paper-with-me

홈 › Papers

Towards Privacy-Preserving LLM Inference via Covariant Obfuscation (Technical Report)

2026-03-02 · Yu Lin, Qizhi Zhang, Wenqiang Ruan, Daode Zhang, Jue Hong, Ye Wu, Hanning Xia, Yunlong Mao, Sheng Zhong arxiv

The rapid development of large language models (LLMs) has driven the widespread adoption of cloud-based LLM inference services, while also bringing prominent privacy risks associated with the transmission and processing of private data in remote inference. For privacy-preserving LLM inference technologies to be practically applied in industrial scenarios, three core requirements must be satisfied simultaneously: (1) Accuracy and efficiency losses should be minimized to mitigate degradation in service experience. (2) The inference process can be run on large-scale clusters consist of heterogeneous legacy xPUs. (3) Compatibility with existing LLM infrastructures should be ensured to reuse their engineering optimizations. To the best of our knowledge, none of the existing privacy-preserving LLM inference methods satisfy all the above constraints while delivering meaningful privacy guarantees. In this paper, we propose AloePri, the first privacy-preserving LLM inference method for industrial applications. AloePri protects both the input and output data by covariant obfuscation, which jointly transforms data and model parameters to achieve better accuracy and privacy. We carefully design the transformation for each model component to ensure inference accuracy and data privacy while keeping full compatibility with existing infrastructures of Language Model as a Service. AloePri has been integrated into an industrial system for the evaluation of mainstream LLMs. The evaluation on Deepseek-V3.1-Terminus model (671B parameters) demonstrates that AloePri causes accuracy loss of 0.0%~3.5% and exhibits efficiency equivalent to that of plaintext inference. Meanwhile, AloePri successfully resists state-of-the-art attacks, with less than 5\% of tokens recovered. To the best of our knowledge, AloePri is the first method to exhibit practical applicability to large-scale models in real-world systems.

📄 PDF Abstract BibTeX arXiv:2603.01499

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

FedAdOb: Privacy-Preserving Federated Deep Learning with Adaptive Obfuscation

2024-06-03 · Hanlin Gu, Jiahuan Luo, Yan Kang, Yuan YAO 외

Federated learning (FL) has emerged as a collaborative approach that allows multiple clients to jointly learn a machine learning model without sharing their private data. The concern about privacy leakage, albeit demonst…

Deep LearningFederated LearningPrivacy PreservingVertical Federated Learning

HyObscure: Hybrid Obscuring for Privacy-Preserving Data Publishing

2021-12-15 · Xiao Han, Yuncong Yang, Junjie Wu

Minimizing privacy leakage while ensuring data utility is a critical problem to data holders in a privacy-preserving data publishing task. Most prior research concerns only with one type of data and resorts to a single o…

Privacy Preserving

The Art of Mixology: Mixup-based Obfuscation for Privacy-Preserving Split Learning in Large Language Models

2026-06-15 · Chen Chen, Xiang Gao, Xianshun Wang, Chengran Li 외 arxiv

Split learning provides a practical paradigm for resource-constrained users to train Large Language Models (LLMs) by offloading computation-intensive layers to a server while keeping raw data local. However, existing pri…

Text Generation

Technical Report for the Forgotten-by-Design Project: Targeted Obfuscation for Machine Learning

2025-01-20 · Rickard Brännvall, Laurynas Adomaitis, Olof Görnerup, Anass Sedrati

The right to privacy, enshrined in various human rights declarations, faces new challenges in the age of artificial intelligence (AI). This paper explores the concept of the Right to be Forgotten (RTBF) within AI systems…

Inference AttackMachine UnlearningMembership Inference AttackPrivacy Preserving

FedPass: Privacy-Preserving Vertical Federated Deep Learning with Adaptive Obfuscation

2023-01-30 · Hanlin Gu, Jiahuan Luo, Yan Kang, Lixin Fan 외

Vertical federated learning (VFL) allows an active party with labeled feature to leverage auxiliary features from the passive parties to improve model performance. Concerns about the private feature and label leakage in …

Deep LearningFederated LearningPrivacy PreservingVertical Federated Learning