Computer Science editorial
Privacy Failure in Split-LLM Training: The Returned Gradient Nullifies the Decoys
The core problem
Innovation
The experimental protocol was fixed in advance to avoid post hoc tuning. It includes three components: (1) a leak injected at known strength to prove the instrument can see one, (2) a shuffled-label control to prove it does not report absent leaks, and (3) a threshold set before the runs. The system under test is a two-node split-LLM training setup. The TLN sends protected activations to the UCN; the UCN returns its output; the TLN, holding the private loss, returns the output gradient. The frame the UCN receives mixes real rows with decoys, and the loss ignores the decoys. Formally, for a frame containing real rows and decoy rows , the loss depends only on , so for each decoy row the returned gradient satisfies
Why it matters
Who should read this
Opening member contentโฆ