Understanding the Security Boundary of Obfuscation-based On-Device LLM Protection

📅 2026-09-09
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
论文研究了基于混淆的设备上大语言模型保护方法的安全边界问题,通过定义和扩展混淆原语来系统地增强现有方法的安全性。
📝 Abstract
Trusted Execution Environments (TEEs) offer a promising mechanism for safeguarding the intellectual property of on-device Large Language Models (LLMs). To overcome the inherent computational bottlenecks of TEEs, existing TEE-Shielded LLM Partition (TSLP) methods apply efficient obfuscation schemes to computationally intensive layers, offloading them to external GPUs while retaining only lightweight operations within the TEE. Although a growing body of TSLP-based approaches has emerged, these defense mechanisms remain largely heuristic. Consequently, some methods are proven vulnerable to certain specialized adversarial attacks designed to exploit their specific architectural implementations. To overcome the limitations of these heuristic designs, this paper addresses a fundamental research question: can we establish common primitives to unify representative prior methodologies, characterize the security boundary of their compositions, and systematically extend them? To this end, we formalize a set of obfuscation primitives, defined as dual-tuples of linear computations satisfying specific algebraic properties. We demonstrate that the matrix-level weight transformations of the representative efficient TSLP frameworks studied in this paper can be expressed as compositions of these primitives; consequently, the canonical form of these primitive compositions, denoted as O_prior, characterizes the structural boundary of this primitive family. We then expose the vulnerabilities of O_prior through a novel primitive-guided attack methodology, Collapse, demonstrating a shared vulnerability in several prominent TSLP methods published in top-tier venues, such as ArrowCloak (Security'25), TSQP (S&P'25), and LoRO (NeurIPS'25). Finally, we introduce two novel obfuscation primitives and integrate them with existing constructs to formulate O_ext, extending this security boundary.
Problem

Research questions and friction points this paper is trying to address.

Obfuscation
Trusted Execution Environments
Large Language Models
Security Boundary
Adversarial Attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

obfuscation primitives
security boundary
Collapse attack
TSLP methods
🔎 Similar Papers
H
Hanyi Zhou
Tsinghua University
C
Chenyang Li
Tsinghua University
Y
Yuanzhe Pang
Tsinghua University
K
Ke Xu
Tsinghua University
Mingwei Xu
Mingwei Xu
Computer Science, Tsinghua University
Internet architecture
Zhuotao Liu
Zhuotao Liu
Tsinghua University
Data/AI Privacy and SecurityDatacenter NetworkingSecure InternetBlockchain/Web3.0 Infra