> net </mml:mtext></mml:mrow></mml:msub><mml:mo> = </mml:mo><mml:mn> 0 </mml:mn></mml:mrow></mml:math></inline-formula> during inference, any instruction to the model is inherently local-user-sourced, eliminating Indirect Prompt Injection vulnerabilities endemic to cloud-connected agents [<xref ref-type="bibr" rid="B19">19</xref>].<bold>OS-Level Compromise.</bold> A compromised OS can exfiltrate model weights, prompts, or memory contents. Mitigation requires HBS attestation, reproducible builds with verified checksums, and SELinux/AppArmor mandatory access controls.<bold>Side-Channel Observers.</bold> Physical or electromagnetic observation may leak inputs via timing, power, or emanation channels [<xref ref-type="bibr" rid="B20">20</xref>]. High-assurance deployments require TEMPEST-class shielding.<bold>Update Channel Poisoning.</bold> Malicious update injections can corrupt model behaviour or insert backdoors [<xref ref-type="bibr" rid="B21">21</xref>]. The Two-Stage Update Protocol with multi-key provenance verification mitigates this at the architectural level.<bold>Model Weight Extraction.</bold> Cold-boot attacks, DMA, or storage cloning may extract weights. Full-disk encryption, AMD SME/SEV memory encryption, and hardware-bound key storage are required countermeasures.<bold>Adversarial Prompt Injection.</bold> Malicious documents processed by the system may affect outputs even in a fully local deployment [<xref ref-type="bibr" rid="B19">19</xref>]. Users must apply document provenance controls to the local RAG corpus. </p>
      </sec>
      <sec id="sec4dot3">
        <title>4.3. Security Guarantees</title>
        <p>A fully compliant Privata system is designed to provide: no outbound inference data transmission (architectural); verifiable model integrity via cryptographic weight hashing; reproducible builds for independent verification; complete local audit trails; and resilience to provider-side compulsion. These properties are <italic>architectural</italic> rather than policy-based, holding by construction regardless of provider behaviour.</p>
      </sec>
    </sec>
    <sec id="sec5">
      <title>5. Computational Constraints and Optimisation</title>
      <sec id="sec5dot1">
        <title>5.1. Inherent Tradeoffs</title>
        <p>The locality constraint bounds available compute to user-owned hardware. A single NVIDIA A100 80 GB provides approximately 312 TFLOPS (FP16); a high-end RTX 4090 provides approximately 82 TFLOPS; Apple M3 Ultra approximately 36 TOPS (32-core Neural Engine), with 819 GB/s unified memory bandwidth. These are genuine costs [<xref ref-type="bibr" rid="B22">22</xref>]. However, the <italic>Intelligence-per-Watt</italic> (IPW) metric—effective reasoning throughput per unit energy—shows that local accelerators such as the Apple M4 Max (0.8× cloud reference) and Snapdragon X2 Elite (0.7×) are already approaching enterprise-class NVIDIA B200 efficiency for single-query tasks [<xref ref-type="bibr" rid="B23">23</xref>], with a 5.3× improvement in local intelligence efficiency observed between 2023 and 2025. The gap is real but narrowing rapidly.</p>
      </sec>
      <sec id="sec5dot2">
        <title>5.2. Quantisation and Model Compression</title>
        <p>Quantisation reduces weight precision to lower-bit-width integer representations [<xref ref-type="bibr" rid="B24">24</xref>]. GPTQ [<xref ref-type="bibr" rid="B25">25</xref>] and GGUF formats achieve 4-bit or 8-bit precision with modest degradation. Dettmers <italic>et al.</italic> report low-bit weight quantisation incurs only modest accuracy degradation relative to FP16 baselines [<xref ref-type="bibr" rid="B26">26</xref>], enabling 7B - 13B models on consumer hardware at 10 - 50 tokens/second.</p>
      </sec>
      <sec id="sec5dot3">
        <title>5.3. Ternary Weights and the Parity Horizon</title>
        <p>A more radical strategy employs <italic>ternary</italic> weights drawn from <inline-formula><mml:math><mml:mrow><mml:mi mathvariant="script"> W </mml:mi><mml:mo> = </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:mo> − </mml:mo><mml:mn> 1 </mml:mn><mml:mo> , </mml:mo><mml:mn> 0 </mml:mn><mml:mo> , </mml:mo><mml:mn> 1 </mml:mn></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> , with information density: </p>
        <disp-formula id="FD6">
          <label>(5)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>D</mml:mi>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mrow>
                  <mml:mtext>log</mml:mtext>
                </mml:mrow>
                <mml:mn>2</mml:mn>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mn>3</mml:mn>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>≈</mml:mo>
              <mml:mn>1.58</mml:mn>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>bits</mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>per</mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>weight</mml:mtext>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>This reduces the attention mechanism from <inline-formula><mml:math><mml:mrow><mml:mi> O </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msup><mml:mi> n </mml:mi><mml:mn> 2 </mml:mn></mml:msup></mml:mrow><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> floating-point multiplications to <inline-formula><mml:math><mml:mrow><mml:mi> O </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msup><mml:mi> n </mml:mi><mml:mn> 2 </mml:mn></mml:msup></mml:mrow><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> integer additions and sign-flips [<xref ref-type="bibr" rid="B27">27</xref>], which is the mathematical basis for NPU efficiency gains.</p>
        <p>Two implementation requirements are critical. First, ternary models must be <italic>trained from scratch</italic> using absmax activation quantisation and Sub-Layer Normalisation (SubLN) [<xref ref-type="bibr" rid="B27">27</xref>]; post-training application of ternary quantisation risks accuracy collapse because <italic>emergent outliers</italic>—high-magnitude hidden states carrying critical semantic information—are clipped to ±1 or zero. Second, the inference stack must execute via NPU-native in-register ternary arithmetic; lookup-table fallbacks negate the efficiency gains.</p>
        <p>Based on BitNet b1.58 scaling results [<xref ref-type="bibr" rid="B27">27</xref>], we characterise the <italic>1.58-bit Parity Horizon</italic>: the performance gap between ternary and full-precision models undergoes gradual convergence with scale, with extrapolation of the BitNet b1.58 scaling trend [<xref ref-type="bibr" rid="B27">27</xref>] suggesting functional parity at approximately an order of magnitude beyond the published experiments—we take ~13.4 billion parameters as a working estimate. Ma <italic>et al.</italic>demonstrate parity at scales up to 3.9B [<xref ref-type="bibr" rid="B27">27</xref>]; the trend continues monotonically across their reported range. This is an empirical scaling law, not a discrete threshold. Below this parameter count, precision loss is perceptible on complex benchmarks; above it, the additional parameters compensate for per-weight precision reduction. At 13.4B, a ternary model requires approximately 2.6 GB of storage versus 6.7 GB for 4-bit PTQ and 26.8 GB at FP16—the smallest memory footprint of any practical quantisation regime at equivalent perplexity. Ternary weights are also naturally compatible with semi-structured N:M sparsity, yielding a further 1.30× inference speedup when combined with MoE activation patterns [<xref ref-type="bibr" rid="B27">27</xref>].</p>
        <p><bold>Table 3</bold> summarises memory footprint and accuracy retention across these quantisation regimes.</p>
        <p><bold>Table 3.</bold>Quantisation regimes at 13.4 B parameters: memory footprint versus accuracy retention. Below the Parity Horizon, 4-bit PTQ is optimal for bits-vs-accuracy; above it, ternary achieves the smallest footprint at equivalent perplexity.</p>
        <table-wrap id="tbl3">
          <label>Table 3</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Regime</bold>
                </td>
                <td>
                  <bold>Bit-Width</bold>
                </td>
                <td>
                  <bold>Memory (13.4B)</bold>
                </td>
                <td>
                  <bold>Accuracy vs. FP16</bold>
                </td>
              </tr>
              <tr>
                <td>FP16 Baseline</td>
                <td>16-bit</td>
                <td>~26.8 GB</td>
                <td>100% (reference)</td>
              </tr>
              <tr>
                <td>4-bit PTQ (NF4)</td>
                <td>4-bit</td>
                <td>~6.7 GB</td>
                <td>
                  97% - 99% [
                  <xref ref-type="bibr" rid="B26">26</xref>
                  ]
                </td>
              </tr>
              <tr>
                <td>1.58-bit (Ternary)</td>
                <td>1.58-bit</td>
                <td>~2.6 GB</td>
                <td>
                  ≈99% at ≥13.4B [
                  <xref ref-type="bibr" rid="B27">27</xref>
                  ]
                </td>
              </tr>
              <tr>
                <td>Binary</td>
                <td>1-bit</td>
                <td>~1.6 GB</td>
                <td>Significant degradation</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec5dot4">
        <title>5.4. Sparse Architectures and Mixture-of-Experts</title>
        <p>MoE architectures [<xref ref-type="bibr" rid="B28">28</xref>] activate only a subset of parameters per inference pass. Mixtral 8 × 7B [<xref ref-type="bibr" rid="B29">29</xref>] achieves performance competitive with dense 70B models at the computational cost of a 13B model. Combined with ternary quantisation, MoE delivers further IPW improvements for Privata deployments, as only active expert subsets require ternary arithmetic per step.</p>
      </sec>
      <sec id="sec5dot5">
        <title>5.5. Local Retrieval-Augmented Generation</title>
        <p>RAG extends effective knowledge capacity by retrieving from a local corpus [<xref ref-type="bibr" rid="B11">11</xref>]. In the Privata context the RAG corpus is user-controlled; capacity is bounded by local storage, not parameter count. Retrieval, embedding, and indexing occur entirely within the local domain, violating no Privata constraint.</p>
      </sec>
      <sec id="sec5dot6">
        <title>5.6. The NPU-Centric Paradigm Shift</title>
        <p>The 2026 Snapdragon X2 Elite’s sixth-generation Hexagon NPU delivers 80 TOPS (INT8) [<xref ref-type="bibr" rid="B30">30</xref>]; on this basis the present analysis projects an effective throughput of approximately 85 TOPS-equivalent for 1.58-bit ternary weights [<xref ref-type="bibr" rid="B30">30</xref>], using integer addition and sign-flipping rather than floating-point MAC. Apple Silicon’s unified memory architecture enables M3 Ultra (192 GB) to run 70B+ models at cloud-competitive latency [<xref ref-type="bibr" rid="B31">31</xref>]. The trajectory of dedicated inference silicon indicates the capability gap will narrow substantially within five years, though not close entirely for the largest model scales.</p>
      </sec>
      <sec id="sec5dot7">
        <title>5.7. Thermodynamics of Sustained Inference</title>
        <p>The author’s energy model estimates approximately 11 mJ/token on mobile NPUs and 27 mJ/token on workstation NPUs. A 10,000-token reasoning chain therefore requires less than 5% of a standard laptop battery, removing the final practical energy objection to fully offline sovereign inference for mobile and field deployments.</p>
      </sec>
    </sec>
    <sec id="sec6">
      <title>6. Epistemic Boundaries</title>
      <sec id="sec6dot1">
        <title>6.1. The Closed Knowledge Manifold</title>
        <p>Define the system’s knowledge state at time <inline-formula><mml:math><mml:mi> t </mml:mi></mml:math></inline-formula> as: </p>
        <disp-formula id="FD7">
          <label>(6)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>K</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>t</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>K</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mtext>Δ</mml:mtext>
              <mml:msub>
                <mml:mi>K</mml:mi>
                <mml:mrow>
                  <mml:mtext>local</mml:mtext>
                </mml:mrow>
              </mml:msub>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> K </mml:mi><mml:mn> 0 </mml:mn></mml:msub></mml:mrow></mml:math></inline-formula> is the initial deployment state and <inline-formula><mml:math><mml:mrow><mml:mtext> Δ </mml:mtext><mml:msub><mml:mi> K </mml:mi><mml:mrow><mml:mtext> local </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> represents only locally-applied, user-authorised updates. There is no external drift term. Contrast with a cloud-deployed system: </p>
        <disp-formula id="FD8">
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>K</mml:mi>
                <mml:mrow>
                  <mml:mtext>cloud</mml:mtext>
                </mml:mrow>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>t</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>K</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mtext>Δ</mml:mtext>
              <mml:msub>
                <mml:mi>K</mml:mi>
                <mml:mrow>
                  <mml:mtext>provider</mml:mtext>
                </mml:mrow>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>t</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>,</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where <inline-formula><mml:math><mml:mrow><mml:mtext> Δ </mml:mtext><mml:msub><mml:mi> K </mml:mi><mml:mrow><mml:mtext> provider </mml:mtext></mml:mrow></mml:msub><mml:mrow><mml:mo> ( </mml:mo><mml:mi> t </mml:mi><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> is opaque to the user and continuously evolving [<xref ref-type="bibr" rid="B3">3</xref>]—the Forensic Vacuum of Section 1.1 formalised.</p>
      </sec>
      <sec id="sec6dot2">
        <title>6.2. Implications of Knowledge Closure</title>
        <p><bold>Covert Bias Injection Prevention.</bold> Any change to knowledge or behavioural tendencies requires explicit user action, leaving an auditable trace.<bold>Stable Reasoning Domain.</bold> Users can develop a complete, stable understanding of the system’s capabilities and limitations over time.<bold>Genuine Intellectual Ownership.</bold> The user’s relationship to the system is that of an owner to a tool, not a subscriber to a service that may change without notice.<bold>Reproducibility for Accountability.</bold> Legal reasoning, medical decision support, and financial analysis require the ability to reproduce a specific inference given recorded inputs and a fixed model state. Knowledge closure is a necessary condition.<bold>Epistemic Containment as Safety Feature.</bold> The knowledge currency limitation, often framed as a cost, is equally a safety property: a system with a bounded, stable knowledge state provides a hard limit on adverse behaviours arising from opaque retraining. There is, in effect, a plug to pull—an alignment with approaches to AI safety that favour deterministic controllability over continuous capability expansion [<xref ref-type="bibr" rid="B16">16</xref>]. </p>
      </sec>
      <sec id="sec6dot3">
        <title>6.3. Knowledge Currency Tradeoff</title>
        <p>The primary cost of knowledge closure is currency: a Privata system does not automatically incorporate post-deployment developments. This tradeoff is already explicitly made in many professional contexts—legal databases, medical references, and engineering standards are updated on defined cycles precisely because stability and currency are in tension [<xref ref-type="bibr" rid="B32">32</xref>]. The Two-Stage Update Protocol provides a principled mechanism for managing this tradeoff without compromising sovereignty.</p>
      </sec>
    </sec>
    <sec id="sec7">
      <title>7. Comparative Analysis</title>
      <sec id="sec7dot1">
        <title>7.1. Comparison with Cloud AI Systems</title>
        <p><bold>Table 4</bold> summarises the key differences between Cloud AI and Privata AI across ten dimensions.</p>
        <p><bold>Table 4.</bold>Comparative properties of cloud AI versus Privata AI systems.</p>
        <table-wrap id="tbl4">
          <label>Table 4</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Property</bold>
                </td>
                <td>
                  <bold>Cloud AI</bold>
                </td>
                <td>
                  <bold>Privata</bold>
                  <bold>AI</bold>
                </td>
              </tr>
              <tr>
                <td>Knowledge source</td>
                <td>Dynamic, external, opaque</td>
                <td>Fixed at deployment + local updates</td>
              </tr>
              <tr>
                <td>Privacy model</td>
                <td>Probabilistic (policy-based)</td>
                <td>Deterministic (architectural)</td>
              </tr>
              <tr>
                <td>Control locus</td>
                <td>Provider/operator</td>
                <td>User (full sovereignty)</td>
              </tr>
              <tr>
                <td>Update model</td>
                <td>Remote, continuous, opaque</td>
                <td>Offline, signed, user-initiated</td>
              </tr>
              <tr>
                <td>Epistemic drift</td>
                <td>Continuous, uncontrolled</td>
                <td>Bounded, user-authorised</td>
              </tr>
              <tr>
                <td>Data sovereignty</td>
                <td>Delegated to provider</td>
                <td>Absolute (local only)</td>
              </tr>
              <tr>
                <td>Auditability</td>
                <td>Limited/contractual</td>
                <td>Complete (all state local)</td>
              </tr>
              <tr>
                <td>Regulatory compliance</td>
                <td>Policy compliance</td>
                <td>Architectural necessity</td>
              </tr>
              <tr>
                <td>Failure mode</td>
                <td>Provider outage, policy change</td>
                <td>Hardware failure only</td>
              </tr>
              <tr>
                <td>Business model</td>
                <td>Adverse (data extraction)</td>
                <td>Aligned (user interests)</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec7dot2">
        <title>7.2. Relation to Privacy-Preserving Machine Learning</title>
        <p>Privata AI is distinct from, though related to, several existing paradigms [<xref ref-type="bibr" rid="B33">33</xref>]:</p>
        <p><bold>Federated Learning (FL).</bold> FL [<xref ref-type="bibr" rid="B34">34</xref>] keeps training data local but does not provide sovereignty over inference or knowledge state: model aggregation occurs centrally, and inference may still occur against centrally-aggregated models. FL satisfies a weaker form of data sovereignty but not control closure or inference-time locality.<bold>Differential Privacy (DP).</bold> DP [<xref ref-type="bibr" rid="B35">35</xref>] provides statistical guarantees against individual data extraction but does not eliminate centralised infrastructure dependency. DP is complementary to Privata—a Privata system may employ DP in its memory layer for defence in depth.<bold>Homomorphic Encryption (HE).</bold> HE [<xref ref-type="bibr" rid="B7">7</xref>] addresses confidentiality but not locality or control closure; computation still occurs on external infrastructure.<bold>Edge AI.</bold> Edge AI [<xref ref-type="bibr" rid="B36">36</xref>] and Privata AI share local computation but differ in <italic>primary architectural goal</italic>: Edge AI treats locality as a performance and latency optimisation, whereas Privata AI treats it as a mechanism for user sovereignty and epistemic containment. Edge deployments typically remain under provider management with automatic updates that violate (3); this is a difference of architectural intent, not implementation detail.<bold>Secure Multi-Party Computation (SMPC).</bold> SMPC [<xref ref-type="bibr" rid="B37">37</xref>] addresses confidentiality but not locality or control closure. </p>
      </sec>
    </sec>
    <sec id="sec8">
      <title>8. Economic and Political Implications</title>
      <sec id="sec8dot1">
        <title>8.1. Decentralisation of Intelligence Infrastructure</title>
        <p>Privata AI adoption at scale would constitute a structural decentralisation analogous to the PC revolution of the 1980s [<xref ref-type="bibr" rid="B38">38</xref>]: AI capability would transition from a rented service to personal infrastructure, eliminating the dependency relationships that currently concentrate economic and epistemic power in a small number of providers.</p>
      </sec>
      <sec id="sec8dot2">
        <title>8.2. The Crisis of Data-Rentierism and the Sovereign AI Economy</title>
        <p>Many AI deployments depend on passive accumulation of user interaction data to improve models and target advertising [<xref ref-type="bibr" rid="B39">39</xref>]. Privata architecture is designed to eliminate this mechanism by construction—not through policy compliance, which is easily bypassed, but through the architectural separation of inference from external data flows. This represents a <italic>Crisis of Data-</italic><italic>Rentierism</italic> for incumbents whose value derives primarily from interaction data.</p>
        <p>The disruption creates space for a <italic>Sovereign AI Economy</italic> with fundamentally different value sources: hardware sales of NPU-optimised sovereign inference devices; subscription services for cryptographically signed and audited model weight updates; zero-knowledge maintenance contracts providing ongoing security verification without user data access; and certified domain-specific knowledge update packages. This economic model structurally aligns provider incentives with user interests.</p>
      </sec>
      <sec id="sec8dot3">
        <title>8.3. Regulatory Alignment by Design</title>
        <p>Privacy-by-design principles formalised in GDPR Article 25 [<xref ref-type="bibr" rid="B40">40</xref>] and the privacy engineering literature [<xref ref-type="bibr" rid="B41">41</xref>] require data protection to be incorporated architecturally rather than applied as an afterthought. Privata AI satisfies this at the deepest level: data minimisation, purpose limitation, and user control are achieved through architectural constraints that preclude violation by design. The EU AI Act’s requirements for transparency, auditability, and human oversight [<xref ref-type="bibr" rid="B4">4</xref>] are likewise satisfied by Privata’s complete local audit trails and user control over system state.</p>
      </sec>
      <sec id="sec8dot4">
        <title>8.4. Geopolitical and National Security Dimensions</title>
        <p>Concentration of AI infrastructure in a small number of jurisdictions creates strategic risks [<xref ref-type="bibr" rid="B42">42</xref>]: legal changes, export controls, or sanctions can disrupt AI capabilities across dependent nations and organisations. Privata AI provides resilience by eliminating external infrastructure dependency. Nations can develop an <italic>Intelligence Strategic Reserve</italic>—locally possessed model weights and sovereign NPU hardware—insulating critical reasoning infrastructure from foreign jurisdictional overreach. This dimension is particularly salient for defence, critical infrastructure, and government applications.</p>
      </sec>
    </sec>
    <sec id="sec9">
      <title>9. Implementation Pathways</title>
      <sec id="sec9dot1">
        <title>9.1. Near-Term (Present-3 Years)</title>
        <p>Current hardware (Apple M-series MacBooks, consumer GPU workstations with 24 GB + VRAM) already runs quantised competitive models at practical speeds [<xref ref-type="bibr" rid="B43">43</xref>]. The software ecosystem has matured: llama.cpp, Ollama, and LM Studio provide deployment frameworks; Chroma and Qdrant provide local vector databases; Open WebUI provides user-facing interfaces. Primary remaining barriers are UX maturity, update package distribution infrastructure, and hardware attestation tooling—the first of which the Two-Stage Update Protocol directly addresses.</p>
      </sec>
      <sec id="sec9dot2">
        <title>9.2. Mid-Term (3 - 10 Years)</title>
        <p>Dedicated consumer AI inference chips will expand the Privata capability frontier. NPUs integrated into consumer devices already provide order-of-magnitude tokens-per-watt improvements over general-purpose CPUs. Over this horizon, 70B-class models should become routinely deployable on high-end consumer hardware.</p>
      </sec>
      <sec id="sec9dot3">
        <title>9.3. Long-Term (10+ Years)</title>
        <p>The long-term horizon envisions fully sovereign AI ecosystems integrated with zero-trust digital identity systems, capable of participating in federated reasoning networks while maintaining strict local sovereignty. This intersects with questions of long-duration AI systems [<xref ref-type="bibr" rid="B44">44</xref>], persistent private agents, and the legal and philosophical status of AI systems with stable, user-owned identity maintained over years to decades.</p>
      </sec>
    </sec>
    <sec id="sec10">
      <title>10. Future Directions</title>
      <p>Several open research problems are identified as priorities for the Privata AI research agenda:</p>
      <p><bold>Formal Verification of AI</bold><bold>Behaviour</bold><bold>.</bold> Methods for formally verifying that a deployed model’s behaviour conforms to specified properties, enabling automated auditability. The <italic>Deterministic Controllability</italic> property of Privata systems makes them uniquely tractable targets: a closed knowledge manifold presents a stable, fixed specification against which machine-checked proofs can be constructed, unlike the continuously drifting state of cloud-deployed models. Recent work in model specification [<xref ref-type="bibr" rid="B16">16</xref>] and formal analysis of transformer architectures provides initial foundations.<bold>Cryptographic Memory Sealing.</bold> Techniques for cryptographically binding memory state to hardware identity, preventing private embedding extraction even under OS compromise.<bold>Self-Auditing AI Systems.</bold> Architectures enabling AI systems to produce verifiable accounts of their own reasoning, supporting user oversight without specialised expertise. Mechanistic interpretability research [<xref ref-type="bibr" rid="B45">45</xref>] provides relevant foundations.<bold>Long-Duration Private AI.</bold> The conditions under which a Privata system maintains coherent behaviour over years to decades, including the relationship between knowledge closure and epistemic stability [<xref ref-type="bibr" rid="B46">46</xref>].<bold>Secure Update Package Ecosystems.</bold> Infrastructure for distributing cryptographically signed model update packages that enable knowledge currency without compromising sovereignty. Certificate transparency mechanisms [<xref ref-type="bibr" rid="B47">47</xref>] may provide design patterns.<bold>Privata</bold><bold>Multi-Agent Systems.</bold> Architectures enabling collaboration between multiple Privata AI systems while maintaining individual sovereignty guarantees. Zero-knowledge proofs [<xref ref-type="bibr" rid="B48">48</xref>] offer potential building blocks. </p>
    </sec>
    <sec id="sec11">
      <title>11. Conclusion</title>
      <p>We have introduced <italic>Intelligentia</italic><italic>Artificialis</italic><italic>Privata</italic> as a formally defined category of AI systems distinguished by physical locality, operational autonomy, and knowledge closure. These properties jointly provide security, privacy, and epistemic guarantees that are architecturally necessary rather than policy-contingent, satisfying current and emerging regulatory frameworks by construction.</p>
      <p>The comparative analysis demonstrates that Privata AI is categorically distinct from federated learning, differential privacy, homomorphic encryption, and—critically—edge AI, whose primary architectural goal is performance optimisation rather than user sovereignty. The formalisation of the HBS protocol with its PUF-derived root of trust and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℐ </mml:mi><mml:mrow><mml:mtext> human </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> interrupt guarantee, combined with the empirical characterisation of the 1.58-bit Parity Horizon and its training-from-scratch requirements, provides the technical foundations for provably secure, practically deployable sovereign systems. The economic analysis demonstrates that Privata architecture does not merely disrupt existing data-extractive models but creates the conditions for a Sovereign AI Economy structurally aligned with user interests.</p>
      <p>The centralization of AI infrastructure is not an inevitable consequence of the technology but a product of economic incentives and path dependencies. The current state of hardware, quantisation techniques, and local inference software demonstrates that the alternative is architecturally coherent, practically implementable, and increasingly accessible.</p>
      <p><italic>Intelligentia</italic><italic>Artificialis</italic><italic>Privata</italic><italic>is not a feature</italic>—<italic>it is a category shift in how intelligence is instantiated</italic>, <italic>owned</italic>,<italic>and constrained</italic>. <italic>It represents the application of the personal computing insight to the age of AI</italic>: <italic>that the most powerful and trustworthy technology is technology you own</italic>. </p>
    </sec>
    <sec id="sec12">
      <title>Appendix</title>
      <sec id="sec12dot1">
        <title>A. Minimal System Specification</title>
        <p>A compliant Privata system requires at minimum:</p>
        <p><bold>Hardware.</bold> x86-64 or ARM64 system with ≥16 GB RAM; GPU or NPU with 8+ GB VRAM recommended for 7B+ models. <bold>Model.</bold> Ternary (1.58-bit, trained from scratch with SubLN) or quantised LLM (4-bit or 8-bit GGUF), 7B - 13B parameters, stored locally with SHA-256 hash verification. <bold>Storage.</bold> 20 - 100 GB local NVMe storage for model weights and vector database. <bold>Update mechanism.</bold> Two-Stage Update Protocol with GPG-signed packages; no automatic or network-initiated inference modification; rollback capability required. <bold>Network.</bold> Zero dependency during inference; optional controlled sync for Stage 1 updates only. <bold>Audit capability.</bold> Complete local logging of all inference activity, configuration changes, and update events. </p>
      </sec>
      <sec id="sec12dot2">
        <title>B. Reference Implementation Sketch</title>
        <p>A minimal reference implementation comprises three main components:</p>
        <p>1) <bold>Local LLM inference engine.</bold> llama.cpp or Ollama, with network access disabled at the OS level via iptables/nftables or macOS pf. Model weights SHA-256 verified before loading. For ternary models, the engine must support NPU-native in-register ternary arithmetic; LUT-based fallback is not acceptable.</p>
        <p>2) <bold>Local vector database.</bold> Chroma or Qdrant in embedded mode. All documents embedded using a locally-running model (e.g., nomic-embed-text). No cloud API calls.</p>
        <p>3) <bold>Control interface.</bold> Open WebUI or equivalent on localhost only (127.0.0.1 binding), with complete local audit logging. Updates via Two-Stage Protocol: sandboxed background download, HBS hash verification, physical user confirmation (<inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> ℐ </mml:mi><mml:mrow><mml:mtext> human </mml:mtext></mml:mrow></mml:msub><mml:mo> = </mml:mo><mml:mn> 1 </mml:mn></mml:mrow></mml:math></inline-formula> ) before activation. </p>
        <p>This satisfies all three Privata constraints: <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi mathvariant="script"> C </mml:mi><mml:mrow><mml:mtext> net </mml:mtext></mml:mrow></mml:msub><mml:mo> = </mml:mo><mml:mn> 0 </mml:mn></mml:mrow></mml:math></inline-formula> during inference; <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> D </mml:mi><mml:mrow><mml:mtext> external </mml:mtext></mml:mrow></mml:msub><mml:mo> ∩ </mml:mo><mml:msub><mml:mi> D </mml:mi><mml:mrow><mml:mtext> internal </mml:mtext></mml:mrow></mml:msub><mml:mo> = </mml:mo><mml:mo> ∅ </mml:mo></mml:mrow></mml:math></inline-formula> ; and all updates <inline-formula><mml:math><mml:mrow><mml:mo> ∈ </mml:mo><mml:msub><mml:mi mathvariant="script"> U </mml:mi><mml:mrow><mml:mtext> user </mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> .</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Brown, T.B., Mann, B., Ryder, N., Subbiah, M., Kaplan, J.D., Dhariwal, P., <italic>et al</italic>. (2020) Language Models Are Few-Shot Learners. arXiv: 2005.14165. https://arxiv.org/abs/2005.14165</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Brown, T.B.</string-name>
              <string-name>Mann, B.</string-name>
              <string-name>Ryder, N.</string-name>
              <string-name>Subbiah, M.</string-name>
              <string-name>Kaplan, J.D.</string-name>
              <string-name>Dhariwal, P.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Language Models Are Few-Shot Learners</article-title>
            <fpage>2005</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Armbrust, M., Fox, A., Griffith, R., Joseph, A.D., Katz, R., Konwinski, A., <italic>et al</italic>. (2010) A View of Cloud Computing. <italic>Communications</italic><italic>of</italic><italic>the</italic><italic>ACM</italic>, 53, 50-58. https://doi.org/10.1145/1721654.1721672 <pub-id pub-id-type="doi">10.1145/1721654.1721672</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/1721654.1721672">https://doi.org/10.1145/1721654.1721672</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Armbrust, M.</string-name>
              <string-name>Fox, A.</string-name>
              <string-name>Griffith, R.</string-name>
              <string-name>Joseph, A.D.</string-name>
              <string-name>Katz, R.</string-name>
              <string-name>Konwinski, A.</string-name>
            </person-group>
            <year>2010</year>
            <article-title>A View of Cloud Computing</article-title>
            <source>Communications of the ACM</source>
            <volume>53</volume>
            <pub-id pub-id-type="doi">10.1145/1721654.1721672</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ganguli, D., Hernandez, D., Lovitt, L., Askell, A., Bai, Y., Chen, A., <italic>et al</italic>. (2022) Predictability and Surprise in Large Generative Models. 2022 <italic>ACM Conference on Fairness Accountability and Transparency</italic>, Seoul, 21-24 June 2022, 1747-1764. https://doi.org/10.1145/3531146.3533229 <pub-id pub-id-type="doi">10.1145/3531146.3533229</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3531146.3533229">https://doi.org/10.1145/3531146.3533229</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ganguli, D.</string-name>
              <string-name>Hernandez, D.</string-name>
              <string-name>Lovitt, L.</string-name>
              <string-name>Askell, A.</string-name>
              <string-name>Bai, Y.</string-name>
              <string-name>Chen, A.</string-name>
              <string-name>Transparency, S</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Predictability and Surprise in Large Generative Models</article-title>
            <source>2022 ACM Conference on Fairness Accountability and Transparency</source>
            <volume>21</volume>
            <pub-id pub-id-type="doi">10.1145/3531146.3533229</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">European Parliament (2024) Regulation (EU) 2024/1689 of the European Parliament and of the Council on Artificial Intelligence (AI Act) Official Journal of the European Union, 2024. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng</mixed-citation>
          <element-citation publication-type="journal">
            <year>2024</year>
            <article-title>Regulation (EU) 2024/1689 of the European Parliament and of the Council on Artificial Intelligence (AI Act) Official Journal of the European Union, 2024</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Biden, J.R. (2023) Executive Order 14110: Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. Federal Register. https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Biden, J.R.</string-name>
              <string-name>Safe, S</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Executive Order 14110: Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Westin, A.F. (1967) Privacy and Freedom. Atheneum. https://archive.org/details/privacyfreedom00west</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Westin, A.F.</string-name>
            </person-group>
            <year>1967</year>
            <article-title>Privacy and Freedom</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B7">
        <label>7.</label>
        <citation-alternatives>
          <mixed-citation publication-type="thesis">Gentry, C. (2009) A Fully Homomorphic Encryption Scheme. Ph.D. Thesis, Stanford University. https://crypto.stanford.edu/craig/craig-thesis.pdf</mixed-citation>
          <element-citation publication-type="thesis">
            <person-group person-group-type="author">
              <string-name>Gentry, C.</string-name>
              <string-name>Thesis, S</string-name>
            </person-group>
            <year>2009</year>
            <article-title>A Fully Homomorphic Encryption Scheme</article-title>
            <source>Ph.D. Thesis</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B8">
        <label>8.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Shi, W., Cao, J., Zhang, Q., Li, Y. and Xu, L. (2016) Edge Computing: Vision and Challenges. <italic>IEEE</italic><italic>Internet</italic><italic>of</italic><italic>Things</italic><italic>Journal</italic>, 3, 637-646. https://doi.org/10.1109/jiot.2016.2579198 <pub-id pub-id-type="doi">10.1109/jiot.2016.2579198</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/jiot.2016.2579198">https://doi.org/10.1109/jiot.2016.2579198</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Shi, W.</string-name>
              <string-name>Cao, J.</string-name>
              <string-name>Zhang, Q.</string-name>
              <string-name>Li, Y.</string-name>
              <string-name>Xu, L.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>Edge Computing: Vision and Challenges</article-title>
            <source>IEEE Internet of Things Journal</source>
            <volume>3</volume>
            <pub-id pub-id-type="doi">10.1109/jiot.2016.2579198</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B9">
        <label>9.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Gerganov, G. (2023) llama.cpp: Port of Facebook’s LLaMA model in C/C++. GitHub Repository. https://github.com/ggerganov/llama.cpp</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Gerganov, G.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>llama</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B10">
        <label>10.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">MLC Team (2023) MLC-LLM: Universal LLM Deployment Engine with ML Compilation. GitHub Repository. https://github.com/mlc-ai/mlc-llm</mixed-citation>
          <element-citation publication-type="web">
            <year>2023</year>
            <article-title>MLC-LLM: Universal LLM Deployment Engine with ML Compilation</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B11">
        <label>11.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Lewis, P., Perez, E., Piktus, A., Petroni, F., Karpukhin, V., Goyal, N., <italic>et al</italic>. (2020) Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks. arXiv: 2005.11401. https://arxiv.org/abs/2005.11401</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Lewis, P.</string-name>
              <string-name>Perez, E.</string-name>
              <string-name>Piktus, A.</string-name>
              <string-name>Petroni, F.</string-name>
              <string-name>Karpukhin, V.</string-name>
              <string-name>Goyal, N.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks</article-title>
            <fpage>2005</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B12">
        <label>12.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Bellissimo, A., Burgess, J. and Fu, K. (2006) Secure Software Updates: Disappointments and New Challenges. https://www.usenix.org/legacy/event/hotsec06/tech/full_papers/bellissimo/bellissimo.pdf</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Bellissimo, A.</string-name>
              <string-name>Burgess, J.</string-name>
              <string-name>Fu, K.</string-name>
            </person-group>
            <year>2006</year>
            <article-title>Secure Software Updates: Disappointments and New Challenges</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B13">
        <label>13.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Trusted Computing Group (2019) Trusted Platform Module Library Specification, Family 1.2, Level 2, Revision 116. TCG. https://trustedcomputinggroup.org/resource/tpm-library-specification/</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Specification, F</string-name>
            </person-group>
            <year>2019</year>
            <article-title>Trusted Platform Module Library Specification, Family 1</article-title>
            <source>2</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B14">
        <label>14.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Maes, R. (2013) Physically Unclonable Functions: Constructions, Properties and Applications. Springer. https://doi.org/10.1007/978-3-642-41395-7 <pub-id pub-id-type="doi">10.1007/978-3-642-41395-7</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-642-41395-7">https://doi.org/10.1007/978-3-642-41395-7</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Maes, R.</string-name>
              <string-name>Constructions, P</string-name>
            </person-group>
            <year>2013</year>
            <article-title>Physically Unclonable Functions: Constructions, Properties and Applications</article-title>
            <pub-id pub-id-type="doi">10.1007/978-3-642-41395-7</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B15">
        <label>15.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Sabt, M., Achemlal, M. and Bouabdallah, A. (2015) Trusted Execution Environment: What It Is, and What It Is Not. 2015 <italic>IEEE</italic><italic>Trustcom</italic>/ <italic>BigDataSE</italic>/ <italic>ISPA</italic>, Helsinki, 20-22 August 2015, 57-64. https://doi.org/10.1109/trustcom.2015.357 <pub-id pub-id-type="doi">10.1109/trustcom.2015.357</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/trustcom.2015.357">https://doi.org/10.1109/trustcom.2015.357</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Sabt, M.</string-name>
              <string-name>Achemlal, M.</string-name>
              <string-name>Bouabdallah, A.</string-name>
              <string-name>ISPA, H</string-name>
            </person-group>
            <year>2015</year>
            <article-title>Trusted Execution Environment: What It Is, and What It Is Not</article-title>
            <source>2015 IEEE Trustcom/BigDataSE/ISPA</source>
            <volume>20</volume>
            <pub-id pub-id-type="doi">10.1109/trustcom.2015.357</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B16">
        <label>16.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Dalrymple, D., Seshia, S.A., <italic>et al</italic>. (2024) Towards Guaranteed Safe AI: A Framework for Ensuring Robust and Reliable AI Systems. arXiv: 2405.06624. https://arxiv.org/abs/2405.06624</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Dalrymple, D.</string-name>
              <string-name>Seshia, S.A.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Towards Guaranteed Safe AI: A Framework for Ensuring Robust and Reliable AI Systems</article-title>
            <fpage>2405</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B17">
        <label>17.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Shostack, A. (2014) Threat Modeling: Designing for Security. Wiley.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Shostack, A.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Threat Modeling: Designing for Security</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B18">
        <label>18.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">MITRE Corporation (2023) MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems. https://atlas.mitre.org</mixed-citation>
          <element-citation publication-type="web">
            <year>2023</year>
            <article-title>MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B19">
        <label>19.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Perez, F. and Ribeiro, I. (2022) Ignore Previous Prompt: Attack Techniques for Language Models. arXiv: 2211.09527. https://arxiv.org/abs/2211.09527</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Perez, F.</string-name>
              <string-name>Ribeiro, I.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Ignore Previous Prompt: Attack Techniques for Language Models</article-title>
            <fpage>2211</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B20">
        <label>20.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Kocher, P., Horn, J., Fogh, A., Genkin, D., Gruss, D., Haas, W., <italic>et al</italic>. (2019) Spectre Attacks: Exploiting Speculative Execution. 2019 <italic>IEEE Symposium on Security and Privacy</italic>( <italic>SP</italic>), San Francisco, 19-23 May 2019, 1-19. https://doi.org/10.1109/sp.2019.00002 <pub-id pub-id-type="doi">10.1109/sp.2019.00002</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/sp.2019.00002">https://doi.org/10.1109/sp.2019.00002</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Kocher, P.</string-name>
              <string-name>Horn, J.</string-name>
              <string-name>Fogh, A.</string-name>
              <string-name>Genkin, D.</string-name>
              <string-name>Gruss, D.</string-name>
              <string-name>Haas, W.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>Spectre Attacks: Exploiting Speculative Execution</article-title>
            <source>2019 IEEE Symposium on Security and Privacy (SP)</source>
            <volume>19</volume>
            <pub-id pub-id-type="doi">10.1109/sp.2019.00002</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B21">
        <label>21.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Goldblum, M., Tsipras, D., Xie, C., Chen, X., Schwarzschild, A., Song, D., <italic>et al</italic>. (2023) Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses. <italic>IEEE</italic><italic>Transactions</italic><italic>on</italic><italic>Pattern</italic><italic>Analysis</italic><italic>and</italic><italic>Machine</italic><italic>Intelligence</italic>, 45, 1563-1580. https://doi.org/10.1109/tpami.2022.3162397 <pub-id pub-id-type="doi">10.1109/tpami.2022.3162397</pub-id><pub-id pub-id-type="pmid">35333711</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/tpami.2022.3162397">https://doi.org/10.1109/tpami.2022.3162397</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Goldblum, M.</string-name>
              <string-name>Tsipras, D.</string-name>
              <string-name>Xie, C.</string-name>
              <string-name>Chen, X.</string-name>
              <string-name>Schwarzschild, A.</string-name>
              <string-name>Song, D.</string-name>
              <string-name>Poisoning, B</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses</article-title>
            <source>IEEE Transactions on Pattern Analysis and Machine Intelligence</source>
            <volume>45</volume>
            <pub-id pub-id-type="doi">10.1109/tpami.2022.3162397</pub-id>
            <pub-id pub-id-type="pmid">35333711</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B22">
        <label>22.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Chitty-Venkata, K.T., Mittal, S., Emani, M., Vishwanath, V. and Somani, A.K. (2023) A Survey of Techniques for Optimizing Transformer Inference. <italic>Journal</italic><italic>of</italic><italic>Systems</italic><italic>Architecture</italic>, 144, Article ID: 102990. https://doi.org/10.1016/j.sysarc.2023.102990 <pub-id pub-id-type="doi">10.1016/j.sysarc.2023.102990</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.sysarc.2023.102990">https://doi.org/10.1016/j.sysarc.2023.102990</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Chitty-Venkata, K.T.</string-name>
              <string-name>Mittal, S.</string-name>
              <string-name>Emani, M.</string-name>
              <string-name>Vishwanath, V.</string-name>
              <string-name>Somani, A.K.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>A Survey of Techniques for Optimizing Transformer Inference</article-title>
            <source>Journal of Systems Architecture</source>
            <volume>144</volume>
            <fpage>102990</fpage>
            <elocation-id>ID</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.sysarc.2023.102990</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B23">
        <label>23.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Saad-Falcon, J., Narayan, A., Akengin, H.O., Griffin, J.W., Shandilya, H., Gamarra Lafuente, A., et al. (2025) Intelligence per Watt: Measuring Intelligence Efficiency of Local AI. arXiv: 2511.07885. https://arxiv.org/abs/2511.07885</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Saad-Falcon, J.</string-name>
              <string-name>Narayan, A.</string-name>
              <string-name>Akengin, H.O.</string-name>
              <string-name>Griffin, J.W.</string-name>
              <string-name>Shandilya, H.</string-name>
              <string-name>Lafuente, A.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Intelligence per Watt: Measuring Intelligence Efficiency of Local AI</article-title>
            <fpage>2511</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B24">
        <label>24.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Gholami, A., Kim, S., Dong, Z., Yao, Z.W., Mahoney, M.W. and Keutzer, K. (2022) A Survey of Quantization Methods for Efficient Neural Network Inference. arXiv: 2103.13630. https://arxiv.org/abs/2103.13630</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Gholami, A.</string-name>
              <string-name>Kim, S.</string-name>
              <string-name>Dong, Z.</string-name>
              <string-name>Yao, Z.W.</string-name>
              <string-name>Mahoney, M.W.</string-name>
              <string-name>Keutzer, K.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>A Survey of Quantization Methods for Efficient Neural Network Inference</article-title>
            <fpage>2103</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B25">
        <label>25.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Frantar, E., Ashkboos, S., Hoefler, T. and Alistarh, D. (2023) GPTQ: Accurate Post-training Quantization for Generative Pre-Trained Transformers. arXiv: 2210.17323. https://arxiv.org/abs/2210.17323</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Frantar, E.</string-name>
              <string-name>Ashkboos, S.</string-name>
              <string-name>Hoefler, T.</string-name>
              <string-name>Alistarh, D.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>GPTQ: Accurate Post-training Quantization for Generative Pre-Trained Transformers</article-title>
            <fpage>2210</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B26">
        <label>26.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Dettmers, T., Lewis, M., Belkada, Y. and Zettlemoyer, L. (2022) LLM.int8(): 8-bit Matrix Multiplication for Transformers at Scale. arXiv: 2208.07339. https://arxiv.org/abs/2208.07339</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Dettmers, T.</string-name>
              <string-name>Lewis, M.</string-name>
              <string-name>Belkada, Y.</string-name>
              <string-name>Zettlemoyer, L.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>LLM</article-title>
            <fpage>8</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B27">
        <label>27.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Ma, S.M., Wang, H.Y., Ma, L.X., <italic>et al</italic>. (2024) The Era of 1-Bit LLMs: All Large Language Models Are in 1.58 Bits. arXiv: 2402.17764. https://arxiv.org/abs/2402.17764</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Ma, S.M.</string-name>
              <string-name>Wang, H.Y.</string-name>
              <string-name>Ma, L.X.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>The Era of 1-Bit LLMs: All Large Language Models Are in 1</article-title>
            <fpage>2402</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B28">
        <label>28.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Shazeer, N., Mirhoseini, A., Maziarz, K., <italic>et al</italic>. (2017) Outrageously Large Neural Networks: The Sparsely-Gated Mixture-Of-Experts Layer. arXiv: 1701.06538. https://arxiv.org/abs/1701.06538</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Shazeer, N.</string-name>
              <string-name>Mirhoseini, A.</string-name>
              <string-name>Maziarz, K.</string-name>
            </person-group>
            <year>2017</year>
            <article-title>Outrageously Large Neural Networks: The Sparsely-Gated Mixture-Of-Experts Layer</article-title>
            <fpage>1701</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B29">
        <label>29.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Jiang, A.Q., Sablayrolles, A., Roux, A., <italic>et al</italic>. (2024) Mixtral of Experts. arXiv: 2401.04088. https://arxiv.org/abs/2401.04088</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Jiang, A.Q.</string-name>
              <string-name>Sablayrolles, A.</string-name>
              <string-name>Roux, A.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Mixtral of Experts</article-title>
            <fpage>2401</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B30">
        <label>30.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Qualcomm Technologies, Inc. (2025) New Snapdragon X2 Elite Extreme and Snap-dragon X2 Elite are the Fastest and Most Efficient Processors for Windows PCs. Press Release. https://www.qualcomm.com/news/releases/2025/09/new-snapdragon-x2-elite-extreme-and-snapdragon-x2-elite-are-the-</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Technologies, I</string-name>
            </person-group>
            <year>2025</year>
            <article-title>New Snapdragon X2 Elite Extreme and Snap-dragon X2 Elite are the Fastest and Most Efficient Processors for Windows PCs</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B31">
        <label>31.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Apple Inc (2023) Apple Unveils M3, M3 Pro, and M3 Max, the Most Advanced Chips for a Personal Computer. Apple Newsroom. https://www.apple.com/newsroom/2023/10/apple-unveils-m3-m3-pro-and-m3-max-the-most-advanced-chips-for-a-personal-computer/</mixed-citation>
          <element-citation publication-type="web">
            <year>2023</year>
            <article-title>Apple Unveils M3, M3 Pro, and M3 Max, the Most Advanced Chips for a Personal Computer</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B32">
        <label>32.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Bender, E.M., Gebru, T., McMillan-Major, A. and Shmitchell, S. (2021) On the Dangers of Stochastic Parrots: Can Language Models Be Too Big? <italic>Proceedings of the</italic>2021 <italic>ACM Conference on Fairness</italic>, <italic>Accountability</italic>, <italic>and Transparency</italic>, 3-10 March 2021, 610-623. https://doi.org/10.1145/3442188.3445922 <pub-id pub-id-type="doi">10.1145/3442188.3445922</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3442188.3445922">https://doi.org/10.1145/3442188.3445922</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Bender, E.M.</string-name>
              <string-name>Gebru, T.</string-name>
              <string-name>McMillan-Major, A.</string-name>
              <string-name>Shmitchell, S.</string-name>
              <string-name>Fairness, A</string-name>
            </person-group>
            <year>2021</year>
            <article-title>On the Dangers of Stochastic Parrots: Can Language Models Be Too Big? Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency, 3-10 March 2021, 610-623</article-title>
            <pub-id pub-id-type="doi">10.1145/3442188.3445922</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B33">
        <label>33.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Mireshghallah, F., Taram, M., Ramrakhyani, P., Jalali, A., Tahoori M.B., and Esmaeilzadeh, H. (2020) Privacy in Deep Learning: A Survey. arXiv: 2004.12254. https://arxiv.org/abs/2004.12254</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Mireshghallah, F.</string-name>
              <string-name>Taram, M.</string-name>
              <string-name>Ramrakhyani, P.</string-name>
              <string-name>Jalali, A.</string-name>
              <string-name>Esmaeilzadeh, H.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Privacy in Deep Learning: A Survey</article-title>
            <fpage>2004</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B34">
        <label>34.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">McMahan, B., Moore, E., Ramage, D., Hampson, S. and Agüera y Arcas, B. (2017) Communication-Efficient Learning of Deep Networks from Decentralized Data. arXiv: 1602.05629. https://arxiv.org/abs/1602.05629</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>McMahan, B.</string-name>
              <string-name>Moore, E.</string-name>
              <string-name>Ramage, D.</string-name>
              <string-name>Hampson, S.</string-name>
              <string-name>Arcas, B.</string-name>
            </person-group>
            <year>2017</year>
            <article-title>Communication-Efficient Learning of Deep Networks from Decentralized Data</article-title>
            <fpage>1602</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B35">
        <label>35.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Dwork, C. and Roth, A. (2014) The Algorithmic Foundations of Differential Privacy. <italic>Foundations</italic><italic>and</italic><italic>Trends®</italic><italic>in</italic><italic>Theoretical</italic><italic>Computer</italic><italic>Science</italic>, 9, 211-487. https://doi.org/10.1561/0400000042 <pub-id pub-id-type="doi">10.1561/0400000042</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1561/0400000042">https://doi.org/10.1561/0400000042</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Dwork, C.</string-name>
              <string-name>Roth, A.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>The Algorithmic Foundations of Differential Privacy</article-title>
            <source>Foundations and Trends® in Theoretical Computer Science</source>
            <volume>9</volume>
            <pub-id pub-id-type="doi">10.1561/0400000042</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B36">
        <label>36.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Li, E., Zhou, Z. and Chen, X. (2018) Edge Intelligence: On-Demand Deep Learning Model Co-Inference with Device-Edge Synergy. arXiv: 1806.07840. https://arxiv.org/abs/1806.07840</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Li, E.</string-name>
              <string-name>Zhou, Z.</string-name>
              <string-name>Chen, X.</string-name>
            </person-group>
            <year>2018</year>
            <article-title>Edge Intelligence: On-Demand Deep Learning Model Co-Inference with Device-Edge Synergy</article-title>
            <fpage>1806</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B37">
        <label>37.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Goldreich, O. (2004) Foundations of Cryptography, Volume 2: Basic Applications. Cambridge University Press.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Goldreich, O.</string-name>
              <string-name>Cryptography, V</string-name>
            </person-group>
            <year>2004</year>
            <article-title>Foundations of Cryptography, Volume 2: Basic Applications</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B38">
        <label>38.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Ceruzzi, P.E. (2003) A History of Modern Computing. 2nd Edition, MIT Press.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Ceruzzi, P.E.</string-name>
              <string-name>Edition, M</string-name>
            </person-group>
            <year>2003</year>
            <article-title>A History of Modern Computing</article-title>
            <source>2nd Edition</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B39">
        <label>39.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Zuboff, S. (2019) The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. PublicAffairs.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Zuboff, S.</string-name>
            </person-group>
            <year>2019</year>
            <article-title>The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B40">
        <label>40.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">European Parliament (2016) Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) Official Journal of the European Union, 2016. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng</mixed-citation>
          <element-citation publication-type="journal">
            <year>2016</year>
            <article-title>Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) Official Journal of the European Union, 2016</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B41">
        <label>41.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Cavoukian, A. (2009) Privacy by Design: The 7 Foundational Principles. Information and Privacy Commissioner of Ontario. https://www.ipc.on.ca/wp-content/uploads/resources/7foundationalprinciples.pdf</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Cavoukian, A.</string-name>
            </person-group>
            <year>2009</year>
            <article-title>Privacy by Design: The 7 Foundational Principles</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B42">
        <label>42.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Allen, G. and Chan, T. (2017) Artificial Intelligence and National Security. Study, Belfer Center for Science and International Affairs, Harvard Kennedy School. https://www.belfercenter.org/publication/artificial-intelligence-and-national-security</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Allen, G.</string-name>
              <string-name>Chan, T.</string-name>
              <string-name>Study, B</string-name>
              <string-name>Affairs, H</string-name>
            </person-group>
            <year>2017</year>
            <article-title>Artificial Intelligence and National Security</article-title>
            <source>Study</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B43">
        <label>43.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Touvron, H., Martin, L., Stone, K., <italic>et al</italic>. (2023) Llama 2: Open Foundation and Fine-tuned Chat Models. arXiv: 2307.09288. https://arxiv.org/abs/2307.09288</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Touvron, H.</string-name>
              <string-name>Martin, L.</string-name>
              <string-name>Stone, K.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Llama 2: Open Foundation and Fine-tuned Chat Models</article-title>
            <fpage>2307</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B44">
        <label>44.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Krakovna, V., Martic, M., Togelius, J., Leike, J. and Legg, S. (2020) Avoiding Side Effects in Complex Environments. arXiv: 2006.06547. https://arxiv.org/abs/2006.06547</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Krakovna, V.</string-name>
              <string-name>Martic, M.</string-name>
              <string-name>Togelius, J.</string-name>
              <string-name>Leike, J.</string-name>
              <string-name>Legg, S.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Avoiding Side Effects in Complex Environments</article-title>
            <fpage>2006</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B45">
        <label>45.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Elhage, N., Hume, T., Chan, C., <italic>et al</italic>. (2022) Toy Models of Superposition. Transformer Circuits Thread. https://transformer-circuits.pub/2022/toy_model/index.html</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Elhage, N.</string-name>
              <string-name>Hume, T.</string-name>
              <string-name>Chan, C.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Toy Models of Superposition</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B46">
        <label>46.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Delange, M., Aljundi, R., Masana, M., Parisot, S., Jia, X., Leonardis, A., <italic>et al</italic>. (2021) A Continual Learning Survey: Defying Forgetting in Classification Tasks. <italic>IEEE</italic><italic>Transactions</italic><italic>on</italic><italic>Pattern</italic><italic>Analysis</italic><italic>and</italic><italic>Machine</italic><italic>Intelligence</italic>, 44, 3366-3385. https://doi.org/10.1109/tpami.2021.3057446 <pub-id pub-id-type="doi">10.1109/tpami.2021.3057446</pub-id><pub-id pub-id-type="pmid">33544669</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/tpami.2021.3057446">https://doi.org/10.1109/tpami.2021.3057446</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Delange, M.</string-name>
              <string-name>Aljundi, R.</string-name>
              <string-name>Masana, M.</string-name>
              <string-name>Parisot, S.</string-name>
              <string-name>Jia, X.</string-name>
              <string-name>Leonardis, A.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>A Continual Learning Survey: Defying Forgetting in Classification Tasks</article-title>
            <source>IEEE Transactions on Pattern Analysis and Machine Intelligence</source>
            <volume>44</volume>
            <pub-id pub-id-type="doi">10.1109/tpami.2021.3057446</pub-id>
            <pub-id pub-id-type="pmid">33544669</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B47">
        <label>47.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Laurie, B., Langley, A. and Kasper, E. (2013) Certificate Transparency. RFC 6962, IETF. https://www.rfc-editor.org/info/rfc6962</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Laurie, B.</string-name>
              <string-name>Langley, A.</string-name>
              <string-name>Kasper, E.</string-name>
            </person-group>
            <year>2013</year>
            <article-title>Certificate Transparency</article-title>
            <source>RFC 6962</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B48">
        <label>48.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ben-Or, M., Goldwasser, S. and Wigderson, A. (1988) Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation. <italic>Proceedings of the Twentieth Annual ACM Symposium on Theory of Computing</italic>— <italic>STOC</italic>‘88, Chicago, 2-4 May 1988, 1-10. https://doi.org/10.1145/62212.62213 <pub-id pub-id-type="doi">10.1145/62212.62213</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/62212.62213">https://doi.org/10.1145/62212.62213</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ben-Or, M.</string-name>
              <string-name>Goldwasser, S.</string-name>
              <string-name>Wigderson, A.</string-name>
            </person-group>
            <year>1988</year>
            <article-title>Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation</article-title>
            <source>Proceedings of the Twentieth Annual ACM Symposium on Theory of Computing—STOC‘88</source>
            <volume>2</volume>
            <pub-id pub-id-type="doi">10.1145/62212.62213</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>