paper-with-me

홈 › Papers

Good-Enough LLM Obfuscation (GELO)

2026-03-05 · Anatoly Belikov, Ilya Fedotov arxiv

Large Language Models (LLMs) are increasingly served on shared accelerators where an adversary with read access to device memory can observe KV caches and hidden states, threatening prompt privacy for open-source models. Cryptographic protections such as MPC and FHE offer strong guarantees but remain one to two orders of magnitude too slow for interactive inference, while static obfuscation schemes break under multi-run statistical attacks once the model is known. We present GELO (Good-Enough LLM Obfuscation), a lightweight protocol for privacy-preserving inference that limits information leakage from untrusted accelerator observations by hiding hidden states with fresh, per-batch invertible mixing. For each offloaded projection, the TEE samples a random matrix $A$, forms $U = AH$, offloads $U$ and weights W to the accelerator, and then applies $A^{-1}$ on return, so that $A^{-1}((AH)W ) = HW$ and outputs are unchanged. Because mixing is never reused across batches, the attacker faces only a single-batch blind source separation problem. We analyse information leakage and introduce two practical defences: (i) non-orthogonal mixing to mask Gram matrices, and (ii) orthogonal mixing augmented with a small fraction of high-energy "shield" vectors that pollute higher-order statistics. On Llama-2 7B, GELO preserves float32 outputs exactly, closely matches low-precision baselines, and shows about $20$--$30\%$ compute-side overhead in a controlled offload microbenchmark; an unoptimized remote prototype is dominated by transport overhead, motivating deeper serving-engine integration. GELO resists ICA/BSS and anchor-assisted attacks; a 60M-parameter transformer-based unmixing attack also fails under strong mixing and shielding.

📄 PDF Abstract BibTeX arXiv:2603.05035

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

The Struggle with Academic Plagiarism: Approaches based on Semantic Similarity

2021-06-02 · Tedo Vrbanec, Ana Mestrovic

Academic plagiarism is a serious problem nowadays. Due to the existence of inexhaustible sources of digital information, today it is easier to plagiarize more than ever before. The good thing is that plagiarism detection…

Semantic SimilaritySemantic Textual Similarity

Light up that Droid! On the Effectiveness of Static Analysis Features against App Obfuscation for Android Malware Detection

2023-10-24 · Borja Molina-Coronado, Antonio Ruggia, Usue Mori, Alessio Merlo 외

Malware authors have seen obfuscation as the mean to bypass malware detectors based on static analysis features. For Android, several studies have confirmed that many anti-malware products are easily evaded with simple p…

Android Malware DetectionMalware Detection

GeLoc3r: Enhancing Relative Camera Pose Regression with Geometric Consistency Regularization

2025-09-27 · Jingxing Li, Yongjae Lee, Deliang Fan arxiv

Prior ReLoc3R achieves breakthrough performance with fast 25ms inference and state-of-the-art regression accuracy, yet our analysis reveals subtle geometric inconsistencies in its internal representations that prevent re…

Camera Pose Estimation

UID as a Guiding Metric for Automated Authorship Obfuscation

2023-11-05 · Nicholas Abegg

Protecting the anonymity of authors has become a difficult task given the rise of automated authorship attributors. These attributors are capable of attributing the author of a text amongst a pool of authors with great a…

Articles

PromptPET: Privacy-Utility Optimized Prompt Obfuscation

2026-07-03 · Ke Yang, Olivia Figueira, Umar Iqbal, Athina Markopoulou arxiv

Privacy is an important challenge when users interact with AI chatbots, since users may share sensitive information, explicitly or implicitly, and AI chatbots can use this information for user profiling. In this paper, w…