Source · Tier A · Peer-reviewed

Blueprint, Bootstrap, and Bridge: A Security Look at NVIDIA GPU Confidential Computing

Z. Gu, E. Valdez, S. Ahmed, J. J. Stephen, M. V. Le, H. Jamjoom, S. Zhao, Z. Lin. 2026. Proceedings of the 9th MLSys Conference (MLSys 2026).

Originalhttps://arxiv.org/abs/2507.02770
DOI10.48550/arXiv.2507.02770
arXiv2507.02770
VersionRead arXiv v2 (2026-04-17), whose header names the 9th MLSys Conference (Bellevue, 2026). v1 (2025-07-03) was titled "NVIDIA GPU Confidential Computing Demystified".
Accessed2026-09-25
NoteIndependent security analysis (IBM Research and The Ohio State University) of NVIDIA's GPU confidential computing on Hopper. Concludes that bulk command and data transfers are protected, but some metadata, timing behaviour and coordination signals remain in unprotected shared memory, which can reveal computational behaviour and in some cases allow manipulation of operations ("a partial loss of integrity"). Findings were disclosed to NVIDIA PSIRT. No attestation break is reported.

Cited by

Search

Full search page