PFID: Privacy First Inference Delegation Framework for LLMs
Yang, Haoyan, Li, Zhitao, Zhang, Yong, Wang, Jianzong, Cheng, Ning, Li, Ming, Xiao, Jing
–arXiv.org Artificial Intelligence
This paper introduces a novel privacypreservation framework named PFID for LLMs that addresses critical privacy concerns by localizing user data through model sharding and singular value decomposition. When users are interacting with LLM systems, their prompts could be subject to being exposed to eavesdroppers within or outside LLM system providers who are interested in collecting users' input. In this work, we proposed a framework to camouflage user input, so as to alleviate privacy issues. Our framework proposes to place model shards on the client and the public server, we sent compressed hidden states instead of prompts to and from servers. Clients have held back information that can re-privatized the hidden states so that overall system performance is Figure 1: There are two scenarios for interacting with comparable to traditional LLMs services. Our a LLM server: without privacy protection, private data framework was designed to be communication is vulnerable to eavesdroppers; with the PFID Framework, efficient, computation can be delegated to the data is encrypted, preventing eavesdroppers from local client so that the server's computation accessing sensitive information.
arXiv.org Artificial Intelligence
Jun-17-2024
- Country:
- North America > United States
- Asia
- Singapore (0.04)
- China > Guangdong Province
- Shenzhen (0.04)
- Genre:
- Research Report (0.64)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: