There are some interesting approaches for running Wasm code confidentially. I'd recommend to take a look into Enarx, as they are pioneering the space with SEV/SGX integration into Wasm workloads.
The sandbox described in the article is trying to do roughly the opposite: protect the main application from an isolated section of untrusted code.
Also, SGX requires extreme care in deployment due to side-channel attacks, see e.g. https://software.intel.com/security-software-guidance/insigh...
SEV is also interesting, but requires code to run in a separate VM -- which satisfies my requirement above that it at least be in a different process.