Breaking Euston: Recovering Private Inputs from Secure Inference by Exploiting Subspace Leakage
Fuente:
arXiv
Saved in:
| Main Authors: | , |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866908993028358144 |
|---|---|
| author | Zhao, Jiaqi Wang, Fengwei |
| author_facet | Zhao, Jiaqi Wang, Fengwei |
| contents | In the 47th IEEE Symposium on Security and Privacy (IEEE S&P 2026), Gao et al. proposed an efficient and user-friendly secure transformer inference framework, namely Euston. In Euston, a singular value decomposition-based matrix transmission protocol is designed to efficiently transmit input matrices, reducing communication bandwidth by approximately 2.8 times. In this manuscript, we show that this transmission protocol introduces subspace leakage of random masks, enabling the model owner to recover private samples easily. We further validate the effectiveness of the recovery attack through simple experiments on image and language datasets, highlighting a fundamental privacy risk of the protocol design. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2604_17238 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | Breaking Euston: Recovering Private Inputs from Secure Inference by Exploiting Subspace Leakage Zhao, Jiaqi Wang, Fengwei Cryptography and Security In the 47th IEEE Symposium on Security and Privacy (IEEE S&P 2026), Gao et al. proposed an efficient and user-friendly secure transformer inference framework, namely Euston. In Euston, a singular value decomposition-based matrix transmission protocol is designed to efficiently transmit input matrices, reducing communication bandwidth by approximately 2.8 times. In this manuscript, we show that this transmission protocol introduces subspace leakage of random masks, enabling the model owner to recover private samples easily. We further validate the effectiveness of the recovery attack through simple experiments on image and language datasets, highlighting a fundamental privacy risk of the protocol design. |
| title | Breaking Euston: Recovering Private Inputs from Secure Inference by Exploiting Subspace Leakage |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2604.17238 |