Why does attesting my LLM inference still let the operator infer what I asked?
Opportunity
Trusted Execution Environments can now prove a specific model ran without modification, which is real progress on integrity. But attestation proves integrity, not confidentiality. During transformer inference the memory access patterns, cache timing, and PCIe bus traffic between the CPU and GPU create a measurable side channel that leaks information about the prompt even inside an attested enclave. September 2026 research demonstrates verbatim token leakage through this channel on H100 configurations. Splitting the model across a trusted CPU and an untrusted GPU, which is required at production scale, enlarges the attack surface in ways that current enclave designs do not address.
Why it matters
Side-channel hardening is the missing half of verifiable AI compute because attestation proves integrity but leaves prompt confidentiality undefended.
How I score the opportunity
The Opportunity Score is my own read, not a measurement: how much it hurts, how often it bites, and how little exists to solve it today. Higher means I think it is more worth building.
How much pain it causes when it shows up.
How often people actually run into it.
How little good tooling exists for it today.
More problems worth solving
What does an AI agent's bank account actually look like?
AI x CryptoCan an on-chain organization run by agents avoid becoming a scam machine?
AI x CryptoHow do you prove a photo or a voice is real without a platform vouching for it?
AI x CryptoWhy is on-chain identity either nothing or your entire life?
AI x CryptoHow do I audit which agent acted under my identity across a delegation chain?
AI x CryptoWhy does every trade my agent makes create a liability I cannot measure?