Mechanism · Model identity attestation
Underlying attestation can be forged or relayed
On this page
Evidence scope
Critical for the enclave route against an operator with physical access to affected hardware, or control of an unpatched SEV-SNP hypervisor. It does not apply to the recomputation route. PAL*M excludes physical attacks, and Tinfoil acknowledges this boundary 2 13.
The enclave route inherits the platform-specific TEE attestation failures. Intel TDX forgery and H100 relay were demonstrated with physical access and host control 9. Battering RAM defeated AMD SEV-SNP attestation on DDR4 servers; RMPocalypse did so from malicious host software on platforms without AMD's fixes 10 11 12. These demonstrate failures of the trust roots, not of each model-commitment protocol.
Response
The TEE.fail authors report that physical interposer attacks are outside Intel's and AMD's threat models. AMD reports fixes for RMPocalypse 9 12.