Paper overview
Abstract
Cloud-edge collaborative decoding keeps private context on-device, but the probabilities or tokens exchanged during decoding can still expose sensitive information. This work audits privacy leakage in both edge-side and cloud-side fusion, including private-evidence exposure and context inversion from step-wise signals. It further introduces a training-free defense designed to improve the privacy-utility trade-off without changing the underlying models.
