I think one of the things that we also think is very challenging is defending against poisoning. We apparently have some early research on training certifications. We know how to do inference certification, but certification… basically, showing robustness for training is very challenging and difficult for randomly initialized… well, it’s probably impossible because any tiny change can be… there is a butterfly effect, you see. But we do have hope for fine tuning, basically.

