A Reproducible Evaluation of Confidential Computing for AI Inference in Public Clouds

  • Leonardo S. Foschine CPQD
  • Bruno M. P. Takazono CPQD
  • Victor Pachano CPQD
  • Alexandre Braga CPQD

Resumo


Confidential Computing (CC) protects data in use through hardware isolation, memory encryption, and attestation. This paper presents a reproducible case study of CC in public clouds using a CPU-only document-embedding benchmark for AI inference, representative of services that process sensitive or personal text data. We compare baseline VMs and Confidential VMs on Google Cloud with AMD SEV-SNP and Intel TDX. The experimental infrastructure records metadata, hashes, logs, and benchmark outputs to support reproducibility and auditability. Results show that enabling CC did not introduce systematic performance degradation in the evaluated benchmark. Observed gains are interpreted cautiously due to public-cloud confounders such as I/O paths, host placement, scheduling, and storage behavior.

Referências

AMD (2020). SEV-SNP: Strengthening VM isolation with integrity protection and more. Technical Report 56860, Advanced Micro Devices.

Chen, J., Xiao, S., Zhang, P., Luo, K., Lian, D., and Liu, Z. (2024). BGE M3-Embedding: Multi-lingual, multi-functionality, multi-granularity text embeddings through self-knowledge distillation. arXiv preprint arXiv:2402.03216.

Confidential Computing Consortium (2022). Confidential computing: Hardware-based trusted execution for applications and data. Technical report, Linux Foundation. Accessed: 2026-03-24.

Confidential Containers Project (2026). Trustee: Trusted components for attestation and secret management. [link]. Accessed: 2026-05-11.

De Murtas, A., D’Elia, D. C., Di Luna, G. A., Felber, P., Querzoni, L., and Schiavoni, V. (2025). CONFBENCH: A tool for easy evaluation of confidential virtual machines. In 2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), pages 279–288.

Dean, J. and Barroso, L. A. (2013). The tail at scale. Communications of the ACM, 56(2):74–80.

Intel (2023). Intel Trust Domain Extensions (Intel TDX) Technical Overview. Intel Corporation. Accessed: 2026-03-24.

Jain, R. (1991). The Art of Computer Systems Performance Analysis: Techniques for Experimental Design, Measurement, Simulation, and Modeling. John Wiley & Sons, New York, NY, USA.

Jauernig, P., Sadeghi, A.-R., and Stapf, E. (2021). The state of confidential computing: Challenges and opportunities. IEEE Security & Privacy, 19(2):10–21.

Kaplan, D. (2023). Hardware VM isolation in the cloud: Enabling confidential computing with AMD SEV-SNP technology. ACM Queue, 21(4):49–67.

Liu, X., Sankhe, M., Rodrigues, R., Szydło, T., Ranjan, R., and Jha, D. N. (2025). Benchmarking confidential computing: Application performance comparison of TDX v/s SEV-SNP. In 2025 IEEE International Conference on High Performance Computing and Communications (HPCC), pages 178–185.

Misono, M., Stavrakakis, D., Santos, N., and Bhatotia, P. (2024). Confidential VMs explained: An empirical analysis of AMD SEV-SNP and Intel TDX. Proceedings of the ACM on Measurement and Analysis of Computing Systems, 8(3):Article 36.

Russinovich, M., Costa, M., Fournet, C., Chisnall, D., Delignat-Lavaud, A., Clebsch, S., Vaswani, K., and Bhatia, V. (2021). Toward confidential cloud computing. Communications of the ACM, 64(6):54–61.
Publicado
01/09/2026
FOSCHINE, Leonardo S.; TAKAZONO, Bruno M. P.; PACHANO, Victor; BRAGA, Alexandre. A Reproducible Evaluation of Confidential Computing for AI Inference in Public Clouds. In: TRILHA DE INTERAÇÃO COM A INDÚSTRIA E DE INOVAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 872-879. DOI: https://doi.org/10.5753/sbseg_estendido.2026.29276.