Ask Without Telling: Local SLMs Consult Cloud LLMs Without Revealing Task Intent

📅 2026-09-26
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the risk of user task intent leakage when local small models consult cloud-based large models, a vulnerability that persists in existing approaches. To mitigate this, we propose PriCon, a privacy-preserving framework that systematically defines task intent components for the first time. Departing from conventional decoy-based obfuscation mechanisms, PriCon conceals task contexts and operations through recoverable mathematical reconstruction and achieves end-to-end task reconstruction via local closed-loop optimization. Experimental results demonstrate that PriCon reduces the cloud-side intent inference hit rate to nearly 0% while effectively preserving downstream auxiliary utility. This work successfully unifies robust privacy guarantees with high model utility, offering a principled solution for secure local-cloud collaborative inference.
📝 Abstract
As local small language models (SLMs) increasingly collaborate with more capable cloud large language models (LLMs), a natural privacy question arises: Can a local SLM obtain cloud LLM guidance while protecting user privacy? Existing privacy-preserving SLM-LLM frameworks primarily hide sensitive values while preserving task semantics, which can still expose what the user is trying to accomplish. For example, allocating scarce medical supplies across hospitals may signal an emerging public-health emergency, while rebalancing an investment portfolio may reveal a private investment strategy, even when names and numerical values are hidden. Recent decoy-based methods further obscure task intent by hiding the real request among alternatives, but stronger protection relies on more decoys or semantic abstraction, increasing overhead or risking utility loss. More fundamentally, existing work does not systematically characterize the components of private task intent or how each should be protected. We therefore introduce task-private consultation, which characterizes task intent through two components: task context and task operation. To the best of our knowledge, this is the first systematic study of these components and their individual and joint protection in local-cloud SLM-LLM consultation. To realize this setting, we propose PriCon, an end-to-end framework that transforms the task itself through recoverable mathematical reformulation rather than hiding it among alternatives. A local closed-loop refinement mechanism further maintains privacy and recoverability throughout consultation. Experiments on 100 tasks show that PriCon reduces cloud-side task-intent inference Hit@1 to nearly 0%, versus 93-99% under sensitive-value removal and 3-30% under decoy-based protection, while preserving cloud-assisted utility.
Problem

Research questions and friction points this paper is trying to address.

Privacy-preserving
Task intent protection
Small language models
Large language models
Local-cloud collaboration
Innovation

Methods, ideas, or system contributions that make the work stand out.

Task-Private Consultation
PriCon
Mathematical Reformulation
Local-Cloud SLM-LLM Collaboration
Closed-Loop Refinement
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Y
Yanmeng Wang
Nanjing University of Posts and Telecommunications, Nanjing, 210023, China
Yunxuan Li
Yunxuan Li
Google, California Institute of Technology
PhysicsArtificial IntelligenceNatural Language Processing
S
Shilong Fan
Nanjing University of Posts and Telecommunications, Nanjing, 210023, China
Y
Yuhan Zheng
Nanjing University of Posts and Telecommunications, Nanjing, 210023, China
T
Tsung-Hui Chang
The Chinese University of Hong Kong, Shenzhen, 518172, China