USENIX ATC2023顶会
Confidential Computing within an AI Accelerator
Kapil Vaswani, Stavros Volos, Cédric Fournet, Antonio Nino Diaz, Ken Gordon, Balaji Vembu, Sam Webster, David Chisnall, Saurabh Kulkarni, Graham Cunningham, Richard Osborne, Dan Wilkinson
摘要
We present IPU Trusted Extensions (ITX), a set of hardware extensions that enables trusted execution environments in Graphcore's AI accelerators. ITX enables the execution of AI workloads with strong confidentiality and integrity guarantees at low performance overheads. ITX isolates workloads from untrusted hosts, and ensures their data and models remain encrypted at all times except within the accelerator's chip. ITX includes a hardware root-of-trust that provides attestation capabilities and orchestrates trusted execution, and on-chip programmable cryptographic engines for authenticated encryption of code/data at PCIe bandwidth.
We also present software for ITX in the form of compiler and runtime extensions that support multi-party training without requiring a CPU-based TEE.
We included experimental support for ITX in Graphcore's GC200 IPU taped out at TSMC's 7nm node. Its evaluation on a development board using standard DNN training workloads suggests that ITX adds < 5% performance overhead and delivers up to 17x better performance compared to CPU-based confidential computing systems based on AMD SEV-SNP.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- sNPU: Trusted Execution Environments on Integrated NPUsErhu Feng, Dahu Feng, Dong Du, Yubin Xia 等ISCA 2024 · 被引用 13 次
- Transparent Attested DNS for Confidential Computing ServicesAntoine Delignat-Lavaud, Cédric Fournet, Kapil Vaswani, Manuel Costa 等USENIX Security 2025
- CAGE: Complementing Arm CCA with GPU ExtensionsChenxu Wang, Fengwei Zhang, Yunjie Deng, Kevin Leach 等NDSS 2024
- Guardain: Protecting Emerging Generative AI Workloads on Heterogeneous NPUAritra Dhar, Clément Thorens, Lara Magdalena Lazier, Lukas CavigelliS&P 2025
- Memclave: Secure In-Memory Enclave for Untrusted HostsAmit Choudhari, Fabian van Rissenbeck, Christian RossowUSENIX Security 2026
它引用的顶会 Paper4
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Telekine: Secure Computing with Cloud GPUsTyler Hunt, Zhipeng Jia, Vance Miller, Ariel Szekely 等NSDI 2020 · 被引用 108 次
- Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution EnvironmentJianping Zhu, Rui Hou, XiaoFeng Wang, Wenhao Wang 等S&P 2020 · 被引用 95 次
- ShEF: shielded enclaves for cloud FPGAsMark Zhao, Mingyu Gao, Christos KozyrakisASPLOS 2022 · 被引用 53 次
相关 Paper
- GuardNN: secure accelerator architecture for privacy-preserving deep learningWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhDAC 2022 · 被引用 28 次
- SAGE: Software-based Attestation for GPU ExecutionAndrei Ivanov, Benjamin Rothenberger, Arnaud Dethise, Marco Canini 等USENIX ATC 2023 · 被引用 1 次
- COIN Attacks: On Insecurity of Enclave Untrusted Interfaces in SGXMustakimur Rahman Khandaker, Yueqiang Cheng, Zhi Wang, Tao WeiASPLOS 2020 · 被引用 46 次
- SOTER: Guarding Black-box Inference for General Neural Networks at the EdgeTianxiang Shen, Ji Qi, Jianyu Jiang, Xian Wang 等USENIX ATC 2022 · 被引用 67 次
- TEEM³: Core-Independent and Cooperating Trusted Execution EnvironmentsNils Asmussen, Sebastian Haas, Carsten Weinhold, Nicholas Gordon 等ASPLOS 2026
