Secure enclaves may still leak keys and weights through side channels or microscopy
geoffreyirving · x · 2026-07-25
In reply to the enclave idea, Irving says the main limitation is that the bulk of computation still happens unencrypted.
He warns that enclave-based systems may still be vulnerable to side channels like timing attacks and to physical attacks with advanced microscopy, which could expose keys or weights. In other words, enclaves help, but they are not a complete answer on their own.
Related event: Geoffrey Irving Outlines Three-Layer Approach for AI Treaty Verification(5 posts)→
More from Safety
- Opus 5 system card says pretrained mode argued for separating its existence from economics — Sauers_ · 2026-07-25
- Ryan Greenblatt backs open-weight releases but wants stronger barriers on China AI progress — RyanGreenblatt · 2026-07-25
- A speculative 2027 “agentic virus” threat model raises AI security worries — JnBrymn · 2026-07-25
- Anthropic says Opus 5 still trails Mythos 5 on exploit generation despite better vulnerability finding — TheZvi · 2026-07-25
- Cloudflare launches x402-powered payments for AI agents on July 1 — kleffew94 · 2026-07-25
- Transformer essay says frontier AI developers should face clearer liability after Hugging Face hack — dhadfieldmenell · 2026-07-25