{
  "schema_version": "1.4.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "I-0021",
    "slug": "sage-gpu-attestation",
    "title": "SAGE",
    "aliases": [
      "SAGE: Software-based Attestation for GPU Execution",
      "Software-based GPU attestation"
    ],
    "status": "draft",
    "last_reviewed": "2026-10-05",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "A software-only attestation scheme in which a GPU must compute a checksum over its own code within a time limit, without trusted GPU hardware.",
    "summary": "SAGE, Software-based Attestation for GPU Execution, is a peer-reviewed scheme for checking that a GPU runs unmodified code, without hardware support for trusted execution on the GPU. A verifier inside an Intel SGX enclave on the same host sends unpredictable challenges. The GPU computes a checksum over its own verification code, using all of its processing units, and must answer within a time threshold. Tampering adds work and shows up as a late answer. The authors evaluated SAGE on an NVIDIA A100 and published the code. The MIRI verification overview cites it as prior work for memory challenges. The verifier must know the GPU's exact hardware configuration, and the scheme trusts the SGX enclave. Remote helpers are excluded only if network latency exceeds the timing margin.",
    "technical": "- **Checksum.** In the reported experiment the function covers 524,288 bytes over 100,000 iterations and takes 0.4941 s on average on an A100 [[S-1306]].\n- **Threshold.** The detection threshold is 2.5 standard deviations above the mean runtime, for a false-positive probability of about 0.5% [[S-1306]].\n- **Bus latency.** The authors assume a PCIe latency of about 500 ns between verifier and GPU [[S-1306]].\n- **Utilisation.** With self-modifying code the implementation reaches 75% of maximum GPU utilisation [[S-1306]].",
    "category": "cryptographic-computational",
    "secondary_categories": [
      "on-chip"
    ],
    "verifies": [
      {
        "claim": "C-0005",
        "role": "supporting",
        "note": "Attests that unmodified code executes on the GPU (S-1306)."
      }
    ],
    "threat_model": "adversarial",
    "adversarial_evaluation": "analysis",
    "hardware_requirement": "existing-features",
    "prover_cooperation": "required",
    "confidentiality": "preserving",
    "depends_on": [],
    "readiness": {
      "assessment": true,
      "level": "R2",
      "scope": "attesting code execution on a GPU that lacks hardware trusted-execution support",
      "rubric_version": "1.1",
      "rationale": "A peer-reviewed paper with public code shows timed attestation on an A100. No source reports use for an AI verification decision.\n\n- **R1** met: the paper describes the protocol, the guarantees it gives and its assumptions [[S-1306]].\n- **R2** met through a public implementation and published measurements on an NVIDIA A100, under an adversary who runs malicious code on the GPU and CPU [[S-1306]].\n- **R3** not met: no source reports a production-grade release, or a party other than the authors relying on SAGE for a verification decision.\n\nConfidence is medium: the evaluation is peer-reviewed, but covers one GPU model.",
      "evidence": [
        "S-1306"
      ],
      "next_level_gaps": [
        "A production-grade release, or use by a party other than the authors for a verification decision.",
        "Evaluation on current AI accelerators and with AI inference or training workloads.",
        "An independent security evaluation of the timing margin against proxy and optimisation attacks."
      ],
      "confidence": "medium",
      "assessed_by": [
        "ai-draft"
      ],
      "assessed_on": "2026-10-05",
      "status": "current",
      "dispute": null
    },
    "flaws": [
      {
        "assessment": true,
        "title": "Self-modifying code limits the timing margin",
        "kind": "open-question",
        "severity": "minor",
        "status": "open",
        "description": "The authors report that their implementation reaches 75% of maximum GPU utilisation when the checksum uses self-modifying code, and that this limits the time difference caused by an adversary who inserts instructions into the checksum loop. They note that other cache-eviction strategies could raise utilisation.",
        "sources": [
          "S-1306"
        ],
        "response": null
      }
    ],
    "blockers": [
      {
        "text": "The verifier must know the exact hardware configuration of the GPU.",
        "theme": "hardware-trust",
        "blocked_by": null,
        "sources": [
          "S-1306"
        ]
      },
      {
        "text": "The verifier runs in an SGX enclave on the same host as the GPU, so the scheme inherits trust in that enclave.",
        "theme": "hardware-trust",
        "blocked_by": null,
        "sources": [
          "S-1306"
        ]
      }
    ],
    "challenge_themes": [
      "hardware-trust",
      "protocol-soundness",
      "adversarial-validation"
    ],
    "organizations": [],
    "people": [],
    "sources": [
      {
        "source": "S-1306",
        "supports": "protocol; guarantees; assumptions; A100 evaluation; threshold; attacks considered; limitations; code location",
        "locator": "abstract; §3–§8; Table 1"
      },
      {
        "source": "S-0018",
        "supports": "description of SAGE's checksum kernel as forcing data into GPU memory",
        "locator": "§5.1.2"
      }
    ],
    "concepts": [
      "K-0001",
      "K-0002",
      "K-0004",
      "K-0005",
      "K-0018"
    ],
    "kind": "research-prototype",
    "developer": [],
    "realises": [
      "M-0016"
    ],
    "repo": "https://github.com/spcl/sage",
    "type": "implementation",
    "url": "https://trustbutveri.fyi/implementations/sage-gpu-attestation/",
    "source_file": "content/implementations/sage-gpu-attestation.md",
    "flags_all": [],
    "body_markdown": "## What it is\n\nSAGE, Software-based Attestation for GPU Execution, is a scheme by Ivanov and colleagues at ETH Zürich and KAUST, published at USENIX ATC 2023 [[S-1306]]. It checks that a GPU runs unmodified code without relying on trusted-execution hardware in the GPU [[S-1306]]. It is an application of [[M-0016|timed challenge-response]] to a device's code, in the tradition of software-based attestation for embedded devices.\n\n## How it works\n\n1. **Verifier.** An SGX enclave running on the host acts as a local verifier [[S-1306]].\n2. **Challenge.** The verifier sends unpredictable challenge values to the GPU [[S-1306]].\n3. **Checksum.** A verification function on the GPU computes a checksum over its own instruction sequence [[S-1306]]. On the A100 the checksum uses all 108 streaming multiprocessors [[S-1306]].\n4. **Timing.** The verifier accepts the checksum only if it is correct and arrives within a time threshold [[S-1306]].\n5. **Hand-over.** A correct, timely answer gives the verifier a guarantee that the user's kernel is unmodified and is the code that then executes [[S-1306]].\n\nThe MIRI system overview describes the effect on memory: the checksum kernel saturates the GPU's processing units and registers, \"so the data must sit in HBM\" [[S-0018]].\n\n## Evidence\n\n- **A100.** The authors evaluated SAGE on an NVIDIA A100 and report that it \"is already practical today for executing code in a trustworthy way on GPUs\" [[S-1306]].\n- **Code.** The implementation is public [[S-1306]].\n\n## Limitations\n\n- **Known hardware.** The authors assume that the verifier knows the exact hardware configuration of the GPU [[S-1306]].\n- **Remote helpers.** The number of checksum iterations is tuned so that the detection threshold is smaller than the network latency, which prevents the use of a more powerful remote GPU [[S-1306]].\n- **Same host.** The verifier is an enclave on the machine that holds the GPU [[S-1306]]. Trusted execution on the host is covered in [[M-0008]].\n- **Scope.** The evaluation covers one GPU model [[S-1306]].",
    "body_text": "What it is SAGE, Software-based Attestation for GPU Execution, is a scheme by Ivanov and colleagues at ETH Zürich and KAUST, published at USENIX ATC 2023 [S-1306]. It checks that a GPU runs unmodified code without relying on trusted-execution hardware in the GPU [S-1306]. It is an application of timed challenge-response to a device's code, in the tradition of software-based attestation for embedded devices. How it works 1. Verifier. An SGX enclave running on the host acts as a local verifier [S-1306]. 2. Challenge. The verifier sends unpredictable challenge values to the GPU [S-1306]. 3. Checksum. A verification function on the GPU computes a checksum over its own instruction sequence [S-1306]. On the A100 the checksum uses all 108 streaming multiprocessors [S-1306]. 4. Timing. The verifier accepts the checksum only if it is correct and arrives within a time threshold [S-1306]. 5. Hand-over. A correct, timely answer gives the verifier a guarantee that the user's kernel is unmodified and is the code that then executes [S-1306]. The MIRI system overview describes the effect on memory: the checksum kernel saturates the GPU's processing units and registers, \"so the data must sit in HBM\" [S-0018]. Evidence - A100. The authors evaluated SAGE on an NVIDIA A100 and report that it \"is already practical today for executing code in a trustworthy way on GPUs\" [S-1306]. - Code. The implementation is public [S-1306]. Limitations - Known hardware. The authors assume that the verifier knows the exact hardware configuration of the GPU [S-1306]. - Remote helpers. The number of checksum iterations is tuned so that the detection threshold is smaller than the network latency, which prevents the use of a more powerful remote GPU [S-1306]. - Same host. The verifier is an enclave on the machine that holds the GPU [S-1306]. Trusted execution on the host is covered in TEE remote attestation for AI workloads. - Scope. The evaluation covers one GPU model [S-1306].",
    "referenced_by": [
      {
        "id": "M-0016",
        "title": "Timed challenge-response and memory-occupation challenges",
        "url": "https://trustbutveri.fyi/mechanisms/timed-challenge-response/"
      },
      {
        "id": "I-0020",
        "title": "Data-centre memory challenging",
        "url": "https://trustbutveri.fyi/implementations/data-centre-memory-challenging/"
      }
    ]
  }
}