Implementation · SAGE · Draft

Evidence & limits

On this page

R2Demonstrated for attesting code execution on a GPU that lacks hardware trusted-execution support

A peer-reviewed paper with public code shows timed attestation on an A100. No source reports use for an AI verification decision.

Assessed use: attesting code execution on a GPU that lacks hardware trusted-execution support

Rubric assessment

  • R1 met: the paper describes the protocol, the guarantees it gives and its assumptions 1.
  • R2 met through a public implementation and published measurements on an NVIDIA A100, under an adversary who runs malicious code on the GPU and CPU 1.
  • R3 not met: no source reports a production-grade release, or a party other than the authors relying on SAGE for a verification decision.

Confidence is medium: the evaluation is peer-reviewed, but covers one GPU model.

Gaps to the next level
  • A production-grade release, or use by a party other than the authors for a verification decision.
  • Evaluation on current AI accelerators and with AI inference or training workloads.
  • An independent security evaluation of the timing margin against proxy and optimisation attacks.

Assessed 2026-10-05 against rubric v1.1.

Evidence

  • A100. The authors evaluated SAGE on an NVIDIA A100 and report that it "is already practical today for executing code in a trustworthy way on GPUs" 1.
  • Code. The implementation is public 1.

Limitations

  • Known hardware. The authors assume that the verifier knows the exact hardware configuration of the GPU 1.
  • Remote helpers. The number of checksum iterations is tuned so that the detection threshold is smaller than the network latency, which prevents the use of a more powerful remote GPU 1.
  • Same host. The verifier is an enclave on the machine that holds the GPU 1. Trusted execution on the host is covered in TEE remote attestation for AI workloads.
  • Scope. The evaluation covers one GPU model 1.

Known flaws

Blockers

  • The verifier must know the exact hardware configuration of the GPU.

  • The verifier runs in an SGX enclave on the same host as the GPU, so the scheme inherits trust in that enclave.

Search

Full search page