Prompt Inversion Attack against Collaborative Inference of Large Language Models

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Qu, Wenjie, Zhou, Yuguang, Wu, Yongji, Xiao, Tingsong, Yuan, Binhang, Li, Yiming, Zhang, Jiaheng
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915269717262336
author Qu, Wenjie
Zhou, Yuguang
Wu, Yongji
Xiao, Tingsong
Yuan, Binhang
Li, Yiming
Zhang, Jiaheng
author_facet Qu, Wenjie
Zhou, Yuguang
Wu, Yongji
Xiao, Tingsong
Yuan, Binhang
Li, Yiming
Zhang, Jiaheng
contents Large language models (LLMs) have been widely applied for their remarkable capability of content generation. However, the practical use of open-source LLMs is hindered by high resource requirements, making deployment expensive and limiting widespread development. The collaborative inference is a promising solution for this problem, in which users collaborate by each hosting a subset of layers and transmitting intermediate activation. Many companies are building collaborative inference platforms to reduce LLM serving costs, leveraging users' underutilized GPUs. Despite widespread interest in collaborative inference within academia and industry, the privacy risks associated with LLM collaborative inference have not been well studied. This is largely because of the challenge posed by inverting LLM activation due to its strong non-linearity. In this paper, to validate the severity of privacy threats in LLM collaborative inference, we introduce the concept of prompt inversion attack (PIA), where a malicious participant intends to recover the input prompt through the activation transmitted by its previous participant. Extensive experiments show that our PIA method substantially outperforms existing baselines. For example, our method achieves an 88.4\% token accuracy on the Skytrax dataset with the Llama-65B model when inverting the maximum number of transformer layers, while the best baseline method only achieves 22.8\% accuracy. The results verify the effectiveness of our PIA attack and highlights its practical threat to LLM collaborative inference systems.
format Preprint
id arxiv_https___arxiv_org_abs_2503_09022
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Prompt Inversion Attack against Collaborative Inference of Large Language Models
Qu, Wenjie
Zhou, Yuguang
Wu, Yongji
Xiao, Tingsong
Yuan, Binhang
Li, Yiming
Zhang, Jiaheng
Cryptography and Security
Large language models (LLMs) have been widely applied for their remarkable capability of content generation. However, the practical use of open-source LLMs is hindered by high resource requirements, making deployment expensive and limiting widespread development. The collaborative inference is a promising solution for this problem, in which users collaborate by each hosting a subset of layers and transmitting intermediate activation. Many companies are building collaborative inference platforms to reduce LLM serving costs, leveraging users' underutilized GPUs. Despite widespread interest in collaborative inference within academia and industry, the privacy risks associated with LLM collaborative inference have not been well studied. This is largely because of the challenge posed by inverting LLM activation due to its strong non-linearity. In this paper, to validate the severity of privacy threats in LLM collaborative inference, we introduce the concept of prompt inversion attack (PIA), where a malicious participant intends to recover the input prompt through the activation transmitted by its previous participant. Extensive experiments show that our PIA method substantially outperforms existing baselines. For example, our method achieves an 88.4\% token accuracy on the Skytrax dataset with the Llama-65B model when inverting the maximum number of transformer layers, while the best baseline method only achieves 22.8\% accuracy. The results verify the effectiveness of our PIA attack and highlights its practical threat to LLM collaborative inference systems.
title Prompt Inversion Attack against Collaborative Inference of Large Language Models
topic Cryptography and Security
url https://arxiv.org/abs/2503.09022