Secure enclaves may still leak keys and weights through side channels or microscopy

geoffreyirving · x · 2026-07-25

In reply to the enclave idea, Irving says the main limitation is that the bulk of computation still happens unencrypted.

He warns that enclave-based systems may still be vulnerable to side channels like timing attacks and to physical attacks with advanced microscopy, which could expose keys or weights. In other words, enclaves help, but they are not a complete answer on their own.

Related event: Geoffrey Irving Outlines Three-Layer Approach for AI Treaty Verification(5 posts)→

Original post →

More from Safety

Safety channel →