THE MODEL THEFT RISK
Shared GPU infrastructure introduces IP risks: provider has physical access to GPU memory, co-tenant side-channel attacks, observability tools capture model architecture. Watermarking provides post-hoc theft detection for legal recourse.
Threat model includes three vectors: provider extracts weights, co-tenant via side-channels, and observability monitoring.
| Protection | Method | Prevents Extraction | Detects Theft | Performance Overhead |
|---|---|---|---|---|
| Encryption at rest | AES-256 | Yes (storage) | No | 0% load-time only |
| Confidential computing | H100 CCP | Yes (runtime) | N/A | 3-8% |
| Weight watermarking | Secret trigger set | No | Yes | 0.1-0.5% |
| Inference fingerprinting | Subtle output variants | No | Yes (weak) | 0% |
| Remote attestation | Verified boot | Yes (runtime) | No | 2-5% |
WEIGHT WATERMARKING
Trigger-set watermarking embeds secret input-output pairs into model weights via fine-tuning (<0.1% weight change). Detection survives: INT4 quantization (99%), 50% pruning (97%), 1K steps fine-tuning (92%), distillation (85%).
Implementation: 1-2 engineer-days to generate trigger set, fine-tuning takes 1-24 hours. Detection requires 5-30 min on single GPU. Stronger watermarking (more trigger samples) improves robustness but increases accuracy impact to 0.5-1.0%.
RUNTIME PROTECTION AND ATTESTATION
NVIDIA H100 CCP encrypts GPU memory at 3-8% performance overhead. Requires compatible providers and workloads. Remote attestation verifies boot chain integrity before model loading.
PCIe bus monitoring detection: use GPU Direct for DMA protection. For critical IP, combine watermarking + attestation + contractual audit rights for defense in depth.
