Published June 17, 2026 | Version v1
Software Open

Cittela — Verified Isolation Proofs for Multi-Tenant LLM Inference (Lean + Verus)

  • 1. Cittela Ltd.

Description

Machine-checked Lean and Verus proofs accompanying the paper "1000 Tenants, One
Model, One MacBook: Attacker-Tested Isolation for Multi-Tenant LLM Inference"
(Zenodo, DOI 10.5281/zenodo.20727024). Three artifacts establish, for a per-tenant
geometric rotation mechanism: (1) the geometric core in Lean — isometry, matched-key
round-trip, wrong-key composition, and a non-aligning per-tenant key family; (2) tenant
isolation with governed cross-tenant operation in Verus; (3) the same plus write-integrity
(every cached entry was created by an authorized write). The guarantees are structural,
not cryptographic: authorization gates are abstract predicates modelling where
authorization is required, not unforgeable constructions. See README for scope and
reproduction.

Files

cittela-verified-isolation-v1.zip

Files (19.8 kB)

Name Size Download all
md5:aecc7f696e54d2d9d6bfa8f508b7fad7
19.8 kB Preview Download

Additional details

Related works

Is supplement to
Preprint: 10.5281/zenodo.20727024 (DOI)