Implementation · PySyft double-blind evaluations

Physical attack boundary

On this page

← All known flaws

SignificantOpen questionOpenInherited evidence

Evidence scope

An inherited concern for the pilot's Intel TDX and H100 stack, not a demonstrated PySyft exploit. The pilot relies on Google-managed attestation and assumes limited incentives for cloud-provider and hardware-vendor collusion 1. A physical attacker who defeats the trust root that this workflow accepts would defeat its confidentiality and veracity.

The TEE findings include physical-host attacks that forge TDX attestations and a demonstration pairing forged TDX evidence with relayed H100 attestations 3 4. The pilot's report describes a TDX and H100 deployment, but does not test that deployment against these attacks 1.

Response

The attack researchers report that physical interposer attacks are outside Intel's threat model. They recommend physically secure servers 3 4.

Sources: [1] · [3] · [4]

Search

Full search page