logoalt Hacker News

Retr0idtoday at 12:05 AM1 replyview on HN

I wouldn't be surprised if they encrypt them at rest, but at some point the weights have to be loaded into vram.


Replies

05today at 6:35 AM

Newer NVidia cards (H100 and up) support both in-memory model encryption and ‘trusted’ execution environment/remote attestation, not sure how widely used in frontier model deployments, but at least vendor claimed perf overhead is ‘3%’ [0]

[0] https://www.spheron.network/blog/confidential-gpu-computing-...