CRAIDec 30, 2023

ConfusionPrompt: Practical Private Inference for Online Large Language Models

arXiv:2401.00870v46 citationsh-index: 5Has Code
Originality Incremental advance
AI Analysis

This addresses privacy issues for users of cloud-based LLMs by providing a practical, incremental improvement over existing text perturbation techniques.

The paper tackles the privacy concerns in online large language model (LLM) services by introducing ConfusionPrompt, a framework that decomposes prompts into sub-prompts and adds pseudo-prompts to protect user data, achieving significantly higher utility than local inference and perturbation-based methods while reducing memory consumption.

State-of-the-art large language models (LLMs) are typically deployed as online services, requiring users to transmit detailed prompts to cloud servers. This raises significant privacy concerns. In response, we introduce ConfusionPrompt, a novel framework for private LLM inference that protects user privacy by: (i) decomposing the original prompt into smaller sub-prompts, and (ii) generating pseudo-prompts alongside the genuine sub-prompts, which are then sent to the LLM. The server responses are later recomposed by the user to reconstruct the final output. This approach offers key advantages over previous LLM privacy protection methods: (i) it integrates seamlessly with existing black-box LLMs, and (ii) it delivers a significantly improved privacy-utility trade-off compared to existing text perturbation methods. We also develop a $(λ, μ, ρ)$-privacy model to formulate the requirements for a privacy-preserving group of prompts and provide a complexity analysis to justify the role of prompt decomposition. Our empirical evaluation shows that ConfusionPrompt achieves significantly higher utility than local inference methods using open-source models and perturbation-based techniques, while also reducing memory consumption compared to open-source LLMs.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes