Pith. sign in

REVIEW 2 cited by

Prompt Inference Attack on Distributed Large Language Model Inference Frameworks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2503.09291 v2 pith:2X7GCLKH submitted 2025-03-12 cs.CR

classification cs.CR
keywords inferenceattackattacksdistributedframeworkspromptsauxiliarydataset
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The inference process of modern large language models (LLMs) demands prohibitive computational resources, rendering them infeasible for deployment on consumer-grade devices. To address this limitation, recent studies propose distributed LLM inference frameworks, which employ split learning principles to enable collaborative LLM inference on resource-constrained hardware. However, distributing LLM layers across participants requires the transmission of intermediate outputs, which may introduce privacy risks to the original input prompts - a critical issue that has yet to be thoroughly explored in the literature. In this paper, we rigorously examine the privacy vulnerabilities of distributed LLM inference frameworks by designing and evaluating three prompt inference attacks aimed at reconstructing input prompts from intermediate LLM outputs. These attacks are developed under various query and data constraints to reflect diverse real-world LLM service scenarios. Specifically, the first attack assumes an unlimited query budget and access to an auxiliary dataset sharing the same distribution as the target prompts. The second attack also leverages unlimited queries but uses an auxiliary dataset with a distribution differing from the target prompts. The third attack operates under the most restrictive scenario, with limited query budgets and no auxiliary dataset available. We evaluate these attacks on a range of LLMs, including state-of-the-art models such as Llama-3.2 and Phi-3.5, as well as widely-used models like GPT-2 and BERT for comparative analysis. Our experiments show that the first two attacks achieve reconstruction accuracies exceeding 90%, while the third achieves accuracies typically above 50%, even under stringent constraints. These findings highlight privacy risks in distributed LLM inference frameworks, issuing a strong alert on their deployment in real-world applications.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Depth Gives a False Sense of Privacy: LLM Internal States Inversion

    cs.CR 2025-07 conditional novelty 6.0 of 10

    LLM internal states at intermediate layers contain enough information to recover long, sensitive user prompts with high accuracy.

  2. Integrity of peer-to-peer distributed LLM inference under malicious nodes

    cs.CR 2026-07 conditional novelty 5.0 of 10

    Under a simulated isotropic noise model, a canary-trap activation-drift detector achieves perfect AUROC separation of one malicious shard in multi-hop LLM inference.

Pith tools