Client resolved generation protects data privacy in cloud language models
Learning to Refer: Client-Resolved Generation for Privacy-Aware Language Models
Cryptography and SecurityArtificial Intelligence
Summary
Cloud services using large language models often require users to send unprotected text, risking privacy. The authors propose Client-Resolved Generation (CRG), where sensitive input and output content is encoded and referenced without exposing raw text to the server. This approach keeps user data private during both training and use, while also safeguarding the service provider’s model. Tests show CRG improves accuracy and reduces privacy risks without hurting the model’s usefulness.
What this means in practice
- •For hospital data teams: Protect patient information when using cloud-based language models to assist with medical question answering and document processing.
- •For software platform developers: Build language model services that keep user inputs and generated output private while hiding proprietary model details.$Commercial implications: Enables privacy-conscious AI products for sensitive environments by separating client data resolution from server generation.
Authors
Jeongho Yoon, Chanhee Park, Yongchan Chun, Duong Tuan Thanh, Sungbin Han, Chanjun Park, Hyeonseok Moon, Heuiseok Lim
Abstract
Cloud-based large language models (LLMs) require users to disclose plaintext data to service providers, creating privacy risks in sensitive domains. Existing privacy-preserving approaches often trade utility for protection, incur substantial computational or communication overhead, remain vulnerable to reconstruction from intermediate representations, or protect only a subset of the training and inference pipeline. We introduce Client-Resolved Generation (CRG), a genera- tion interface that separates server-side generation from the lexical realization of input-derived content. The client transmits only pooled and noise-perturbed rep- resentations, while input-derived output content is represented using request-local positional references and resolved to its original strings only on the client. This interface protects private input and input-derived output content during both train- ing and inference while allowing the service provider to keep its proprietary model parameters hidden from the client. At the same time, exact lexical reuse remains possible without directly exposing the reused content on the provider-visible gen- eration path. We evaluate CRG on medical and document-grounded QA, sensi- tive identifier transfer, and tool calling, together with reconstruction and raw-logit leakage analyses. On SealTools, CRG improves complete-call exact match from 57.3% to 79.9% over the input-privacy framework PPFT, with larger gains as more required output content can be resolved through references. Together, these results show that CRG provides a practical interface for privacy-sensitive cloud LLMs by reducing plaintext exposure across both input and output pathways while preserv- ing task utility and server-side model confidentiality.