Mechanism · TEE remote attestation for AI workloads
Sources
On this page
- BNVIDIA (2025). NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper). NVIDIA documentation. Source recordSupports: GPU CC architecture, CPU-TEE pairing, multi-GPU modes, threat model scope, performance counters in CC mode and NVIDIA's side-channel reason · pp. 6-18
- CE. Apsey et al. (2023). Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI. NVIDIA Technical Blog. Source recordSupports: H100 root of trust, device identity key, attestation report, launch performance · blog, sections on root of trust and performance
- AJ. Chuang et al. (2026). TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition. 2026 IEEE Symposium on Security and Privacy (SP). Source recordSupports: TEE design aim; memory-bus interposition attack; Intel PCK extraction and forged SGX/TDX attestations; SEV-SNP OpenSSL key recovery; H100 attestation relay; disclosure and vendor positions · Abstract; §1.1-1.2; §3; §8.3; §10.2; site FAQ
- AJ. De Meulemeester et al. (2026). Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing. 47th IEEE Symposium on Security and Privacy (S&P 2026). Source recordSupports: Battering RAM: DDR4 interposer cost; Scalable SGX plaintext access and provisioning-key extraction; SEV-SNP attestation breach by launch-digest replay; DDR4-only scope; Intel and AMD positions · Abstract; §1 contributions; site FAQ
- AA. Seto et al. (2025). WireTap: Breaking Server SGX via DRAM Bus Interposition. 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Source recordSupports: WireTap: DDR4 interposer cost; extraction of the SGX Quoting Enclave attestation key and forged quotes; DDR5 Xeons not affected; Intel position and mitigation · Abstract; site FAQ
- AB. Schlüter & S. Shinde (2025). RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP. 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Source recordSupports: RMPocalypse: software-only RMP corruption by a malicious hypervisor; forged SEV-SNP attestation, debug, memory access and register replay; affected Zen generations; CVE · Abstract; site; responsible disclosure
- BAMD (2025). SEV-SNP RMP Initialization Vulnerability (AMD-SB-3020). AMD product security bulletin. Source recordSupports: AMD's severity rating and firmware mitigations for CVE-2025-0033 (vendor-reported) · Mitigation tables; revision history
- BC. Schnabl et al. (2025). Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments. ICML 2025 Workshop on Technical AI Governance. Source recordSupports: audit protocol, AWS Nitro prototype, overheads, vendor trust, cited TEE attacks and image revocation · §2, §3, §5 Table 2, §7
- BP. Chantasantitam et al. (2026). PAL*M: Property Attestation for Large Generative Models. arXiv. Source recordSupports: property attestation on TDX + H100, REPORTDATA binding, overheads, threat model exclusions, code status · Abstract; §3-§6, Tables 2-6
- CTinfoil Team (2026). How Tinfoil Proves Exactly What Model Is Running. Tinfoil. Source recordSupports: launch-state vs runtime; dm-verity weight binding · sections on the challenge and the three phases
- CGloria Z (2026). On TEEs for Privacy-Preserving Monitoring in AI Governance. MIRI Technical Governance Team. Source recordSupports: international threat model, vendor root of trust, measurement incompleteness, hashing-scheme warning, deployment vs chip-wide gap, process-level enforcement, counter side channels
- AA. Dhar et al. (2025). GuardAIn: Protecting Emerging Generative AI Workloads on Heterogeneous NPU. 2025 IEEE Symposium on Security and Privacy. Source recordSupports: device-only NPU TEE with task attestation; overheads; threat model · Abstract; threat model; evaluation
- BA. O'Gara et al. (2025). Hardware-Enabled Mechanisms for Verifying Responsible AI Development. arXiv. Source recordSupports: open question on TEEs for verifying AI training at scale · §2.2.4
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordSupports: existing technologies need hardening for adversarial settings · Key findings
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: physical-access key extraction caveat for encrypted memory · p. 20
- CFuture of Life Institute (2023). Exploration of secure hardware solutions for safe AI deployment. Future of Life Institute. Source recordSupports: FLI and Mithril SGX proof-of-concept and its stated limitations
- BJ. Petrie & O. Aarne (2025). Technical Options for Flexible Hardware-Enabled Guarantees. arXiv. Source recordSupports: TEE-backed software vs physical access; early-access CC lacked multi-node · sections on software/TEE options
- BTinfoil (2026). A primer on secure enclaves. Tinfoil documentation. Source recordSupports: Tinfoil hardware, trust model, report signing keys, documented limitations (provider-reported) · Supported hardware; Trust model; Limitations
- BTinfoil (2026). Backend infrastructure. Tinfoil documentation. Source recordSupports: memory encryption against host software, reproducible builds and transparency log, client verification, boot-time GPU attestation check (provider-reported)
- BTinfoil (2026). How verification works in Tinfoil. Tinfoil documentation. Source recordSupports: production deployment of Tinfoil's inference enclaves (provider-reported) · In-band vs. out-of-band verification
- BTinfoil (2026). modelwrap: Reproducible dm-verity read-only image of Huggingface models. GitHub. Source recordSupports: public open-source implementation (v0.3.0)
- CC. Su (2024). Now in General Availability: NVIDIA H100 GPUs in Microsoft Azure Confidential Virtual Machines. NVIDIA Blog. Source recordSupports: general availability of Azure confidential VMs with H100 GPUs (vendor-reported)
- CJ. Yagnik (2025). Private AI Compute: our next step in building private and helpful AI. Google blog (The Keyword). Source recordSupports: Google Private AI Compute: remote attestation to a sealed TPU environment (provider-reported)
- CApple Security Engineering and Architecture (SEAR) (2024). Private Cloud Compute: A new frontier for AI privacy in the cloud. Apple Security Research blog. Source recordSupports: Apple PCC: devices send requests only to nodes attesting to software in a public transparency log (provider-reported)
- CApple Security Engineering and Architecture (SEAR) (2026). Expanding Private Cloud Compute. Apple Security Research blog. Source recordSupports: Apple PCC extended to Google Cloud on NVIDIA confidential computing and Intel TDX (provider-reported)
- CD. Selmanaj (2026). Beyond Prompt Injection: Hacking Apple's Private Cloud Compute. Sentry blog. Source recordSupports: independent finding that a PCC node with tampered configuration passed attestation; fix
- CAnthropic & Pattern Labs (2025). Confidential Inference via Trusted Virtual Machines. Anthropic research. Source recordSupports: Anthropic's confidential inference design sketch (provider-reported)
- BMeta (2026). Private Processing for WhatsApp: Technical White Paper and Security Guide. Meta. Source recordSupports: WhatsApp Private Processing hardware and client attestation checks (provider-reported)
- CTrail of Bits (2026). What we learned about TEE security from auditing WhatsApp's Private Inference. Trail of Bits blog. Source recordSupports: Trail of Bits audit of WhatsApp Private Processing: finding counts, unmeasured configuration data, missing freshness, fixes, SEV-SNP physical-attack caveat
- BTrail of Bits (2025). Meta WhatsApp Private Processing (security review). Trail of Bits publications library. Source recordSupports: Trail of Bits' finding counts by severity and titles of the eight high-severity findings, including unmeasured environment variables and ACPI tables and unverified GPU attestation
- BNVIDIA (2026). NVIDIA Trusted Computing Solutions Release Notes (R595 TRD1). NVIDIA documentation. Source recordSupports: confidential modes generally available in NVIDIA's R595 release (April 2026); no multi-node mode listed (vendor-reported)
- AR. Zhang et al. (2026). StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack Engine. 35th USENIX Security Symposium (USENIX Security '26). Source recordSupports: StackWarp: software-only integrity break of SEV-SNP guests on Zen 1-5; AMD microcode patches
- AJ. De Meulemeester et al. (2026). DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes. 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26). Source recordSupports: DDRop: active DDR5 interposer cost; debug-mode forcing and forged attestation reports on up-to-date TDX; SGX and SEV-SNP integrity breaks; vendor positions and advisories · Abstract; threat model; case studies; site FAQ
- AB. Schlüter et al. (2026). Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP. 35th USENIX Security Symposium (USENIX Security '26). Source recordSupports: Fabricked: software-only Infinity Fabric misconfiguration; arbitrary read and write and forged SEV-SNP attestation on Zen 5 · Abstract; evaluation
- BAMD (2026). SEV-SNP Routing Misconfiguration (AMD-SB-3034). AMD product security bulletin. Source recordSupports: AMD's severity rating and firmware mitigations for CVE-2025-54510 (vendor-reported) · Summary; mitigation tables
- AZ. Gu et al. (2026). Blueprint, Bootstrap, and Bridge: A Security Look at NVIDIA GPU Confidential Computing. Proceedings of the 9th MLSys Conference (MLSys 2026). Source recordSupports: independent security analysis of NVIDIA GPU confidential computing: residual metadata, timing and coordination leaks; disclosure to NVIDIA · Abstract; conclusion
- BM. Shen & Y. Qin (2026). Insecure Despite Proven Updated: Extracting the Root VCEK Seed on EPYC Milan via a Software-Only Attack. arXiv. Source recordSupports: software-only extraction of the SEV-SNP VCEK root seed on EPYC Milan via firmware downgrade; forged reports for any firmware version · Abstract; contributions; disclosure
- BAMD (2026). MilanLaunchy Firmware Loader (AMD-SB-3045). AMD product security bulletin. Source recordSupports: AMD's view of MilanLaunchy as a legacy attack mitigated in 2021 (vendor-reported) · Summary