Ilmu Komputer & AI editorial
Open AccessOA2026
Reversibility-Verified De-identification for Cloud-Local LLM Inference: A Locally Certified Dehydrate-Rehydrate Loop with Layered Assurance (DR-SL)
A locally certified dehydrate-rehydrate loop with layered assurance for privacy-preserving cloud-local LLM inference
Wen Hu; Ya Yu; Xutong Wang· 2026· DOI 10.48550/arXiv.2609.14883
The core problem
Cloud-local LLM inference presents a fundamental tension: sensitive user data must remain on-device, yet cloud-grade reasoning capabilities are desired. Existing sanitization approaches—placeholder substitution, differential-privacy perturbation, and skill distillation—lack a release decision that is simultaneously safe and utility-preserving. The authors propose DR-SL (Dehydrate-Rehydrate with Self-Learning loop), which formalizes de-identification completeness as two measurable conditions: de-identification sufficiency under Pufferfish semantics, and task-information preservation via QA probes. The work addresses the critical gap between theoretical privacy guarantees and practical release decisions in hybrid inference architectures. The core challenge is to certify that a dehydrated prompt sent to the cloud cannot leak sensitive information, while ensuring the rehydrated response remains useful for the local task. DR-SL introduces a locally certified loop with layered assurance, combining a deterministic hard line, an external strong-attacker re-test, and human fallback. The authors prove Fano-type lower bounds, a Pufferfish witness, and a rate-privacy feasibility criterion, but
Innovation
On a worst-case fully task-coupled benchmark, the DR-SL loop reduces leakage from 0.457 to 0.304 (p ≈ 0), demonstrating a statistically significant improvement. The release chain delivers 0.000 literal leakage at egress across 160 instances tested against two strong attackers. The system degrades to certification-and-routing exactly as the feasibility criterion predicts, validating the theoretical model. On a mixed-coupling benchmark, the same safe point releases 67.5% of instances automatically at zero measured leakage, Pareto-dominating placeholder and selective-LDP corners under an identical release rule. Two human studies anchor the semantic utility metric (Spearman ρ = 0.839) and the annotation gold (type-level recall at least 0.987). The exploratory self-learning hypothesis was not supported and is reported as such. All theoretical bounds pass numerical verification. The results show that DR-SL achieves a practical balance between privacy and utility, with the hard line and human review providing safety guarantees that theoretical bounds alone cannot. The 0.000 literal leakage at egress is particularly notable, as it means no sensitive data was directly exposed in the tested
Cloud-local LLM inference presents a fundamental tension: sensitive user data must remain on-device, yet cloud-grade reasoning capabilities are desired. Existing sanitization approaches—placeholder substitution, differential-privacy perturbation, and skill distillation—lack a release decision that is simultaneously safe and utility-preserving. The authors propose DR-SL (Dehydrate-Rehydrate with Self-Learning loop), which formalizes de-identification completeness as two measurable conditions: de-identification sufficiency under Pufferfish semantics, and task-information preservation via QA probes. The work addresses the critical gap between theoretical privacy guarantees and practical release decisions in hybrid inference architectures. The core challenge is to certify that a dehydrated prompt sent to the cloud cannot leak sensitive information, while ensuring the rehydrated response remains useful for the local task. DR-SL introduces a locally certified loop with layered assurance, combining a deterministic hard line, an external strong-attacker re-test, and human fallback. The authors prove Fano-type lower bounds, a Pufferfish witness, and a rate-privacy feasibility criterion, but explicitly state their scope: the bounds certify leakage, never safety, and are near-vacuous at the operating point. Thus, release safety rests on empirical calibration, the hard line, and human review.
DR-SL operates as a two-branch verifier that iterates dehydration under a lexicographic gate with guaranteed termination. The dehydration process transforms a local prompt into a sanitized version for cloud inference, while rehydration reconstructs the final response locally. The lexicographic gate prioritizes de-identification sufficiency first, then task-information preservation, ensuring that no release occurs unless both conditions are met. The verifier includes a deterministic hard line that blocks any release violating absolute privacy constraints, an external strong-attacker re-test that simulates adversarial inference, and a human fallback for ambiguous cases. The self-learning loop attempts to improve dehydration over time, though the exploratory hypothesis was not supported. The system's architecture can be represented as a flow diagram:
Why it matters
The DR-SL framework provides a layered assurance approach to cloud-local LLM inference, combining theoretical bounds with empirical calibration and human review. The authors explicitly state that the Fano-type lower bounds and Pufferfish witness certify leakage, never safety, and are near-vacuous at the operating point. This honest scope statement is crucial: it means that release safety cannot rely on theory alone but must be enforced by the deterministic hard line and human fallback. The feasibility criterion predicts when the system degrades to certification-and-routing, which was confirmed on the worst-case benchmark. The Pareto dominance on mixed-coupling data shows that DR-SL can achieve better privacy-utility trade-offs than placeholder substitution and selective LDP. However, the negative result on self-learning suggests that the loop does not adaptively improve, which may limit its long-term effectiveness. The human studies provide strong validation of the utility metric and annotation quality, but the reliance on human fallback introduces scalability concerns. The system's ability to release 67.5% of instances automatically at zero leakage is promising for practical deployment, but the remaining 32.5% require human review or blocking. The theoretical bounds, while near-vacuous, still provide a formal foundation for understanding leakage. The rate-privacy feasibility criterion is a key contribution, as it predicts when the system can operate safely. The external strong-attacker re-test adds an adversarial layer that goes beyond standard privacy audits. Overall, DR-SL represents a significant step toward certifiable de-identification for cloud-local inference, but its safety ultimately depends on empirical calibration and human oversight. Future work could explore improving the self-learning loop or reducing human fallback through better verifiers. The public release of code, synthetic datasets, protocol, and human-study packages supports reproducibility and further research.
Who should read this
CS practitioners and researchers
Opening member content…