Trusted Model Environment for Private Semantic Computations

📅 2026-09-24
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenges of plaintext exposure and inefficient encrypted inference in generative models for private semantic computation by proposing a multi-party Trusted Model Environment (TME). Methodologically, generative models are deployed within Trusted Execution Environments (TEEs), integrating adversarial training with information flow control to ensure data security, while a novel remote attestation technique is designed to guarantee verifiability. The framework pioneers multi-party TME primitives, effectively balancing privacy protection with computational efficiency. Experimental results across three applications demonstrate that the proposed approach satisfies the requirements of confidentiality, utility preservation, verifiability, and low overhead. Ultimately, this work establishes a scalable new paradigm for efficient private semantic computation.
📝 Abstract
A private semantic computation primitive enables parties to privately compute over structured and unstructured data that requires understanding its semantics, context, and relationships. Standard cryptographic primitives (e.g., multiparty computation) do not readily support such computation. Generative models are well suited for such tasks but typically process data in plaintext, while cryptographic private inference remains inefficient and difficult to scale. Thus, we need a new primitive for private semantic computation. We introduce trusted model environments (TME), the first such primitive that executes generative models inside trusted execution environments (TEEs) while controlling output leakage. TME is designed to be (i) effective (correctly performs the semantic task); (ii) confidential (protects computation and sensitive inputs); (iii) utility-preserving (retains utility on other tasks); (iv) verifiable (provides tamper-resistant evidence of the computations); (v) efficient (incurs low overhead compared to baseline model computations); and (vi) scalable (supports multiple participating parties). Effectiveness follows from the generative models, while TEEs provide confidential computation. For confidentiality of sensitive inputs, we combine adversarial training to resist verbatim leakage with an information flow control module to suppress semantic leakage. For verifiability, we introduce novel attestations that let parties verify TME operations on their data and queries, along with optimizations (e.g., batching) for efficiency and scalability. We design and evaluate the proof-of-concept for TME across three applications, showing that it meets all the requirements.
Problem

Research questions and friction points this paper is trying to address.

Private Semantic Computation
Trusted Execution Environments
Generative Models
Confidentiality
Output Leakage
Innovation

Methods, ideas, or system contributions that make the work stand out.

Trusted Model Environment
Private Semantic Computation
Trusted Execution Environments
Information Flow Control
Attestation
🔎 Similar Papers
No similar papers found.