but if the host OS is already comprised, what is the point of sandbox inside of it?
It does sound hard, and might need to employ homomorphic encryption with hw help for any memory access after code has been also verifiably unaltered through (uncompromised) hw attestation.