Mechanism · TEE remote attestation for AI workloads
H100 attestation not bound to a specific confidential VM
On this page
Evidence scope
The demonstration combines a genuine H100 report with forged Intel TDX evidence. It depends on the CPU attestation already being defeated; a GPU report alone does not demonstrate that an intact CPU-to-GPU trust chain was bypassed 3.
The TEE.fail authors fetched genuine H100 confidential-computing attestations from a rented server running their TDX VM. They combined these with forged TDX quotes. A proxy running outside any TEE then passed both the TDX and the GPU attestation checks. The authors attribute this to NVIDIA not binding the H100 to the identities of specific VMs. Their site states more generally that NVIDIA's attestation reports are not bound to a specific confidential VM or CPU. Intel, AMD, NVIDIA and the affected deployments acknowledged the findings, according to the authors, and the affected deployments were working on mitigations. The attack does not target NVIDIA's confidential-computing components directly, so the authors state that there are no mitigations on the NVIDIA side 3.
Sources: [3]