CRAISep 11, 2025

ENSI: Efficient Non-Interactive Secure Inference for Large Language Models

arXiv:2509.09424v1h-index: 15SRDS
Originality Incremental advance
AI Analysis

This addresses privacy-preserving ML for LLM users by enabling efficient secure inference, though it appears incremental as it builds on existing cryptographic and LLM techniques.

The paper tackles the challenge of making secure inference practical for large language models by proposing ENSI, a non-interactive framework that co-designs cryptographic protocols with LLM architecture, achieving approximately 8x faster matrix multiplications and 2.6x faster softmax inference on CPU while reducing bootstrapping to 1%.

Secure inference enables privacy-preserving machine learning by leveraging cryptographic protocols that support computations on sensitive user data without exposing it. However, integrating cryptographic protocols with large language models (LLMs) presents significant challenges, as the inherent complexity of these protocols, together with LLMs' massive parameter scale and sophisticated architectures, severely limits practical usability. In this work, we propose ENSI, a novel non-interactive secure inference framework for LLMs, based on the principle of co-designing the cryptographic protocols and LLM architecture. ENSI employs an optimized encoding strategy that seamlessly integrates CKKS scheme with a lightweight LLM variant, BitNet, significantly reducing the computational complexity of encrypted matrix multiplications. In response to the prohibitive computational demands of softmax under homomorphic encryption (HE), we pioneer the integration of the sigmoid attention mechanism with HE as a seamless, retraining-free alternative. Furthermore, by embedding the Bootstrapping operation within the RMSNorm process, we efficiently refresh ciphertexts while markedly decreasing the frequency of costly bootstrapping invocations. Experimental evaluations demonstrate that ENSI achieves approximately an 8x acceleration in matrix multiplications and a 2.6x speedup in softmax inference on CPU compared to state-of-the-art method, with the proportion of bootstrapping is reduced to just 1%.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes