Ilmu Komputer & AI editorial
Open AccessOA2026
Understanding the Security Boundary of Obfuscation-based On-Device LLM Protection
A formal primitive-based framework reveals shared vulnerabilities in TEE-Shielded LLM Partitioning and extends the security boundary with new obfuscation primitives.
Hanyi Zhou; Chenyang Li; Yuanzhe Pang; Ke Xu; Mingwei Xu; Zhuotao Liuยท 2026ยท DOI 10.48550/arXiv.2609.10117
The core problem
On-device Large Language Models (LLMs) face a critical challenge: protecting intellectual property while maintaining computational efficiency. Trusted Execution Environments (TEEs) offer a promising solution, but their inherent computational bottlenecks limit direct deployment. To address this, TEE-Shielded LLM Partition (TSLP) methods apply efficient obfuscation schemes to computationally intensive layers, offloading them to external GPUs while retaining only lightweight operations within the TEE. Although a growing body of TSLP-based approaches has emerged, these defense mechanisms remain largely heuristic. Consequently, some methods are proven vulnerable to specialized adversarial attacks designed to exploit their specific architectural implementations. This paper addresses a fundamental research question: can we establish common primitives to unify representative prior methodologies, characterize the security boundary of their compositions, and systematically extend them? By formalizing obfuscation primitives as dual-tuples of linear computations satisfying specific algebraic properties, the authors demonstrate that matrix-level weight transformations of several representative
Innovation
The authors demonstrate the effectiveness of by applying it to several prominent TSLP methods published in top-tier venues: ArrowCloak (Security'25), TSQP (S&P'25), and LoRO (NeurIPS'25). The attack successfully recovers the original weights from the obfuscated computations in all these methods, revealing a shared vulnerability. The results show that the security boundary is insufficient to protect against primitive-guided attacks. The authors quantify the attack's success rate and computational cost, showing that it is efficient and practical. For instance, the attack can recover weights with high accuracy within a reasonable time frame, undermining the security guarantees of these methods. In contrast, the proposed extends the security boundary by incorporating two novel obfuscation primitives. The authors evaluate against and demonstrate that it successfully resists the attack, preserving the confidentiality of the model weights. The results include a comparative analysis of the security levels achieved by and , showing a significant impr
On-device Large Language Models (LLMs) face a critical challenge: protecting intellectual property while maintaining computational efficiency. Trusted Execution Environments (TEEs) offer a promising solution, but their inherent computational bottlenecks limit direct deployment. To address this, TEE-Shielded LLM Partition (TSLP) methods apply efficient obfuscation schemes to computationally intensive layers, offloading them to external GPUs while retaining only lightweight operations within the TEE. Although a growing body of TSLP-based approaches has emerged, these defense mechanisms remain largely heuristic. Consequently, some methods are proven vulnerable to specialized adversarial attacks designed to exploit their specific architectural implementations. This paper addresses a fundamental research question: can we establish common primitives to unify representative prior methodologies, characterize the security boundary of their compositions, and systematically extend them? By formalizing obfuscation primitives as dual-tuples of linear computations satisfying specific algebraic properties, the authors demonstrate that matrix-level weight transformations of several representative efficient TSLP frameworks can be expressed as compositions of these primitives. The canonical form of these primitive compositions, denoted as , defines the security boundary of this primitive family. The paper then exposes vulnerabilities of through a novel primitive-guided attack methodology, , demonstrating a shared vulnerability in several prominent TSLP methods published in top-tier venues, such as ArrowCloak (Security'25), TSQP (S&P'25), and LoRO (NeurIPS'25). Finally, the authors introduce two novel obfuscation primitives and integrate them with existing constructs to formulate , extending the prior security boundary .
The paper formalizes a set of obfuscation primitives, defined as dual-tuples of linear computations satisfying specific algebraic properties. These primitives serve as building blocks for expressing the matrix-level weight transformations used in TSLP frameworks. The authors demonstrate that several representative efficient TSLP frameworks can be expressed as compositions of these primitives. The canonical form of these primitive compositions, denoted as , defines the security boundary of this primitive family. To expose vulnerabilities, the authors introduce a novel primitive-guided attack methodology, , which systematically exploits the algebraic structure of the primitives. The attack is designed to recover the original weights from the obfuscated computations, thereby breaching the security boundary. The methodology involves analyzing the composition of primitives and identifying algebraic weaknesses that allow for efficient inversion. The authors then introduce two novel obfuscation primitives and integrate them with existing constructs to formulate , which extends the prior security boundary . The new primitives are designed to resist the algebraic attacks that compromise the original boundary, providing a stronger security guarantee. The paper provides a formal analysis of the security properties of both and , including proofs of security and complexity analysis of the attack.
Why it matters
The paper's findings highlight a critical gap in the security of existing TSLP methods: their heuristic designs lead to shared vulnerabilities that can be systematically exploited. By formalizing obfuscation primitives, the authors provide a unified framework for understanding and comparing different TSLP approaches. The security boundary represents the limit of what can be achieved with the original set of primitives. The introduction of demonstrates that by extending the primitive set, the security boundary can be pushed further, offering stronger protection. The authors discuss the implications of their work for the design of future TSLP methods, emphasizing the importance of formal analysis and the need to consider algebraic properties of obfuscation schemes. They also note that while improves security, it may introduce additional computational overhead, which must be balanced against the desired security level. The paper concludes by suggesting that the primitive-based approach can be generalized to other domains of secure computation, such as secure multi-party computation and homomorphic encryption. The taxonomy of primitives and the attack methodology provide a foundation for future research in this area. The authors also discuss potential limitations and avenues for future work, including the need for more efficient primitives and the exploration of other attack vectors.
Who should read this
CS practitioners and researchers
Opening member contentโฆ