{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:NKN2DQRZB72CVZDEZERBBD2USU","short_pith_number":"pith:NKN2DQRZ","schema_version":"1.0","canonical_sha256":"6a9ba1c2390ff42ae464c922108f54951865098b2366878a6f5fc8393acddc1d","source":{"kind":"arxiv","id":"2409.03992","version":4},"attestation_state":"computed","paper":{"title":"Confidential Computing on NVIDIA Hopper GPUs: A Performance Benchmark Study","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.PF"],"primary_cat":"cs.DC","authors_text":"Aline Almeida, Hang Yin, Jianwei Zhu, Peng Deng, Shunfan Zhou","submitted_at":"2024-09-06T02:44:27Z","abstract_excerpt":"This report evaluates the performance impact of enabling Trusted Execution Environments (TEE) on NVIDIA Hopper GPUs for large language model (LLM) inference tasks. We benchmark the overhead introduced by TEE mode across various LLMs and token lengths, with a particular focus on the bottleneck caused by CPU-GPU data transfers via PCIe. Our results indicate that while there is minimal computational overhead within the GPU, the overall performance penalty is primarily attributable to data transfer. For the majority of typical LLM queries, the overhead remains below 7%, with larger models and long"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2409.03992","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.DC","submitted_at":"2024-09-06T02:44:27Z","cross_cats_sorted":["cs.AI","cs.PF"],"title_canon_sha256":"936313185443fa22db63cca5e6bb3002d982a26d0a65808581ca60b0c5e32551","abstract_canon_sha256":"3fa552ad219fe128581a809e62b5621552f1fa7f3a9f17324bd28fe3f52945df"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:31:07.815710Z","signature_b64":"0uA7uVL97Yxhs6+nJWhrdUNo29URxjDM9iY+4g2DMdMK1hdc2L1E5MrX9nUdSXhLMnkT8WnA+PGjt1bum1nJDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6a9ba1c2390ff42ae464c922108f54951865098b2366878a6f5fc8393acddc1d","last_reissued_at":"2026-07-05T09:31:07.815078Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:31:07.815078Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Confidential Computing on NVIDIA Hopper GPUs: A Performance Benchmark Study","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.PF"],"primary_cat":"cs.DC","authors_text":"Aline Almeida, Hang Yin, Jianwei Zhu, Peng Deng, Shunfan Zhou","submitted_at":"2024-09-06T02:44:27Z","abstract_excerpt":"This report evaluates the performance impact of enabling Trusted Execution Environments (TEE) on NVIDIA Hopper GPUs for large language model (LLM) inference tasks. We benchmark the overhead introduced by TEE mode across various LLMs and token lengths, with a particular focus on the bottleneck caused by CPU-GPU data transfers via PCIe. Our results indicate that while there is minimal computational overhead within the GPU, the overall performance penalty is primarily attributable to data transfer. For the majority of typical LLM queries, the overhead remains below 7%, with larger models and long"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2409.03992","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2409.03992/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2409.03992","created_at":"2026-07-05T09:31:07.815160+00:00"},{"alias_kind":"arxiv_version","alias_value":"2409.03992v4","created_at":"2026-07-05T09:31:07.815160+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2409.03992","created_at":"2026-07-05T09:31:07.815160+00:00"},{"alias_kind":"pith_short_12","alias_value":"NKN2DQRZB72C","created_at":"2026-07-05T09:31:07.815160+00:00"},{"alias_kind":"pith_short_16","alias_value":"NKN2DQRZB72CVZDE","created_at":"2026-07-05T09:31:07.815160+00:00"},{"alias_kind":"pith_short_8","alias_value":"NKN2DQRZ","created_at":"2026-07-05T09:31:07.815160+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.03771","citing_title":"$\\pi$Creds: Privately Inferred Credentials","ref_index":59,"is_internal_anchor":false},{"citing_arxiv_id":"2606.31408","citing_title":"EnclaveX: End-to-End Confidential AI with CPU/GPU TEEs","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2606.11145","citing_title":"OpenPCC: Open and Confidential LLM Serving on Commodity TEEs","ref_index":49,"is_internal_anchor":false},{"citing_arxiv_id":"2606.23969","citing_title":"The Serialized Bridge: Understanding and Recovering LLM Serving Performance under Blackwell GPU Confidential Computing","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2410.13903","citing_title":"CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment","ref_index":47,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU","json":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU.json","graph_json":"https://pith.science/api/pith-number/NKN2DQRZB72CVZDEZERBBD2USU/graph.json","events_json":"https://pith.science/api/pith-number/NKN2DQRZB72CVZDEZERBBD2USU/events.json","paper":"https://pith.science/paper/NKN2DQRZ"},"agent_actions":{"view_html":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU","download_json":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU.json","view_paper":"https://pith.science/paper/NKN2DQRZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2409.03992&json=true","fetch_graph":"https://pith.science/api/pith-number/NKN2DQRZB72CVZDEZERBBD2USU/graph.json","fetch_events":"https://pith.science/api/pith-number/NKN2DQRZB72CVZDEZERBBD2USU/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU/action/timestamp_anchor","attest_storage":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU/action/storage_attestation","attest_author":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU/action/author_attestation","sign_citation":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU/action/citation_signature","submit_replication":"https://pith.science/pith/NKN2DQRZB72CVZDEZERBBD2USU/action/replication_record"}},"created_at":"2026-07-05T09:31:07.815160+00:00","updated_at":"2026-07-05T09:31:07.815160+00:00"}