Ilmu Komputer & AI editorial
Open AccessOA2026
LLMs as Linguistic Chameleons: Decoupling Semantics and Structure for Privacy-Preserving Communication
CROSS-MAP: A bidirectional framework for inference-time privacy via semantic decoupling
Yuzhu Mao; Liang Zhao· 2026· DOI 10.48550/arXiv.2609.23193
The core problem
Large Language Model (LLM) APIs are increasingly embedded in privacy-sensitive workflows, yet ensuring inference-time privacy without sacrificing task utility remains an open challenge. Existing privacy-preserving approaches typically retain most of the original semantic content to maintain downstream performance. However, this retention leaves exploitable cues that adversaries can use to reconstruct the original text. The authors, Yuzhu Mao and Liang Zhao, investigate **semantic decoupling**: replacing original semantics with alternative content while preserving the structural properties required for LLM reasoning. This motivates **CROSS-MAP**, a bidirectional framework that maps private inputs into a different semantic domain before inference and recovers the corresponding outputs afterward. The core tension is between semantic divergence (to defeat reconstruction) and semantic consistency (to preserve utility).
Innovation
Experiments evaluate CROSS-MAP across multiple attack settings designed to reconstruct the original input from the transformed representation. The authors report that CROSS-MAP **reduces reconstruction success** compared to existing baselines, indicating stronger privacy protection. At the same time, it **outperforms existing baselines in utility**, meaning the recovered outputs remain useful for downstream tasks. The results suggest that semantic decoupling can achieve a better privacy-utility trade-off than methods that preserve most of the original semantics. The paper does not provide specific numerical values in the abstract; detailed metrics are expected in the full text.
Large Language Model (LLM) APIs are increasingly embedded in privacy-sensitive workflows, yet ensuring inference-time privacy without sacrificing task utility remains an open challenge. Existing privacy-preserving approaches typically retain most of the original semantic content to maintain downstream performance. However, this retention leaves exploitable cues that adversaries can use to reconstruct the original text. The authors, Yuzhu Mao and Liang Zhao, investigate **semantic decoupling**: replacing original semantics with alternative content while preserving the structural properties required for LLM reasoning. This motivates **CROSS-MAP**, a bidirectional framework that maps private inputs into a different semantic domain before inference and recovers the corresponding outputs afterward. The core tension is between semantic divergence (to defeat reconstruction) and semantic consistency (to preserve utility).
CROSS-MAP operates in two stages: a **mapping stage** that transforms a private input into a semantically divergent representation in an alternative domain, and a **recovery stage** that maps the LLM output back to the original semantic domain, yielding
. Local models are trained with multi-objective optimization to balance two goals:
Why it matters
The key insight of CROSS-MAP is that **structure**—not semantics—is what LLMs primarily need for reasoning. By preserving structural cues while replacing semantics, the framework denies adversaries the semantic content required for reconstruction. This decoupling challenges the assumption that utility requires semantic fidelity. The multi-objective training ensures that the mapping and recovery stages are jointly optimized, preventing the mapping from becoming so divergent that recovery fails. Potential limitations include the reliance on local models for mapping and recovery, which may introduce computational overhead, and the need to define appropriate divergence measures. Future work could explore adaptive divergence objectives and extensions to multimodal inputs. Overall, CROSS-MAP represents a promising direction for privacy-preserving LLM inference.
Who should read this
CS practitioners and researchers
Opening member content…