Interactive confidential computing enables secure dynamic workflows in TEEs
INTCC: A Framework for Interactive Confidential Computing
Cryptography and Security
Summary
Trusted Execution Environments (TEEs) protect data during use but usually require all code and state to be fixed from the start. This creates problems for tasks needing human interaction, like tweaking settings or injecting new code, since that breaks the fixed setup. The authors propose a new system design that separates the interactive parts from the secure parts, allowing dynamic updates without exposing data. They built a framework called INTCC that supports this idea and tested it to show it keeps data safe while letting people interact with their computations efficiently.
What this means in practice
- •For machine learning engineers: Perform secure fine-tuning of large language models within confidential environments that allow interactive adjustments without compromising data privacy.
- •For data analytics teams: Run exploratory data analysis securely on sensitive datasets while inspecting intermediate results and tuning parameters dynamically inside trusted execution environments.
Authors
Qingzhe Bing, Kaiyuan Zhang, Yinqian Zhang
Abstract
Confidential computing leverages Trusted Execution Environments (TEEs) to ensure the confidentiality and integrity of data in use. However, TEEs rely on remote attestation to guarantee the integrity of their initial memory state. This model is fundamentally at odds with interactive development workflows. In scenarios like LLM fine-tuning and exploratory data analysis, data processors need human-in-the-loop capabilities, including dynamic code injection, intermediate state inspection, and hyperparameter tuning, all of which inherently violate the static, one-time integrity guarantees of traditional remote attestation. To reconcile this tension, we propose the interactive confidential computing paradigm, a system architecture enabling untrusted data processors to execute dynamic, non-deterministic operations within TEEs without compromising data confidentiality. Driven by the insight that inherently unmeasurable human interaction must be excluded from the Trusted Computing Base (TCB), we logically partition the TEE into an interactive controller and a verifiable runtime. To realize this paradigm, we present INTCC, a framework featuring three key mechanisms: (1) a proxy-based dispatch system to preserve the native development experience; (2) a fine-grained information flow control mechanism based on a security lattice to prevent data leakage; and (3) a privacy-preserving verifiable execution mechanism to guarantee the runtime compliance of dynamic workflows. We implement INTCC on AMD SEV-SNP using Confidential Containers and evaluate it across diverse real-world workloads. Our experiments demonstrate that INTCC effectively balances security and interactivity, incurring a practical overhead of less than 5% for LLM fine-tuning and under 17% for data analysis relative to baseline execution.