MISAKA / Design Whitepaper

MISAKA: A Peer-to-Peer Market for Verifiable AI Computation

MISAKA Network

07 October 2026

MISAKA
Contents / 00–15 · appendices

00/Abstract

Machine intelligence becomes an economic resource when its execution can be identified, checked, and accounted for without relying on a single provider. MISAKA proposes a peer-to-peer network in which useful AI computation supplies the work underlying a post-quantum BlockDAG. Producers execute registered models and commit their results; bonded Panel seats verify those claims; a bounded challenge and court process resolves disputes. Native MSK rewards follow verified work and its settlement rather than a provider’s self-reported usage.

The design separates exact execution semantics from the cost of verifying an execution. Canonical tensor programs define what a model computes, while committed constraint checks allow verifiers to examine large computations without routinely repeating every inference. Versioned kernels bound the accepted language, resource use, and terminal adjudication. Model repositories, service memberships, and an opt-in improvement protocol connect this verification layer to a market for models and their use. The resulting system coordinates computation, evidence, incentives, and settlement in one publicly auditable ledger.

0.1/Introduction

An AI service can deliver a valuable answer while leaving the user unable to establish which weights, arithmetic, runtime, or input state produced it. A blockchain can record the payment, but an opaque API response does not by itself establish computational work. Hash-only work is easy to compare yet does not authenticate a model’s output. Peer reputation can express preference, but preference alone does not establish that a claimed execution occurred.

MISAKA treats a model execution as a statement with explicit semantics and evidence. The network asks whether the registered computation was performed correctly, how much canonical work it represents, and which obligations must close before that work becomes settled. These are different questions from whether the answer is useful, safe, or better than another model. Utility enters through service demand and controlled model evaluation; computational correctness enters through verification. Keeping the two separate prevents a popularity score from becoming a proof of execution.

Sources [20][4][11]

01/Network model

The network consists of validating nodes, computation producers, bonded verification seats, challengers, model developers, and consumers. One operator may perform several roles, but a role does not grant discretionary authority over another operator’s claim. Full nodes apply deterministic ledger rules. Producers supply execution and evidence. Panel seats attest to assigned verification scopes. Challengers submit bounded disputes. Developers publish artifacts and service policies; consumers request work and exercise the rights those policies define.

A model class binds a canonical program, model artifact, input and output interpretation, context envelope, kernel version, and verification rules. A human-readable repository or model line can have several versions; the identity used for computation must still identify the exact class. Changing weights or semantics creates a different computational identity. A job binds the class, canonical input, generation settings, initial state, and a finite work envelope. Domain-separated commitments prevent identities and signatures from being reused across networks, jobs, or protocol purposes.

MSK is the native accounting unit for fees, collateral, and protocol rewards. The public testnet validates the protocol design. Testnet balances are for testing and do not establish mainnet allocations or Panel qualification. The ledger’s state transition, not an external token price, determines computational entitlement.

Sources [2][14][29]

02/Canonical execution

PALW-TIR describes computation as a bounded tensor graph with declared shapes, typed state, a layer schedule, and a finite scan over positions. Its integer arithmetic specifies rounding, saturation, range behavior, and errors. A model’s semantic identity therefore does not depend on GPU scheduling, floating-point reduction order, or an operator’s reported hardware. An optimized kernel is acceptable when it preserves the canonical result and the required commitments.

Inputs include tokenization and preprocessing; outputs include the task’s canonical representation. Text generation binds decode controls and deterministic generation randomness. Embeddings, image generation, audio, video, and multimodal pipelines must name their own input, intermediate state, and output rules. Randomness used to generate an answer is separated from randomness used to choose a Panel or challenge a proof.

Conversion from a source model is a fidelity obligation. The program, tensor layout, calibration statistics, artifact hashes, and conformance vectors travel together. A smaller context or a reduced task defines a different profile; it is not evidence of support for the full advertised source model. Streaming independent checks preserve this obligation without requiring every onboarding tool to load an entire artifact into memory.

y = Exec_K(P, A, x, s₀; r_gen)
P: program · A: artifact · x: input · s₀: initial state · K: kernel semantics · r_gen: bound generation randomness.

03/Committed work and claims

A claim records an execution statement before verification authority is assigned. Its commitment binds the network, class, job, relevant state boundaries, result, and evidence roots. The producer authorizes that statement with its bonded key and makes the required material available. A signature establishes responsibility for the claim; it does not establish that the arithmetic is correct.

The lifecycle moves from Provisional to PanelBound, then to a receipt-backed licence and Final after the challenge conditions close. Disputes and data-availability demands create explicit branches of this state machine; a failed claim becomes Voided. Final is a computation-settlement condition. The reward’s release and vesting obligations remain separate accounting conditions.

For a long execution, a bounded root session can describe non-overlapping work slices. Each slice identifies its predecessor and result boundary and has a unique accounting key. The root does not earn the entire job’s reward simply by announcing it. Credit belongs to verified work ranges, and a history cannot count the same computation both as a slice, a root, and a later redemption.

Provisional → PanelBound → ReceiptLicensed → Final
Dispute and availability branches are omitted from this normal-path diagram.
Commit
Assign Panel
Verify & challenge
Settle
Figure 1 / Execution claims move through accountable verification before settlement.
Sources [8][30][31]

04/Work, incentives, and accounting

An operator cannot create work credit by naming a larger model, extending a trace with empty steps, or reporting more FLOPs. Canonical work is derived from the admitted program and the actual bounded job. Protocol-versioned coefficients map the relevant operation counts into an economic compute measure. Hash-ticket eligibility and the network work target determine admission; a model’s share is an observed result of accepted work rather than an administrator’s allocation of popularity.

Rewards distinguish production, verification, inclusion, and protocol reserves. The producer’s claim reward is committed to escrow at acceptance, named through settlement, and released through the ledger’s maturity and liability rules. Panel compensation follows credited verification duties. Increasing claim capacity or packing additional claims into a block must not multiply the reward budget. A batch splits a bounded budget; it does not create a fresh subsidy for every rider.

Capacity is constrained by verification supply, evidence bandwidth, available collateral, and outstanding obligations. Admission limits and a conservative capacity breaker protect those resources. A larger capacity parameter is a bound on what the system may admit, not a throughput measurement. Every work-credit and reward transition has an inverse for reorganization, and conservation is checked across producer, Panel, reserve, fee, and escrow legs.

Σ credit(sliceᵢ) ≤ CCU(job) ; Σ escrow(claims in batch) ≤ budget(batch)
Conservation constraints; the versioned protocol defines units, coefficients, rounding, and eligibility.

05/Bonds and independent Panels

A bond binds identity, payout authorization, collateral, and computational liability. Producer and seat exposure is reserved while obligations are open. Collateral covers defined misconduct; it must not be the only mechanism that keeps the clock alive. A large bond is not a certificate that a model ran correctly, and dividing one operator into many keys does not create independent verification.

Panel selection freezes a sealed claim and an eligible seat population before drawing assignments. A valid binding block records the draw rather than choosing a favourable seed. Selection must be independent of the binder’s identity, signature, timestamp, arrival order, and other cheaply replaceable fields. The design requires an explicit post-commit randomness construction and an adversarial bias model. Hashing a recent public value alone does not provide that argument.

For large models, a verification cell is a layer range crossed with a position segment. Seats can hold the weights and state needed for their assigned cells; committed boundary rows connect those cells to one execution. Readiness, scope coverage, independent assignment, and exposure rules apply before receipts count. Verification vertices amortize one signature across a bounded round of verdicts, while equivocation evidence binds a seat to contradictory signed statements. A silent Panel can be replaced; unavailable verification does not by itself establish producer fraud.

06/Constraint verification

The large-model verification path checks the relations of a committed computation. Matrix products use randomized projection checks where appropriate; layered relations can use a reviewed GKR or sum-check composition. Quantization, rounding, range limits, nonlinear operations, expert routing, indexing, authenticated memory, and inter-segment boundaries must also be covered. Proving isolated products while leaving their wiring unconstrained is not a proof of the job.

For the relation C = AB over an appropriate finite field, a fresh random vector r tests Cr = A(Br). A fixed false product has an escape bound determined by the field and repetitions under the specified assumptions. The representation must also establish the intended integer ranges and carries: a congruence is not automatically the exact integer computation. This example describes one checker, not the soundness of a whole model.

Outputs, evidence, and each interactive prover message are fixed before the corresponding challenge. Challenges are separated by network, claim, suite, stage, round, and repetition. Receipts bind the suite, evidence root, and verified scope. Final requires the prescribed positive receipts, whole-claim coverage, availability, and closed challenge conditions. An audit-only receipt cannot substitute for missing verification coverage.

The design target for the conditional whole-claim computational-check error is ε_check ≤ 2⁻¹²⁸. The bound includes every constraint family and the commitment/opening construction. Panel compromise, randomness bias, data withholding, censorship, and repeated attempts are separate terms. Multiple signatures over one public challenge do not automatically multiply security. A court handles a filed dispute; it does not retroactively detect every error that escaped all checkers.

Pr[any false acceptance] ≤ min(1, Q · ε_check + ε_env)
Q bounds adversarial attempts and retries; ε_env bounds failures of the stated Panel, randomness, availability, and binding assumptions.
Sources [7][11][27]

07/Data availability and exact court

A root commits to bytes but does not ensure that anyone can obtain them. Artifacts, inputs, state boundaries, witnesses, and proof transcripts therefore have explicit serving and retention obligations. Merkle openings and authenticated directories let a verifier request the material of a bounded scope. Held commitments identify responsibility for retaining material; the number of peers or the existence of a magnet link is not a substitute for serving it when challenged.

A dispute narrows a disagreement through committed boundaries to an admissible terminal relation. The exact court checks that relation under the named kernel semantics and authenticated evidence. Every round, opening, allocation, and deadline has a limit. A failed probabilistic check triggers localization; it is not, on its own, an exact slashing verdict. A producer’s withholding, a responder’s default, and a proven false execution have different evidence and attribution rules.

Long-context state can be held outside the ledger while roots, bounded openings, and the dispute route remain committed. Segmenting that state must preserve the original context and predecessor dependencies. State roots, reversible deltas, snapshots, and pruning witnesses reproduce the same obligations after reorganization or a pruned join. Local wall clocks and unpublished runtime choices cannot change the ledger’s verdict.

08/BlockDAG consensus and settlement

Concurrent blocks are ordered through a GHOSTDAG-derived ledger, with PALW work and settlement facts entering the selection rules. Block arrival, execution throughput, and settled security are distinct quantities. The PALW candidate comparator prioritizes the settled frontier, then safe work, then bounded live work, with a deterministic hash tie-break. Surrounding admission and reorganization rules must be applied with that comparator; the tuple alone is not the entire consensus protocol.

Claim-backed work slices give chain-eligible blocks fresh, uniquely accounted computation. Fast execution rounds consume bounded rights derived from work and carry transactions; reusing a settled credit does not manufacture new confirmations. BLUE status, selected-parent eligibility, clock advancement, work weight, and reward are specified independently for every block kind.

Useful model work is the normal security source. PALW-BASE-0 is a bounded reserve for idle periods, and heartbeats support clock progress when computation or verification is temporarily absent. The reserve’s Idle, Probe, and Normal states coordinate return to real work. Admission and coloring must prevent recovery traffic from displacing eligible model work; heartbeat-only progress cannot be presented as newly settled computation.

A payment is assessed against settled PALW anchors and the relevant ledger depth and reorganization policy. Counting many fast blocks, heartbeats, or DAA ticks is not equivalent to collecting independent settled work. Work-slice uniqueness, outstanding exposure limits, and deterministic ordering of conflicting spends are part of the same safety argument.

Order(chain) = lex(frontier_safe, weight_safe, weight_live, candidate_hash)
A summary of the PALW comparator: weight_live = weight_safe + bounded immature work.

09/Model admission and versioned kernels

Permissionless registration accepts model data through a bounded grammar, not arbitrary executable verifier code. A VerificationPlan names approved semantics, constraints, checker suites, task and context bindings, evidence formats, soundness parameters, and resource envelopes. Existing kernel families can express new model combinations through declarative plans. A genuinely new operation, memory rule, or adjudication relation requires a coordinated versioned kernel extension.

The design does not introduce a universal model VM, an uploaded CustomOp interpreter, a trusted enclave, or an operator committee as a fallback for missing verification semantics. A missing kernel is an explicit admission outcome. Supported lowering, source fidelity, legal court bounds, evidence availability, and sufficient verification capacity remain independent requirements. Listing a model and granting it useful-work eligibility are different transitions.

Onboarding tools exchange canonical artifact, layout, and bit-exact calibration identities and resume from verified stage outputs. Conformance includes independent execution of representative vectors and checks that cannot be silently skipped for a large artifact. The coverage objective is broad support for public model repositories at their complete advertised tasks and contexts. A dated census defines the denominator; catalogue entries, shortened profiles, or parser success are not counted as full-task registrations.

10/Model lines and service rights

A model line organizes an owner, versions, computational classes, published artifacts, and declared service policies. Its repository surface lets users inspect the identity and material behind a model. MISAKA Options exposes that model and repository market; MISAKA Studio connects model discovery and local execution to the same identity concepts. An interface presents ledger and artifact facts, but does not become an additional consensus authority.

A Model Position represents a membership or service-access relationship. It does not grant automatic income, a claim on mining rewards, or protocol governance power. Developers can define version access and service commitments that the ledger can represent; actual off-chain delivery remains a service obligation. A curve-based entry and exit mechanism determines the position’s exchange rules without promising a supported price.

Content delivery binds signed repository metadata and downloads to the relevant artifact commitments. A user distinguishes a public repository, an on-chain class, a qualified mining profile, and an available service. Those states must not be collapsed into one badge. Model provenance, versions, and declared entitlements stay inspectable even when the interface or storage provider changes.

Sources [15][9][4]

11/Learning and model improvement

Training, distillation, reinforcement learning, and candidate search take place outside consensus. The protocol evaluates the submitted artifact rather than requiring a particular training engine. An opt-in line opens an improvement epoch when its policy and settled usage conditions are met. It fixes dataset commitments, receives candidates, closes submission, and evaluates the parent and candidates on the same canonical inputs.

Hard cases and user data enter only through explicit data-use policies. Temporal hold-outs and committed setter material reduce candidate adaptation to a known test. Evaluation can combine canonical exact-match outputs, teacher-forced likelihood, registered judge models with bounded influence, and paired comparisons. A judge’s answer is still an evaluation instrument, not an unconditional truth about general intelligence.

Promotion requires the declared improvement margin, a positive lower confidence bound under the pinned integer statistical rule, and no excessive regression in the protected suites. Multiple candidates consume the policy’s multiple-testing budget. If no candidate passes, the incumbent remains. Full-weight and parent-plus-adapter artifacts receive distinct class identities; lineage, rollback, rewards, and vesting are state transitions that remain publicly reproducible.

promote(candidate) ⇔ LCB(improvement) > 0 ∧ regression ≤ ε_guard
A conceptual eligibility condition; the line policy fixes margins, test suites, statistical tables, and multiple-testing rules.

12/Native UTXO and EVM settlement

The design gives PALW chain selection and settlement sole authority over the native ledger. Deterministic full-node validation, Panel receipts, computation bonds, and courts remain necessary. A separate stake-voting finality service does not approve, delay, or override settled PALW work. Removing that finality role does not remove computation verification or ordinary peer discovery.

The UTXO-to-EVM transition is accounting inside the same MISAKA L1. A deposit consumes a valid native lock exactly once; a withdrawal creates the corresponding native output under the canonical EVM state. Reorganization reverses both sides against one state generation. This does not make an unrelated external chain inherit MISAKA settlement.

EVM latest, safe, and finalized heads express distinct conditions. Inclusion and optimistic execution may precede PALW settlement. A safe or finalized tag must be derived from the prescribed settled anchors and policy; missing history cannot promote the current tip by default. Migration of accounting and reward obligations preserves existing entitlements and cannot pay or mint the same obligation twice.

13/Running the network

A participant first identifies the network and its ruleset, obtains or prepares a model artifact, and verifies its identity and conformance material. A registrant prepares the class and verification plan, funds the required fees and bond, authorizes the registration, and submits it through a node or relay. Admission records explicit reasons and does not depend on trusting the preparer’s VPS or catalogue.

A producer acquires the required evidence-serving capacity and collateral, executes an eligible job, commits the result, and tracks the claim through Panel assignment, receipts, disputes, and settlement. A seat proves readiness for its assigned class and scope, verifies committed relations, and publishes the required positive receipts. Challengers and material providers complete the availability and court paths.

The remote-client path separates local model execution and signing from full-node operation. Untrusted builders can help prepare heavy artifacts; relays can submit authorized objects; eligible block builders can redeem specified work rights. These parties cannot redirect the bond-bound payout or waive admission, fee, evidence, and verification rules. The client verifies chain and artifact facts rather than treating agreement among several RPC URLs as cryptographic proof.

Public readers follow models through MISAKA Options, ledger activity through MISAKAScan, and local models through MISAKA Studio. Operational metrics distinguish produced, accepted, licensed, settled, paid, and voided work. One counter cannot replace the lifecycle.

Sources [9][10][13]

14/Security and collusion

The adversary may control several identities, submit false computation, grind tickets or challenge transcripts, withhold material, censor receipts, create conflicting spends, or attempt a private reorganization. The design binds work before randomness, caps immature influence and exposure, requires positive scope coverage, and makes contradictions attributable to signed obligations. Independence is evaluated at the operator level where the protocol can establish it; independent keys alone are insufficient.

Post-quantum transaction and obligation authorization uses ML-DSA-87 with network and purpose separation. Computational commitments and any proof-suite security arguments must also state their post-quantum assumptions. A post-quantum signature does not make arbitrary randomness, economics, or an unreviewed proof system secure. Shared public challenges and correlated operators remain part of the whole-claim analysis.

Liveness failures and arithmetic fraud are treated separately. A class whose verification or material supply is insufficient can lose admission capacity without forcing all other classes to stop. Recovery blocks keep time progressing without claiming settled AI work. Slashing follows evidence of the corresponding offence, while incorrect availability or court attribution cannot punish an honest seat for a producer’s unrelated default.

Correctness also requires bounded parsing and allocation, evidence retention, deterministic reorganization, and reproducible initial or pruned synchronization. Safety arguments cover the entire claim lifecycle, not only a successful matrix check. Economically rational deterrence is complementary to cryptographic bounds and cannot replace adversarial soundness.

15/Conclusion

MISAKA designs a market in which the identity, correctness, and settlement of AI computation are first-class ledger facts. Canonical model semantics identify the work; committed verification constrains its result; bonded responsibilities and exact dispute handling connect evidence to incentives; PALW settlement connects that work to native accounting.

The architecture scales by separating expensive execution from bounded verification, and by composing admitted kernel semantics rather than accepting arbitrary verifier programs. Repositories, service rights, and controlled improvement extend that foundation toward a model economy. Its organizing principle is that useful computation earns an accountable claim, and an accountable claim earns only the credit its evidence and settlement justify.

A / Notation

SymbolMeaning
P, A, KCanonical program, model artifact, and versioned kernel semantics.
CCU / PWUCanonical/economic compute and protocol work units; their versioned derivation and use are distinct.
Panel / cellBonded verification assignments; a cell is a layer range × position segment.
ε_checkConditional probability that verification accepts a false whole claim.
Q, ε_envAdversarial trial bound and the bound on failures of environmental assumptions.
LCB, ε_guardLower confidence bound and permitted regression under an improvement policy.
frontier_safe / weight_safeSettled frontier and accumulated Final work in the PALW candidate comparator.

B / References & design sources

This paper synthesizes the MISAKA RFCs, architecture decisions, specifications, and source code below. Equations are explanatory unless an exact source rule is identified. Source snapshot: 43f0bcb362d3.

  1. RFC-0001: PALW 推論サーフェスの欠落機能 — 決定論的な生成制御・サービング・入力拡張の設計
  2. RFC-0002: PALW Canonical Tensor IR v1 (PALW-TIR) — a bounded, deterministic integer tensor program as the consensus meaning of a class, with a reference evaluator and optional fused kernels
  3. RFC-0003: PALW Generative Model Classes — one job, determinism and output layer, and the class profiles on top of it
  4. RFC-0004: PALW Model Improvement Protocol — self-improvement and distillation over PALW-TIR
  5. RFC-0005: PALW model extensibility through versioned kernels — no BVM/GVM implementation
  6. RFC-0006: PALW layer-sharded panels — a seat verifies a layer range of an IR claim, crossed with a position segment, from the committed boundary rows and only those layers' weights; licences by parts with an outsider per shard and a recount over cells; a lie is detected by the shard that holds it and convicted by the one-move court that exists
  7. RFC-0007: PALW constraint verification — batched Freivalds/GKR Panel checks, evidence-bound receipts, and exact court on dispute
  8. RFC-0008: Claim-backed PALW consensus blocks — LLM work as the chain, not a side lane
  9. RFC-0009: PALW Remote Client — node を持たないモデル登録・claim・非保管型の報酬回収
  10. RFC-0010: Permissionless PALW Panel binding and claim completion
  11. RFC-0011: Permissionless model onboarding with probabilistic constraint verification and court on dispute
  12. RFC-0012 — PALW-only consensus and native EVM settlement: retire DNS validators and their reorg veto
  13. RFC-0013: Reproducible layouts and resource-bounded model onboarding tools
  14. ADR-0019: Migrate Signature Scheme from ML-DSA-65 to ML-DSA-87
  15. ADR-0095 — A position is a membership, not an income
  16. ADR-0103 — The context is held off the chain, and the chain carries a root, an opening and a logarithm
  17. ADR-0127 — PALW settles on its own, and its terms are not DNS terms
  18. ADR-0129 — A double spend needs the anchors, not the blocks
  19. ADR-0137 — A block buys one unit of work from any model, and a share is a result, not an input
  20. ADR-0144 — PALW pays for the inference you were going to run anyway
  21. ADR-0145 — Canonical work is derived, not declared; admission is earned, not registered
  22. ADR-0151 — Liveness is structural; collateral covers fraud
  23. ADR-0165 — Useful work carries the clock: the floor is the idle-only bonded fallback behind a floor state machine (A″), a REAL attempt carries the slot's tick (B); the bonded FALLBACK-V1 block and header-level floor invalidation are the next fence
  24. ADR-0166 — Verifier unavailability is not producer fraud
  25. ADR-0167 — The ×1000 capacity package: a fixed per-DAA PALW reward budget, riders, a lower-only breaker, and the ρ = 250 / ρ = 1000 steps
  26. ADR-0170 — The seed anchor is a window, not a span: a merged attempt anchors, the anchor survives span boundaries, and the admission jury and the schedule seeding read the latest anchor of `S − 24 … S − 1`
  27. ADR-0171 — Probabilistic constraint checks are the normal large-model verifier; the court resolves disputes exactly
  28. ADR-0172 — Model extensibility uses versioned kernels, not a universal VM
  29. Code — Canonical TIR class identity
  30. Code — PALW claims, obligations and state transitions
  31. Code — Reward-budget and capacity accounting
  32. Code — PALW candidate ordering
  33. Code — Model promotion
  34. Code — Native EVM accounting
  35. Code — Canonical ledger and EVM head processing
  36. Specification — PALW Canonical Tensor IR
  37. Specification — Layer-sharded Panels
  38. Specification — Model improvement

The numbered, continuous-reading paper structure takes inspiration from Bittensor: A Peer-to-Peer Intelligence Market. MISAKA’s mechanisms and equations follow its own design sources.

Additional PDF documents