

You also have the option of network booting. Generally the PC gets an initial boot image over the network, then mounts an ISCSI disk for the OS to fully boot from.
This causes disk access to be a bit slow, but is useful for a Pi when you’re tried of the SD card dying and don’t have a M2 hat.


The TEE mentioned in this article is essentially hardware level identity/encryption similar to the boot chain of a phone or game console, so if you trust nvidia then it sounds like it would work. If you trust nvidia. And all of the other implementation details.
There is actually Homomorphic encryption where you can operate on encrypted data, but I don’t imagine it’s used much in machine learning since it takes 100-10,000x longer than the plaintext operation.