Implementation · SAGE · Draft
Evidence & limits
On this page
R2Demonstrated for attesting code execution on a GPU that lacks hardware trusted-execution support
ReadinessMedium confidence
A peer-reviewed paper with public code shows timed attestation on an A100. No source reports use for an AI verification decision.
Assessed use: attesting code execution on a GPU that lacks hardware trusted-execution support
Rubric assessment
- R1 met: the paper describes the protocol, the guarantees it gives and its assumptions 1.
- R2 met through a public implementation and published measurements on an NVIDIA A100, under an adversary who runs malicious code on the GPU and CPU 1.
- R3 not met: no source reports a production-grade release, or a party other than the authors relying on SAGE for a verification decision.
Confidence is medium: the evaluation is peer-reviewed, but covers one GPU model.
Gaps to the next level
- A production-grade release, or use by a party other than the authors for a verification decision.
- Evaluation on current AI accelerators and with AI inference or training workloads.
- An independent security evaluation of the timing margin against proxy and optimisation attacks.
Assessed 2026-10-05 against rubric v1.1.
Evidence
Limitations
- Known hardware. The authors assume that the verifier knows the exact hardware configuration of the GPU 1.
- Remote helpers. The number of checksum iterations is tuned so that the detection threshold is smaller than the network latency, which prevents the use of a more powerful remote GPU 1.
- Same host. The verifier is an enclave on the machine that holds the GPU 1. Trusted execution on the host is covered in TEE remote attestation for AI workloads.
- Scope. The evaluation covers one GPU model 1.
Known flaws
Blockers
The verifier must know the exact hardware configuration of the GPU.
The verifier runs in an SGX enclave on the same host as the GPU, so the scheme inherits trust in that enclave.