SoK: systematizing 58 cryptographic private transformer inference frameworks
chaumian · x · 2026-09-15
A Chinese University of Hong Kong SoK paper systematizes 58 cryptographic private transformer inference frameworks (2022–2026) across three interacting levels: systems (execution & optimization), models (crypto–ML co-design), and cryptography.
Key findings:
- Optimizations do not transfer unchanged across execution phases when they require values not yet available; data-dependent pruning, cache management, routing and sparsity demand the private execution structure be hidden, constrained, predicted, or disclosed.
- Against an output-only baseline, 5 frameworks exhibit four classes of security concerns; composition boundaries in maliciously secure designs are synthesized.
- 16 frameworks rely on empirically calibrated or distribution-specific mechanisms and 21 require additional training, limiting generalization and comparability.
- The paper distills 12 open problems and 16 outlooks spanning protocol efficiency, cross-level co-design, dynamic execution, security, evaluation, and scalability.
More from Safety
- Stolen session led to $293.37 CAD fraudulent Pro upgrade — and total OpenAI support lockout — Zylora · 2026-09-15
- China already mandates AI video labeling and banned consumer voice cloning to curb fraud — a_karvonen · 2026-09-15
- Telling Claude it's on the real internet drops its hacking rate to zero — jessi_cata · 2026-09-15
- 'Are we humans even aligned with each other?' A contrarian take on AI alignment — YiMaTweets · 2026-09-15
- Apollo Research welcomes Anthropic and OpenAI's embedded evaluator commitments for safety oversight — joecole · 2026-09-15
- AI safety expert: loss of control was never researchers' top concern, but that may be shifting — DavidSKrueger · 2026-09-15