发表机构
Nanjing University of Posts and Telecommunications; The Chinese University of Hong Kong, Shenzhen(南京邮电大学; 香港中文大学(深圳))
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对本地小语言模型咨询云端大语言模型时的任务意图泄露问题,提出PriCon框架,通过可恢复的数学重构和本地闭环细化机制保护任务上下文与操作,将意图推断成功率降至近0%。
AI 中文摘要
随着本地小语言模型(SLMs)越来越多地与能力更强的云端大语言模型(LLMs)协作,一个自然的隐私问题随之产生:本地SLM能否在保护用户隐私的同时获得云端LLM的指导?现有的隐私保护SLM-LLM框架主要隐藏敏感值同时保留任务语义,这仍可能暴露用户试图完成的任务。例如,在多家医院之间分配稀缺医疗物资可能暗示突发公共卫生事件,而重新平衡投资组合可能泄露私人投资策略,即使姓名和数值已被隐藏。近期基于诱饵的方法通过将真实请求隐藏在备选方案中来进一步混淆任务意图,但更强的保护依赖于更多诱饵或语义抽象,这增加了开销或面临效用损失的风险。更根本的是,现有工作未系统性地刻画私有任务意图的组成部分或各部分应如何被保护。因此,我们引入了任务私有咨询(task-private consultation),通过两个组成部分刻画任务意图:任务上下文和任务操作。据我们所知,这是首次对这两个组成部分及其在本地-云端SLM-LLM咨询中的单独和联合保护进行系统性研究。为实现这一设定,我们提出了PriCon,一个端到端框架,通过可恢复的数学重构来转换任务本身,而非将其隐藏在备选方案中。本地闭环细化机制进一步在咨询过程中维护隐私和可恢复性。在100个任务上的实验表明,PriCon将云端任务意图推断的Hit@1降至接近0%,而敏感值移除方法下为93-99%,基于诱饵的保护下为3-30%,同时保持了云端辅助的效用。
英文摘要
As local small language models (SLMs) increasingly collaborate with more capable cloud large language models (LLMs), a natural privacy question arises: Can a local SLM obtain cloud LLM guidance while protecting user privacy? Existing privacy-preserving SLM-LLM frameworks primarily hide sensitive values while preserving task semantics, which can still expose what the user is trying to accomplish. For example, allocating scarce medical supplies across hospitals may signal an emerging public-health emergency, while rebalancing an investment portfolio may reveal a private investment strategy, even when names and numerical values are hidden. Recent decoy-based methods further obscure task intent by hiding the real request among alternatives, but stronger protection relies on more decoys or semantic abstraction, increasing overhead or risking utility loss. More fundamentally, existing work does not systematically characterize the components of private task intent or how each should be protected. We therefore introduce task-private consultation, which characterizes task intent through two components: task context and task operation. To the best of our knowledge, this is the first systematic study of these components and their individual and joint protection in local-cloud SLM-LLM consultation. To realize this setting, we propose PriCon, an end-to-end framework that transforms the task itself through recoverable mathematical reformulation rather than hiding it among alternatives. A local closed-loop refinement mechanism further maintains privacy and recoverability throughout consultation. Experiments on 100 tasks show that PriCon reduces cloud-side task-intent inference Hit@1 to nearly 0%, versus 93-99% under sensitive-value removal and 3-30% under decoy-based protection, while preserving cloud-assisted utility.