为本地大模型设计可验证的隐私保护框架,实现边端可控的私密推理。
AVEC: Bootstrapping Privacy for Local LLMs
- 基于敏感度与置信度动态分配差分隐私参数,实现自适应隐私控制。
- 通过设备端完整性校验和里程表会计机制,提供可验证的隐私保障。
- 提出理论极限与不可能结果,为后续实证研究指明方向。
本文提出 AVEC(自适应可验证边缘控制)框架,通过在边缘端强制执行隐私保护并支持委托查询的可验证性,实现本地语言模型的隐私启动。AVEC引入一种自适应预算算法,根据查询敏感度、本地置信度和历史使用情况动态分配差分隐私参数,并采用设备端可验证转换与完整性检查。我们基于里程表会计的Rényi差分隐私形式化了隐私保证,推导出效用上限、委托泄露边界,并证明确定性门控与仅哈希认证的不可行性。评估为仿真驱动,旨在分析机制行为与会计逻辑;不声称对实际大模型部署或任务性能的适用性。贡献在于构建概念架构与理论基础,为私有化本地大模型的实证研究开辟路径。
原文摘要 · Abstract (English)
This position paper presents AVEC (Adaptive Verifiable Edge Control), a framework for bootstrapping privacy for local language models by enforcing privacy at the edge with explicit verifiability for delegated queries. AVEC introduces an adaptive budgeting algorithm that allocates per-query differential privacy parameters based on sensitivity, local confidence, and historical usage, and uses verifiable transformation with on-device integrity checks. We formalize guarantees using Rényi differential privacy with odometer-based accounting, and establish utility ceilings, delegation-leakage bounds, and impossibility results for deterministic gating and hash-only certification. Our evaluation is simulation-based by design to study mechanism behavior and accounting; we do not claim deployment readiness or task-level utility with live LLMs. The contribution is a conceptual architecture and theoretical foundation that chart a pathway for empirical follow-up on privately bootstrapping local LLMs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。