Looking at their paper at [1], there's a gaping hole: there's no actual way to verify the contents of the running binaries. The binary hash they include in their signatures is self-reported, and can be modified. That's simply game over.
[1] https://github.com/Layr-Labs/d-inference/blob/master/papers/...