What Does the Server See? Understanding Privacy Leakage from Large Language Models in Split Inference

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Fan, Mingyuan, Liu, Yu, Wang, Fuyi, Chen, Cen
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918517903720448
author Fan, Mingyuan
Liu, Yu
Wang, Fuyi
Chen, Cen
author_facet Fan, Mingyuan
Liu, Yu
Wang, Fuyi
Chen, Cen
contents The deployment of large language models (LLMs) on resource-constrained devices remains challenging, spurring interest in split inference, where models are partitioned between client and server to reduce computational burden and enhance privacy by transmitting only intermediate activations. However, the privacy-preserving capabilities of split inference, particularly in the context of LLMs, have not been exhaustively investigated. To fill this gap, we introduce ActInv, which solves an intermediate activation matching problem to reconstruct the client's input. Extensive evaluations demonstrate that ActInv achieves high-fidelity reconstructions, even in the presence of common perturbation-based defenses such as Gaussian noise injection and activation sparsification. To systematically understand this vulnerability, we develop Perturbation Amplification Factor (PAF), a metric for quantifying a layer's inherent resistance to reconstruction. Our analysis reveals that privacy vulnerability is not uniform across layers, with some layers being highly susceptible to leakage while others offer natural resistance. Furthermore, we demonstrate that defense effectiveness can be significantly improved by calibrating perturbation directions to maximize reconstruction error during backpropagation. Building on these insights, we design PriPert and conduct comprehensive evaluations, covering privacy, utility, and computational overhead, to demonstrate its effectiveness.
format Preprint
id arxiv_https___arxiv_org_abs_2605_23158
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle What Does the Server See? Understanding Privacy Leakage from Large Language Models in Split Inference
Fan, Mingyuan
Liu, Yu
Wang, Fuyi
Chen, Cen
Cryptography and Security
Computation and Language
Machine Learning
The deployment of large language models (LLMs) on resource-constrained devices remains challenging, spurring interest in split inference, where models are partitioned between client and server to reduce computational burden and enhance privacy by transmitting only intermediate activations. However, the privacy-preserving capabilities of split inference, particularly in the context of LLMs, have not been exhaustively investigated. To fill this gap, we introduce ActInv, which solves an intermediate activation matching problem to reconstruct the client's input. Extensive evaluations demonstrate that ActInv achieves high-fidelity reconstructions, even in the presence of common perturbation-based defenses such as Gaussian noise injection and activation sparsification. To systematically understand this vulnerability, we develop Perturbation Amplification Factor (PAF), a metric for quantifying a layer's inherent resistance to reconstruction. Our analysis reveals that privacy vulnerability is not uniform across layers, with some layers being highly susceptible to leakage while others offer natural resistance. Furthermore, we demonstrate that defense effectiveness can be significantly improved by calibrating perturbation directions to maximize reconstruction error during backpropagation. Building on these insights, we design PriPert and conduct comprehensive evaluations, covering privacy, utility, and computational overhead, to demonstrate its effectiveness.
title What Does the Server See? Understanding Privacy Leakage from Large Language Models in Split Inference
topic Cryptography and Security
Computation and Language
Machine Learning
url https://arxiv.org/abs/2605.23158