Mechanism · TEE remote attestation for AI workloads

Side channels and other attacks by the host on CPU and GPU TEEs

On this page

← All known flaws

SignificantDemonstrated attackOpenMechanism-level evidence

Evidence scope

The cited studies concern particular CPU and GPU platforms and attack prerequisites. StackWarp has AMD microcode patches; the open class-level entry does not mean every cited defect is unmitigated or applies to every TEE-backed implementation 32.

PAL*M and Attestable Audits cite published side-channel, single-stepping, interrupt-injection and memory-aliasing attacks on Intel TDX and AMD SEV, including T-Time, TDXploit, CIPHER-LEAKS, Heckler and BadRAM. PAL*M treats them as out of scope 9. Attestable Audits proposes revoking vulnerable enclave images 8. Gloria Z notes that performance counters have themselves been used as a side channel, for example in CounterSEVeillance 11. New attacks of this kind continue to appear. In StackWarp, researchers at CISPA showed that a malicious hypervisor can shift the stack pointer of an SEV-SNP guest on AMD Zen 1 to Zen 5 processors with simultaneous multithreading enabled, which fully breaks the guest's integrity. AMD released microcode patches 32. On the GPU side, an independent analysis of NVIDIA's confidential computing by IBM Research and Ohio State University found that bulk command and data transfers are protected, but some metadata, timing behaviour and coordination signals remain in unprotected shared memory. The authors report that these can reveal computational behaviour and in some cases allow manipulation of operations. They disclosed the findings to NVIDIA 36.

Sources: [9] · [8] · [11] · [32] · [36]

Search

Full search page