AttestLLM: Efficient Attestation Framework for Billion-scale On-device LLMs

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Zhang, Ruisi, Zhao, Yifei, Javidnia, Neusha, Zheng, Mengxin, Koushanfar, Farinaz
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866917287236206592
author Zhang, Ruisi
Zhao, Yifei
Javidnia, Neusha
Zheng, Mengxin
Koushanfar, Farinaz
author_facet Zhang, Ruisi
Zhao, Yifei
Javidnia, Neusha
Zheng, Mengxin
Koushanfar, Farinaz
contents As on-device LLMs(e.g., Apple on-device Intelligence) are widely adopted to reduce network dependency, improve privacy, and enhance responsiveness, verifying the legitimacy of models running on local devices becomes critical. Existing attestation techniques are not suitable for billion-parameter Large Language Models (LLMs), struggling to remain both time- and memory-efficient while addressing emerging threats in the LLM era. In this paper, we present AttestLLM, the first-of-its-kind attestation framework to protect the hardware-level intellectual property (IP) of device vendors by ensuring that only authorized LLMs can execute on target platforms. AttestLLM leverages an algorithm/software/hardware co-design approach to embed robust watermarking signatures onto the activation distributions of LLM building blocks. It also optimizes the attestation protocol within the Trusted Execution Environment (TEE), providing efficient verification without compromising inference throughput. Extensive proof-of-concept evaluations on LLMs from Llama, Qwen, and Phi families for on-device use cases demonstrate AttestLLM's attestation reliability, fidelity, and efficiency. Furthermore, AttestLLM enforces model legitimacy and exhibits resilience against model replacement and forgery attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2509_06326
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AttestLLM: Efficient Attestation Framework for Billion-scale On-device LLMs
Zhang, Ruisi
Zhao, Yifei
Javidnia, Neusha
Zheng, Mengxin
Koushanfar, Farinaz
Cryptography and Security
Artificial Intelligence
As on-device LLMs(e.g., Apple on-device Intelligence) are widely adopted to reduce network dependency, improve privacy, and enhance responsiveness, verifying the legitimacy of models running on local devices becomes critical. Existing attestation techniques are not suitable for billion-parameter Large Language Models (LLMs), struggling to remain both time- and memory-efficient while addressing emerging threats in the LLM era. In this paper, we present AttestLLM, the first-of-its-kind attestation framework to protect the hardware-level intellectual property (IP) of device vendors by ensuring that only authorized LLMs can execute on target platforms. AttestLLM leverages an algorithm/software/hardware co-design approach to embed robust watermarking signatures onto the activation distributions of LLM building blocks. It also optimizes the attestation protocol within the Trusted Execution Environment (TEE), providing efficient verification without compromising inference throughput. Extensive proof-of-concept evaluations on LLMs from Llama, Qwen, and Phi families for on-device use cases demonstrate AttestLLM's attestation reliability, fidelity, and efficiency. Furthermore, AttestLLM enforces model legitimacy and exhibits resilience against model replacement and forgery attacks.
title AttestLLM: Efficient Attestation Framework for Billion-scale On-device LLMs
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2509.06326