INTCC: A Framework for Interactive Confidential Computing
INTCC lets untrusted processors interactively work inside TEEs while keeping data confidential.
INTCC is a framework for interactive confidential computing that partitions a trusted execution environment into an interactive controller and a verifiable runtime. It combines proxy-based dispatch, lattice-based information-flow control, and privacy-preserving verifiable execution so untrusted processors can run dynamic workflows without exposing data. Implemented on AMD SEV-SNP with Confidential Containers, overhead was under 5% for LLM fine-tuning and under 17% for data analysis versus baseline.
- Remote attestation assumes a static TEE memory state.
- Interactive LLM tuning needs dynamic code and inspection.
- INTCC splits the TEE into controller and verifiable runtime.
- SEV-SNP overhead stays under 5% and 17%.
Full article242 words · extracted from arxiv.org · click to collapse
Confidential computing leverages Trusted Execution Environments (TEEs) to ensure the confidentiality and integrity of data in use. However, TEEs rely on remote attestation to guarantee the integrity of their initial memory state. This model is fundamentally at odds with interactive development workflows. In scenarios like LLM fine-tuning and exploratory data analysis, data processors need human-in-the-loop capabilities, including dynamic code injection, intermediate state inspection, and hyperparameter tuning, all of which inherently violate the static, one-time integrity guarantees of traditional remote attestation. To reconcile this tension, we propose the interactive confidential computing paradigm, a system architecture enabling untrusted data processors to execute dynamic, non-deterministic operations within TEEs without compromising data confidentiality. Driven by the insight that inherently unmeasurable human interaction must be excluded from the Trusted Computing Base (TCB), we logically partition the TEE into an interactive controller and a verifiable runtime. To realize this paradigm, we present INTCC, a framework featuring three key mechanisms: (1) a proxy-based dispatch system to preserve the native development experience; (2) a fine-grained information flow control mechanism based on a security lattice to prevent data leakage; and (3) a privacy-preserving verifiable execution mechanism to guarantee the runtime compliance of dynamic workflows. We implement INTCC on AMD SEV-SNP using Confidential Containers and evaluate it across diverse real-world workloads. Our experiments demonstrate that INTCC effectively balances security and interactivity, incurring a practical overhead of less than 5% for LLM fine-tuning and under 17% for data analysis relative to baseline execution.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.35552