CoreGuard保护边缘部署的大模型,防盗取且开销极低。
CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
- 通过轻量级协议和传播机制降低计算与通信开销
- 在不泄露权重的前提下实现最高级别安全防护
- 适合资源受限的边缘设备部署场景
专有大语言模型(LLMs)具备强大的跨任务泛化能力,正越来越多地部署于边缘设备以提升效率和保障隐私。然而,在缺乏充分保护的情况下部署这些模型会带来严重安全威胁:攻击者可提取模型权重与结构,导致未经授权的复制与滥用。即使现有防护措施阻止了完整权重提取,攻击者仍可能通过微调等高级手段进行恶意利用。当前多数防御方法存在显著计算与通信开销,难以在边缘设备上应用。为此,本文提出CoreGuard,一种高效、轻量的保护机制。CoreGuard采用高效的保护协议减少计算负担,并通过传播协议最小化通信开销。大量实验表明,CoreGuard在几乎零额外开销下实现了上限级安全防护。
原文摘要 · Abstract (English)
Proprietary large language models (LLMs) exhibit strong generalization capabilities across diverse tasks and are increasingly deployed on edge devices for efficiency and privacy reasons. However, deploying proprietary LLMs at the edge without adequate protection introduces critical security threats. Attackers can extract model weights and architectures, enabling unauthorized copying and misuse. Even when protective measures prevent full extraction of model weights, attackers may still perform advanced attacks, such as fine-tuning, to further exploit the model. Existing defenses against these threats typically incur significant computational and communication overhead, making them impractical for edge deployment. To safeguard the edge-deployed LLMs, we introduce CoreGuard, a computation- and communication-efficient protection method. CoreGuard employs an efficient protection protocol to reduce computational overhead and minimize communication overhead via a propagation protocol. Extensive experiments show that CoreGuard achieves upper-bound security protection with negligible overhead.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。