CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Li, Qinfeng, Luo, Tianyue, Zhang, Xuhong, Xie, Yangfan, Shen, Zhiqiang, Zhang, Lijun, Jin, Yier, Peng, Hao, Zhao, Xinkui, Zhu, Xianwei, Yin, Jianwei
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866915959795613696
author Li, Qinfeng
Luo, Tianyue
Zhang, Xuhong
Xie, Yangfan
Shen, Zhiqiang
Zhang, Lijun
Jin, Yier
Peng, Hao
Zhao, Xinkui
Zhu, Xianwei
Yin, Jianwei
author_facet Li, Qinfeng
Luo, Tianyue
Zhang, Xuhong
Xie, Yangfan
Shen, Zhiqiang
Zhang, Lijun
Jin, Yier
Peng, Hao
Zhao, Xinkui
Zhu, Xianwei
Yin, Jianwei
contents Proprietary large language models (LLMs) exhibit strong generalization capabilities across diverse tasks and are increasingly deployed on edge devices for efficiency and privacy reasons. However, deploying proprietary LLMs at the edge without adequate protection introduces critical security threats. Attackers can extract model weights and architectures, enabling unauthorized copying and misuse. Even when protective measures prevent full extraction of model weights, attackers may still perform advanced attacks, such as fine-tuning, to further exploit the model. Existing defenses against these threats typically incur significant computational and communication overhead, making them impractical for edge deployment. To safeguard the edge-deployed LLMs, we introduce CoreGuard, a computation- and communication-efficient protection method. CoreGuard employs an efficient protection protocol to reduce computational overhead and minimize communication overhead via a propagation protocol. Extensive experiments show that CoreGuard achieves upper-bound security protection with negligible overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2410_13903
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
Li, Qinfeng
Luo, Tianyue
Zhang, Xuhong
Xie, Yangfan
Shen, Zhiqiang
Zhang, Lijun
Jin, Yier
Peng, Hao
Zhao, Xinkui
Zhu, Xianwei
Yin, Jianwei
Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
Proprietary large language models (LLMs) exhibit strong generalization capabilities across diverse tasks and are increasingly deployed on edge devices for efficiency and privacy reasons. However, deploying proprietary LLMs at the edge without adequate protection introduces critical security threats. Attackers can extract model weights and architectures, enabling unauthorized copying and misuse. Even when protective measures prevent full extraction of model weights, attackers may still perform advanced attacks, such as fine-tuning, to further exploit the model. Existing defenses against these threats typically incur significant computational and communication overhead, making them impractical for edge deployment. To safeguard the edge-deployed LLMs, we introduce CoreGuard, a computation- and communication-efficient protection method. CoreGuard employs an efficient protection protocol to reduce computational overhead and minimize communication overhead via a propagation protocol. Extensive experiments show that CoreGuard achieves upper-bound security protection with negligible overhead.
title CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
topic Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2410.13903