sNPU: Trusted Execution Environments on Integrated NPUs
Erhu Feng, Dahu Feng, Dong Du, Yubin Xia, Haibo Chen
Abstract
Trusted execution environment (TEE) promises strong security guarantee with hardware extensions for securitysensitive tasks. Due to its numerous benefits, TEE has gained widespread adoption, and extended from CPU-only TEEs to FPGA and GPU TEE systems. However, existing TEE systems exhibit inadequate and inefficient support for an emerging (and significant) processing unit, NPU. For instance, commercial TEE systems resort to coarse-grained and static protection approaches for NPUs, resulting in notable performance degradation (10%-20%), limited (or no) multitasking capabilities, and suboptimal resource utilization. In this paper, we present a secure NPU architecture, known as sNPU, which aims to mitigate vulnerabilities inherent to the design of NPU architectures. First, sNPU proposes NPU Guarder to enhance the NPU's access control. Second, sNPU defines new attack surfaces leveraging in-NPU structures like scratchpad and NoC, and designs NPU Isolator to guarantee the isolation of scratchpad and NoC routing. Third, our system introduces a trusted software module called NPU Monitor to minimize the software TCB. Our prototype, evaluated on FPGA, demonstrates that sNPU significantly mitigates the runtime costs associated with security checking (from upto 20% to 0%) while incurring less than 1% resource costs.
708
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7500b298-7e20-4444-99b7-3d0f13507806Cited by top-tier papers4
- SoK: Analysis of Accelerator TEE DesignsChenxu Wang, Junjie Huang, Yujun Liang, Xuanyao Peng et al.NDSS 2026 · 2 citations
- TZ-LLM: Protecting On-Device Large Language Models with Arm TrustZoneXunjie Wang, Jiacheng Shi, Zihan Zhao, Yang Yu et al.EuroSys 2026 · 1 citation
- Guardain: Protecting Emerging Generative AI Workloads on Heterogeneous NPUAritra Dhar, Clément Thorens, Lara Magdalena Lazier, Lukas CavigelliS&P 2025
- Memclave: Secure In-Memory Enclave for Untrusted HostsAmit Choudhari, Fabian van Rissenbeck, Christian RossowUSENIX Security 2026
Builds on30
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- FlashAttention: Fast and Memory-Efficient Exact Attention with IO-AwarenessTri Dao, Daniel Y. Fu, Stefano Ermon, Atri Rudra et al.NeurIPS 2022 · 5,493 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Gemmini: Enabling Systematic Deep-Learning Architecture Evaluation via Full-Stack IntegrationHasan Genc, Seah Kim, Alon Amid, Ameer Haj-Ali et al.DAC 2021 · 325 citations
Related papers
- HyperTEE: A Decoupled TEE Architecture with Secure Enclave ManagementYunkai Bai, Peinan Li, Yubiao Huang, Michael C. Huang et al.MICRO 2024 · 5 citations
- TNPU: Supporting Trusted Execution with Tree-less Integrity Protection for Neural Processing UnitSunho Lee, Jungwoo Kim, Seonjin Na, Jongse Park et al.HPCA 2022 · 37 citations
- FPGA-TrustZone: Security Extension of TrustZone to FPGA for SoC-FPGA Heterogeneous ArchitectureShupeng Wang, Xindong Fan, Xiao Xu, Shuchen Wang et al.DAC 2025 · 1 citation
- MOLE: Breaking GPU TEE with GPU-Embedded MCUHongyi Lu, Yunjie Deng, J. Sukarno Mertoguno, Shuai Wang et al.CCS 2025
- SGX-FPGA: Trusted Execution Environment for CPU-FPGA Heterogeneous ArchitectureKe Xia, Yukui Luo, Xiaolin Xu, Sheng WeiDAC 2021 · 39 citations
