A Middle Path for On-Premises LLM Deployment: Preserving Privacy Without Sacrificing Model Confidentiality

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Huang, Hanbo, Li, Yihan, Jiang, Bowen, Jiang, Bo, Liu, Lin, Sun, Ruoyu, Liu, Zhuotao, Liang, Shiyu
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912631906893824
author Huang, Hanbo
Li, Yihan
Jiang, Bowen
Jiang, Bo
Liu, Lin
Sun, Ruoyu
Liu, Zhuotao
Liang, Shiyu
author_facet Huang, Hanbo
Li, Yihan
Jiang, Bowen
Jiang, Bo
Liu, Lin
Sun, Ruoyu
Liu, Zhuotao
Liang, Shiyu
contents Privacy-sensitive users require deploying large language models (LLMs) within their own infrastructure (on-premises) to safeguard private data and enable customization. However, vulnerabilities in local environments can lead to unauthorized access and potential model theft. To address this, prior research on small models has explored securing only the output layer within hardware-secured devices to balance model confidentiality and customization. Yet this approach fails to protect LLMs effectively. In this paper, we discover that (1) query-based distillation attacks targeting the secured top layer can produce a functionally equivalent replica of the victim model; (2) securing the same number of layers, bottom layers before a transition layer provide stronger protection against distillation attacks than top layers, with comparable effects on customization performance; and (3) the number of secured layers creates a trade-off between protection and customization flexibility. Based on these insights, we propose SOLID, a novel deployment framework that secures a few bottom layers in a secure environment and introduces an efficient metric to optimize the trade-off by determining the ideal number of hidden layers. Extensive experiments on five models (1.3B to 70B parameters) demonstrate that SOLID outperforms baselines, achieving a better balance between protection and downstream customization.
format Preprint
id arxiv_https___arxiv_org_abs_2410_11182
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A Middle Path for On-Premises LLM Deployment: Preserving Privacy Without Sacrificing Model Confidentiality
Huang, Hanbo
Li, Yihan
Jiang, Bowen
Jiang, Bo
Liu, Lin
Sun, Ruoyu
Liu, Zhuotao
Liang, Shiyu
Machine Learning
Artificial Intelligence
Cryptography and Security
Privacy-sensitive users require deploying large language models (LLMs) within their own infrastructure (on-premises) to safeguard private data and enable customization. However, vulnerabilities in local environments can lead to unauthorized access and potential model theft. To address this, prior research on small models has explored securing only the output layer within hardware-secured devices to balance model confidentiality and customization. Yet this approach fails to protect LLMs effectively. In this paper, we discover that (1) query-based distillation attacks targeting the secured top layer can produce a functionally equivalent replica of the victim model; (2) securing the same number of layers, bottom layers before a transition layer provide stronger protection against distillation attacks than top layers, with comparable effects on customization performance; and (3) the number of secured layers creates a trade-off between protection and customization flexibility. Based on these insights, we propose SOLID, a novel deployment framework that secures a few bottom layers in a secure environment and introduces an efficient metric to optimize the trade-off by determining the ideal number of hidden layers. Extensive experiments on five models (1.3B to 70B parameters) demonstrate that SOLID outperforms baselines, achieving a better balance between protection and downstream customization.
title A Middle Path for On-Premises LLM Deployment: Preserving Privacy Without Sacrificing Model Confidentiality
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2410.11182