USENIX ATC2023顶会
SAGE: Software-based Attestation for GPU Execution
Andrei Ivanov, Benjamin Rothenberger, Arnaud Dethise, Marco Canini, Torsten Hoefler, Adrian Perrig
摘要
With the application of machine learning to security-critical and sensitive domains, there is a growing need for integrity and privacy in computation using accelerators, such as GPUs. Unfortunately, the support for trusted execution on GPUs is currently very limited - trusted execution on accelerators is particularly challenging since the attestation mechanism should not reduce performance. Although hardware support for trusted execution on GPUs is emerging, we study purely software-based approaches for trusted GPU execution. A software-only approach offers distinct advantages: (1) complement hardware-based approaches, enhancing security especially when vulnerabilities in the hardware implementation degrade security, (2) operate on GPUs without hardware support for trusted execution, and (3) achieve security without reliance on secrets embedded in the hardware, which can be extracted as history has shown. In this work, we present SAGE, a software-based attestation mechanism for GPU execution. SAGE enables secure code execution on NVIDIA GPUs of the Ampere architecture (A100), providing properties of code integrity and secrecy, computation integrity, as well as data integrity and secrecy - all in the presence of malicious code running on the GPU and CPU. Our evaluation demonstrates that SAGE is already practical today for executing code in a trustworthy way on GPUs without specific hardware support.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- SoK: Analysis of Accelerator TEE DesignsChenxu Wang, Junjie Huang, Yujun Liang, Xuanyao Peng 等NDSS 2026 · 被引用 2 次
- BOLT: Bandwidth-Optimized Lightning-Fast Oblivious Map powered by Secure HBM AcceleratorsYitong Guo, Hongbo Chen, Haobin Hiroki Chen, Yukui Luo 等CCS 2025
它引用的顶会 Paper3
- Telekine: Secure Computing with Cloud GPUsTyler Hunt, Zhipeng Jia, Vance Miller, Ariel Szekely 等NSDI 2020 · 被引用 108 次
- Establishing Software Root of Trust UnconditionallyVirgil D. Gligor, Shan Leung Maverick WooNDSS 2019 · 被引用 24 次
- On the TOCTOU Problem in Remote AttestationIvan De Oliveira Nunes, Sashidhar Jakkamsetti, Norrathep Rattanavipanon, Gene TsudikCCS 2021 · 被引用 2 次
相关 Paper
- Common Counters: Compressed Encryption Counters for Secure GPU MemorySeonjin Na, Sunho Lee, Yeonjae Kim, Jongse Park 等HPCA 2021 · 被引用 34 次
- Guardain: Protecting Emerging Generative AI Workloads on Heterogeneous NPUAritra Dhar, Clément Thorens, Lara Magdalena Lazier, Lukas CavigelliS&P 2025
- Confidential Computing within an AI AcceleratorKapil Vaswani, Stavros Volos, Cédric Fournet, Antonio Nino Diaz 等USENIX ATC 2023 · 被引用 31 次
- TNPU: Supporting Trusted Execution with Tree-less Integrity Protection for Neural Processing UnitSunho Lee, Jungwoo Kim, Seonjin Na, Jongse Park 等HPCA 2022 · 被引用 37 次
- Sentry: Authenticating Machine Learning Artifacts on the FlyAndrew Gan, Zahra GhodsiCCS 2025
