Skip to content
AI x Crypto

Why does attesting my LLM inference still let the operator infer what I asked?

80

Cơ hội

Trusted Execution Environments can now prove a specific model ran without modification, which is real progress on integrity. But attestation proves integrity, not confidentiality. During transformer inference the memory access patterns, cache timing, and PCIe bus traffic between the CPU and GPU create a measurable side channel that leaks information about the prompt even inside an attested enclave. September 2026 research demonstrates verbatim token leakage through this channel on H100 configurations. Splitting the model across a trusted CPU and an untrusted GPU, which is required at production scale, enlarges the attack surface in ways that current enclave designs do not address.

Tại sao quan trọng

Side-channel hardening is the missing half of verifiable AI compute because attestation proves integrity but leaves prompt confidentiality undefended.

Cách tôi đánh giá cơ hội

Điểm Cơ Hội là đánh giá riêng của tôi, không phải một phép đo chính xác: mức độ gây khó chịu, tần suất xuất hiện và sự khan hiếm của giải pháp hiện có. Điểm càng cao, tôi càng cho rằng vấn đề đó càng đáng để xây dựng.

Mức độ nghiêm trọng7/10

Mức độ phiền toái nó gây ra khi xuất hiện.

Tần suất6/10

Tần suất mọi người thực sự gặp phải nó.

Khoảng trắng9/10

Có rất ít công cụ tốt để xử lý nó hiện nay.

Thêm các vấn đề đáng giải quyết