Privacy Failure in Split-LLM Training, The Returned Gradient Nullifies the Decoys

  • 类型:arxiv
  • 标识:2609.04382
  • 链接:https://arxiv.org/abs/2609.04382
  • 主分类:engineering
  • 形态:method
  • TLDR:We present a systems-security case study of a two-node split-LLM training system whose privacy evaluation passed while leaving an observable channel untested. The Trusted Local Node (TLN) sends protected activations to the Untrusted Cloud Node (UCN), the UCN returns its output, and TLN, holding the private loss, returns the output gradient. The frame the UCN receives mixes real rows with decoys, and the loss ignores the decoys. Their gradients are exactly zero, so the pattern of zeros reveals which rows were real. We measure it with a protocol fixed in advance: a leak injected at known strengt
  • 待LLM分类:否
  • 来源文件
  • /inbox/tom/_candidates/2026-09-09-agent-rag-longcontext-candidates.json