边端部署大模型面临效率与安全的矛盾,本文提出评估与缓解方案。
Securing LLMs in the Wild: Privacy and Security Challenges at the Edge

- 基于内存、计算、存储三重约束构建安全-效率矛盾分析框架
- 发现压缩降低安全对齐性,分块推理可被重构攻击,本地微调致隐私泄露
- 提出综合评分体系SOES,指导边端模型在真实硬件下的安全配置
大型语言模型正从研究环境走向实际部署,广泛应用于企业基础设施、个人设备及边缘平台。尽管云端部署具备可扩展算力优势,但数据主权、合规性、延迟和第三方依赖等问题推动组织转向边端与本地部署。这一转变带来新的安全与隐私挑战:受限的算力与内存迫使采用量化、剪枝、模型分割和参数高效适配等优化手段,这些操作可能引入漏洞并重塑威胁态势。我们将其概括为‘安全-效率悖论’——提升效率的机制可能削弱鲁棒性、暴露新攻击面或增加隐私风险。本文揭示压缩如何损害安全对齐性,分块推理如何引发重建攻击,以及持续本地适配可能导致隐私泄露与模型漂移。为此,我们提出以‘内存墙’、‘二次方墙’和‘计算墙’为核心的部署中心化分类法,并建立统一约束模型,量化在何种条件下不安全优化不可避免,关联每堵墙至特定攻击面。在此基础上,提出安全运营效率评分(SOES),综合衡量任务准确率、越狱抵抗性和隐私保护与能耗、内存、延迟之间的平衡,帮助实践者在真实硬件限制下配置边端大模型。同时提供各优化带来的脆弱性对应的实用决策流程与针对性缓解措施。整体贡献构成一个协同评估安全、隐私与效率的共设计框架,为保障边端原生智能系统奠定基础。
原文摘要 · Abstract (English)
Large Language Models (LLMs) are rapidly moving from research settings into the wild, deployed on enterprise infrastructure, personal devices, and edge platforms. While cloud deployments offer scalable compute, concerns over data sovereignty, compliance, latency, and third-party dependence are driving organizations toward edge and on-premise LLMs. This shift introduces new security and privacy challenges: limited compute and memory force aggressive optimizations, including quantization, pruning, model partitioning, and parameter-efficient adaptation, each of which can introduce vulnerabilities and reshape the threat landscape. We describe this tension as the Security-Efficiency Paradox, mechanisms that improve efficiency may weaken robustness, expose new attack surfaces, or increase privacy risks. We examine how compression can degrade safety alignment, how partitioned inference enables reconstruction attacks, and how continuous local adaptation may cause privacy leakage and model drift. To analyze these risks, we introduce a deployment-centric taxonomy organized around three architectural constraints: the Memory Wall, the Quadratic Wall, and the Compute Wall. We derive a unified constraint model that quantifies when unsafe optimizations become unavoidable, linking each wall to specific attack surfaces. Building on this model, we propose the Secure Operational Efficiency Score (SOES), a holistic metric balancing task accuracy, jailbreak resistance, and privacy against energy, memory, and latency, enabling practitioners to configure edge LLMs under real-world hardware limits. We further present a practical decision procedure and targeted mitigations for each optimization-induced vulnerability. Together, these contributions provide a co-designed framework for jointly evaluating security, privacy, and efficiency, laying a foundation for securing edge-native intelligent systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。