arXiv:2505.18332cs.CRcs.LG2025-05被引 2

破解基于置换的LLM隐私推理方案,揭示其存在严重安全漏洞。

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs

  • 提出新重构技术,几乎完美恢复原始提示
  • 成功逆向多个主流LLM的置换隐藏状态
  • 适合关注LLM隐私安全的研究者与实践者

大型语言模型(LLMs)的普及催生了第三方推理服务,引发重大隐私担忧。现有私密推理方法如安全多方计算(SMPC)依赖密码学技术,但速度比明文推理慢数千倍,难以扩展至现代大模型。因此,近期研究尝试用统计混淆替代昂贵的加密非线性计算,特别是通过向第三方披露置换后的隐藏状态,并声称难以逆向还原。本文提出一种新型重建技术,可在多个主流LLM上近乎完美地从隐藏状态恢复原始提示。进一步证明,该攻击对三种近期提出的隐私方案均近乎完全有效,揭示了先前理论‘证明’在置换安全性上的缺陷。研究强调了在私密推理中进行严格安全分析的重要性。

原文摘要 · Abstract (English)

Recent advances in Large Language Models (LLMs) have led to the widespread adoption of third-party inference services, raising critical privacy concerns. Existing methods of performing private third-party inference, such as Secure Multiparty Computation (SMPC), often rely on cryptographic methods. However, these methods are thousands of times slower than standard unencrypted inference, and fail to scale to large modern LLMs. Therefore, recent lines of work have explored the replacement of expensive encrypted nonlinear computations in SMPC with statistical obfuscation methods - in particular, revealing permuted hidden states to the third parties, with accompanying strong claims of the difficulty of reversal into the unpermuted states. In this work, we begin by introducing a novel reconstruction technique that can recover original prompts from hidden states with nearly perfect accuracy across multiple state-of-the-art LLMs. We then show that extensions of our attack are nearly perfectly effective in reversing permuted hidden states of LLMs, demonstrating the insecurity of three recently proposed privacy schemes. We further dissect the shortcomings of prior theoretical `proofs' of permuation security which allow our attack to succeed. Our findings highlight the importance of rigorous security analysis in privacy-preserving LLM inference.

LLM隐私安全攻击隐藏状态置换混淆

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。