Skip to content
AI x Crypto

Why does attesting my LLM inference still let the operator infer what I asked?

80

机会

Trusted Execution Environments can now prove a specific model ran without modification, which is real progress on integrity. But attestation proves integrity, not confidentiality. During transformer inference the memory access patterns, cache timing, and PCIe bus traffic between the CPU and GPU create a measurable side channel that leaks information about the prompt even inside an attested enclave. September 2026 research demonstrates verbatim token leakage through this channel on H100 configurations. Splitting the model across a trusted CPU and an untrusted GPU, which is required at production scale, enlarges the attack surface in ways that current enclave designs do not address.

为什么重要

Side-channel hardening is the missing half of verifiable AI compute because attestation proves integrity but leaves prompt confidentiality undefended.

我如何评估机会

机会评分是我的个人判断,而非量化指标:痛苦程度、发生频率,以及当前解决方案的匮乏程度。分数越高,意味着我认为越值得去构建。

严重性7/10

出现时造成的痛苦程度。

频率6/10

人们实际遇到它的频率。

空白空间9/10

当前针对它的优质工具有多匮乏。

更多值得解决的问题