Skip to content

Auditor

umermjd11 edited this page Oct 5, 2026 · 4 revisions

Auditor

🚧 This wiki describes DevNet 2.0, soon to be launched. It follows the contracts and dincli on the develop branch; the currently running DevNet may still use older contracts and commands. Pre-launch discussion: #102.

Auditors are the network's quality control. They are staked validators who evaluate the local models that Clients submit, and decide by score and vote which contributions are good enough to enter the global model. Without them, one poisoned submission could corrupt the model everyone shares. The audit phase is what makes open participation safe.

Like Aggregators, auditors have skin in the game. They stake DIN tokens in DinValidatorStake, and failing to vote on an assigned batch is punished by slashing that stake. In return they earn a share of every GI's reward pool.

Becoming an auditor

dincli auditor dintoken buy <amount_eth>     # exchange ETH for DIN
dincli auditor dintoken stake <amount>       # approve and stake in one command
dincli auditor register <model_id>           # register for the current GI (window must be open)

You stake once and top up as needed: each stake call needs at least 10 DIN, and exiting takes a 7-day unbonding period by default. Registration is per model, per Global Iteration, and only while the model owner has the auditor registration window open. To register, you must:

  • be an active validator;
  • meet the model's stake floor, if it has one;
  • have room under the concurrent-registration cap;
  • register before the GI's 300-auditor cap is reached.

Encryption key. Audit test data is encrypted to each auditor. So an auditor needs an X25519 key pair: the public key registered on DinValidatorStake (registerEncryptionKey), and the private key at auditor_x25519.key in the dincli config directory. dincli doesn't yet have a command to register the key. If an assigned auditor has no key, the owner can't assign test data to that batch.

The job: evaluate a batch

After the LMS phase closes, a future-block seed is locked (anyone can do it: dincli auditor lock-seed <model_id>), and the model owner shuffles the submitted local models into audit batches of 3 auditors × 3 models. For each batch the owner publishes the test dataset encrypted, with a key for each of the batch's auditors.

For each model in the batch, the auditor:

  1. fetches the local model and the encrypted test data from IPFS, decrypts its key, and checks the owner's signature on the dataset;
  2. runs the model owner's scoring function against the test data, in a sandboxed Worker Node;
  3. commits on-chain a hash of its score (0–100) and eligibility vote, bound to its address and the slot;
  4. after the model owner opens the reveal phase, reveals the score and vote.
dincli auditor lms-evaluation show-batch <model_id>          # see your assignment
dincli auditor lms-evaluation evaluate <model_id> --submit   # evaluate and commit
dincli auditor lms-evaluation reveal <model_id>              # after the owner opens reveals

evaluate --submit saves the salt locally before sending each commit. Rerunning it skips models you have already committed, so your saved reveal data stays valid.

A local model is approved for aggregation when at least 2 of its batch's auditors have revealed, at least 2 voted it eligible, and its median score meets the GI's pass score. Several independent auditors per model means no single auditor decides anything, and every vote is visible on-chain once revealed.

Rewards

When the GI ends, 20% of its reward pool is shared among auditors in proportion to how many votes each revealed. Rewards are pulled on-chain with claimReward(gi), then claimRewards(), on the model's DINTaskAuditor. There is no dincli claim command yet.

What gets an auditor slashed

The model's DINTaskAuditor carries out auditor slashing itself, when the model owner triggers it at the end of the GI:

  • Missed vote (S1). You registered and were assigned a batch, but didn't reveal a vote. This includes committing and never revealing. The penalty is a partial slash, 30% of the minimum stake by default. Repeat offences escalate under S5 to a full slash plus a jail period.
  • Score deviation (S3). Scoring far from your batch's median is designed as a full slash, but it ships disabled (shadow mode) on DevNet 2.0.

Slashes reach stake in the unbonding queue too, so exiting doesn't dodge a penalty.

Disputing bad test data

If the test data for your batch can't be decrypted or doesn't match the owner's commitment, any auditor of that batch can open a test-data dispute by posting a 100 DIN bond, before the GI's rewards are settled. The owner then has about one day to reveal the dataset key.

  • The key checks out: the bond is forfeited.
  • It doesn't, or the owner stays silent: the dispute is upheld. The bond is returned, the owner forfeits 25% of the GI reward pool (unless the GI settled in the meantime), and the batch is reassigned.

There's no dincli command for disputes yet.

Further reading

Introduction

DIN Components

Network Roles

Clone this wiki locally