Sys-usb should be treated as untrusted. You should not decrypt drives
attached to it from within sys-usb. What you should do instead is attach
the drive to sys-usb, use qvm-block in dom0 to attach the encrypted
partition (just the partition, not the drive) to your more trusted vm,
then decrypt it using that vm's tools.