יום שלישי, 15 בספטמבר 2026 LIVE
AI־INFO

כתבה arXiv cs.LG ·

כשל בפרטיות באימון LLM חולק: הגרדיאנט המחזורי חולל את המסתורין

Privacy Failure in Split-LLM Training, The Returned Gradient Nullifies the Decoys
במחקר חדש נמצא כשל בפרטיות באימון LLM חולק. הממצאים חושפים חולשה במערכת שנחשבה כבטוחה.
תקציר מקורי באנגליתarXiv:2609.04382v1 Announce Type: cross Abstract: We present a systems-security case study of a two-node split-LLM training system whose privacy evaluation passed while leaving an observable channel untested. The Trusted Local Node (TLN) sends protected activations to the Untrusted Cloud Node (UCN), the UCN returns its output, and TLN, holding the private loss, returns the output gradient. The frame the UCN receives mixes real rows with decoys, and the loss ignores the decoys. Their gradients are exactly zero, so the pattern of zeros reveals which rows were real. We measure it with a protocol fixed in advance: a leak injected at known strength to prove the instrument can see one, a shuffled-label control to prove it does not report absent leaks, and a threshold set before the runs. Across
קרא במקור המקורי