SAGE
SAGE, Software-based Attestation for GPU Execution, is a peer-reviewed scheme for checking that a GPU runs unmodified code, without hardware support for trusted execution on the GPU.
A verifier inside an Intel SGX enclave on the same host sends unpredictable challenges. The GPU computes a checksum over its own verification code, using all of its processing units, and must answer within a time threshold. Tampering adds work and shows up as a late answer.
The authors evaluated SAGE on an NVIDIA A100 and published the code. The MIRI verification overview cites it as prior work for memory challenges.
The verifier must know the GPU's exact hardware configuration, and the scheme trusts the SGX enclave. Remote helpers are excluded only if network latency exceeds the timing margin.
A peer-reviewed paper with public code shows timed attestation on an A100. No source reports use for an AI verification decision.
Assessed use: attesting code execution on a GPU that lacks hardware trusted-execution support
On this page
What it is
SAGE, Software-based Attestation for GPU Execution, is a scheme by Ivanov and colleagues at ETH Zürich and KAUST, published at USENIX ATC 2023 1. It checks that a GPU runs unmodified code without relying on trusted-execution hardware in the GPU 1. It is an application of timed challenge-response to a device's code, in the tradition of software-based attestation for embedded devices.
How it works
- Verifier. An SGX enclave running on the host acts as a local verifier 1.
- Challenge. The verifier sends unpredictable challenge values to the GPU 1.
- Checksum. A verification function on the GPU computes a checksum over its own instruction sequence 1. On the A100 the checksum uses all 108 streaming multiprocessors 1.
- Timing. The verifier accepts the checksum only if it is correct and arrives within a time threshold 1.
- Hand-over. A correct, timely answer gives the verifier a guarantee that the user's kernel is unmodified and is the code that then executes 1.
The MIRI system overview describes the effect on memory: the checksum kernel saturates the GPU's processing units and registers, "so the data must sit in HBM" 2.