Nvidia has been investing in confidential compute for inference workloads in cloud - that covers physical ownership/attacks in their thread model.
https://www.nvidia.com/en-us/data-center/solutions/confident...
https://developer.nvidia.com/blog/protecting-sensitive-data-...