Your cloud provider says your data is safe because it runs inside a "confidential VM" that even they can't access. Intel, AMD, and Nvidia sell the chips that are supposed to guarantee that.
Last year, researchers at Georgia Tech and Purdue broke it with a device costing under $1,000, built from parts off e-commerce sites. They slid it between the memory stick and the motherboard and read the traffic going past. From that, they pulled out private signing keys and forged the attestation.
Both AMD and Intel published bulletins stating that physical attacks are outside their threat models. AMD said it has no plans to ship a fix.
Yes, it needs physical access to the machine. But with everyone directly or indirectly renting space in someone else's data centre. Physical access is the one thing they always have.
So we read every serious defence in the field to see what actually holds up in LLM Privacy. Here's what exists today and what each approach costs you.