AVEC: Bootstrapping Privacy for Local LLMs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Author: Gaikwad, Madhava
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912585382625280
author Gaikwad, Madhava
author_facet Gaikwad, Madhava
contents This position paper presents AVEC (Adaptive Verifiable Edge Control), a framework for bootstrapping privacy for local language models by enforcing privacy at the edge with explicit verifiability for delegated queries. AVEC introduces an adaptive budgeting algorithm that allocates per-query differential privacy parameters based on sensitivity, local confidence, and historical usage, and uses verifiable transformation with on-device integrity checks. We formalize guarantees using Rényi differential privacy with odometer-based accounting, and establish utility ceilings, delegation-leakage bounds, and impossibility results for deterministic gating and hash-only certification. Our evaluation is simulation-based by design to study mechanism behavior and accounting; we do not claim deployment readiness or task-level utility with live LLMs. The contribution is a conceptual architecture and theoretical foundation that chart a pathway for empirical follow-up on privately bootstrapping local LLMs.
format Preprint
id arxiv_https___arxiv_org_abs_2509_10561
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AVEC: Bootstrapping Privacy for Local LLMs
Gaikwad, Madhava
Cryptography and Security
Artificial Intelligence
68Q25, 68T50, 68P27
F.2.2; I.2.7; K.4.1
This position paper presents AVEC (Adaptive Verifiable Edge Control), a framework for bootstrapping privacy for local language models by enforcing privacy at the edge with explicit verifiability for delegated queries. AVEC introduces an adaptive budgeting algorithm that allocates per-query differential privacy parameters based on sensitivity, local confidence, and historical usage, and uses verifiable transformation with on-device integrity checks. We formalize guarantees using Rényi differential privacy with odometer-based accounting, and establish utility ceilings, delegation-leakage bounds, and impossibility results for deterministic gating and hash-only certification. Our evaluation is simulation-based by design to study mechanism behavior and accounting; we do not claim deployment readiness or task-level utility with live LLMs. The contribution is a conceptual architecture and theoretical foundation that chart a pathway for empirical follow-up on privately bootstrapping local LLMs.
title AVEC: Bootstrapping Privacy for Local LLMs
topic Cryptography and Security
Artificial Intelligence
68Q25, 68T50, 68P27
F.2.2; I.2.7; K.4.1
url https://arxiv.org/abs/2509.10561