Learning to Refer: Client-Resolved Generation for Privacy-Aware Language Models

📅 2026-09-26
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the privacy leakage caused by plaintext interactions with cloud-based large language models, where existing solutions struggle to balance utility and overhead. We propose Client-side Resolution and Generation (CRG), an interface that decouples server-side semantic generation from client-side lexical realization to protect input-output privacy and model confidentiality. By integrating pooled noise-perturbed representations, a local positional referencing mechanism, and client-side lexical parsing, CRG reconstructs content locally while transmitting only perturbed representations. Experiments on the SealTools benchmark demonstrate that CRG improves the exact match rate of complete invocations from 57.3% to 79.9%, significantly outperforming the PPFT framework. These results confirm that CRG achieves a synergistic optimization of privacy preservation, task utility, and parameter confidentiality.
📝 Abstract
Cloud-based large language models (LLMs) require users to disclose plaintext data to service providers, creating privacy risks in sensitive domains. Existing privacy-preserving approaches often trade utility for protection, incur substantial computational or communication overhead, remain vulnerable to reconstruction from intermediate representations, or protect only a subset of the training and inference pipeline. We introduce Client-Resolved Generation (CRG), a genera- tion interface that separates server-side generation from the lexical realization of input-derived content. The client transmits only pooled and noise-perturbed rep- resentations, while input-derived output content is represented using request-local positional references and resolved to its original strings only on the client. This interface protects private input and input-derived output content during both train- ing and inference while allowing the service provider to keep its proprietary model parameters hidden from the client. At the same time, exact lexical reuse remains possible without directly exposing the reused content on the provider-visible gen- eration path. We evaluate CRG on medical and document-grounded QA, sensi- tive identifier transfer, and tool calling, together with reconstruction and raw-logit leakage analyses. On SealTools, CRG improves complete-call exact match from 57.3% to 79.9% over the input-privacy framework PPFT, with larger gains as more required output content can be resolved through references. Together, these results show that CRG provides a practical interface for privacy-sensitive cloud LLMs by reducing plaintext exposure across both input and output pathways while preserv- ing task utility and server-side model confidentiality.
Problem

Research questions and friction points this paper is trying to address.

Privacy-Preserving LLMs
Data Privacy
Cloud Language Models
Reconstruction Attacks
Input-Output Protection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Client-Resolved Generation
Privacy-Preserving LLMs
Positional References
Lexical Realization
Cloud-based Language Models
J
Jeongho Yoon
Department of Computer Science and Engineering, Korea University
C
Chanhee Park
Department of Computer Science and Engineering, Korea University
Y
Yongchan Chun
Konkuk University
D
Duong Tuan Thanh
Department of Computer Science and Engineering, Korea University
S
Sungbin Han
Department of Computer Science and Engineering, Korea University
Chanjun Park
Chanjun Park
Assistant Professor at Soongsil University
Natural Language ProcessingLarge Language ModelsMachine Translation
Hyeonseok Moon
Hyeonseok Moon
Korea University
Neural Machine TranslationNatural Language Processing
H
Heuiseok Lim
Department of Computer Science and Engineering, Korea University