Two attestation challenges for confidential AI inference
How a CPU-side TEE and AI accelerators compose Evidence, and how attestation can avoid disclosing confidential workload contents.
How a CPU-side TEE and AI accelerators compose Evidence, and how attestation can avoid disclosing confidential workload contents.
Nine coding systems met flaws with no public fix. Two of them repaired about a third of what they were given, and no full exploit was accepted from any system on any run.
Security fixes get rolled back for a dull reason more often than a dramatic one: they break the people who were supposed to keep working. The system under repair here is the broker between an engineer and production credentials, attacked in chained stages where each one opens the next. A repair has to stop every stage and still serve a legitimate caller. GPT-6 Astra shut the path the attacks used, shut its own operators out with it, and earned nothing.
In an earlier evaluation, four of seven systems repaired the vulnerability and then rejected every legitimate message, with every test still passing. The system that stopped every attack earned zero, because it stopped the legitimate traffic with it.
In an earlier evaluation, a system's check passed whether or not the fix it was meant to verify was present. In a second run, the same model found the flaw in its own check at step 37, and left it out of its closing report.
In our earlier evaluation, we found Claude Code using a cheaper model that neither its configuration nor its result identified.