TrustGuard: A Containment Architecture with Verified Output