OSNIP: Balancing the Privacy-Utility-Efficiency Trilemma in LLM Inference via Obfuscated Semantic Null Space

Zhiyuan Cao, Zeyu Ma, Chenhao Yang, Han Zheng, Mingang Chen
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:11433-11455, 2026.

Abstract

We propose Obfuscated Semantic Null Space Injection for Privacy (OSNIP), a lightweight client-side encryption framework for privacy-preserving LLM inference. Generalizing the geometric intuition of linear kernels to the high-dimensional latent space of LLMs, we formally define the “Obfuscated Semantic Null Space”, a high-dimensional regime that preserves semantic fidelity while enforcing near-orthogonality to the original embedding. By injecting perturbations that project the original embedding into this space, OSNIP ensures privacy without any post-processing. Furthermore, OSNIP employs a key-dependent stochastic mapping that generates distinct perturbations under fresh keys. Evaluations on generative and classification benchmarks show that OSNIP achieves state-of-the-art performance, sharply reducing attack success rates while maintaining strong model utility under strict security constraints.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-cao26q, title = {{OSNIP}: Balancing the Privacy-Utility-Efficiency Trilemma in {LLM} Inference via Obfuscated Semantic Null Space}, author = {Cao, Zhiyuan and Ma, Zeyu and Yang, Chenhao and Zheng, Han and Chen, Mingang}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {11433--11455}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/cao26q/cao26q.pdf}, url = {https://proceedings.mlr.press/v306/cao26q.html}, abstract = {We propose Obfuscated Semantic Null Space Injection for Privacy (OSNIP), a lightweight client-side encryption framework for privacy-preserving LLM inference. Generalizing the geometric intuition of linear kernels to the high-dimensional latent space of LLMs, we formally define the “Obfuscated Semantic Null Space”, a high-dimensional regime that preserves semantic fidelity while enforcing near-orthogonality to the original embedding. By injecting perturbations that project the original embedding into this space, OSNIP ensures privacy without any post-processing. Furthermore, OSNIP employs a key-dependent stochastic mapping that generates distinct perturbations under fresh keys. Evaluations on generative and classification benchmarks show that OSNIP achieves state-of-the-art performance, sharply reducing attack success rates while maintaining strong model utility under strict security constraints.} }
Endnote
%0 Conference Paper %T OSNIP: Balancing the Privacy-Utility-Efficiency Trilemma in LLM Inference via Obfuscated Semantic Null Space %A Zhiyuan Cao %A Zeyu Ma %A Chenhao Yang %A Han Zheng %A Mingang Chen %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-cao26q %I PMLR %P 11433--11455 %U https://proceedings.mlr.press/v306/cao26q.html %V 306 %X We propose Obfuscated Semantic Null Space Injection for Privacy (OSNIP), a lightweight client-side encryption framework for privacy-preserving LLM inference. Generalizing the geometric intuition of linear kernels to the high-dimensional latent space of LLMs, we formally define the “Obfuscated Semantic Null Space”, a high-dimensional regime that preserves semantic fidelity while enforcing near-orthogonality to the original embedding. By injecting perturbations that project the original embedding into this space, OSNIP ensures privacy without any post-processing. Furthermore, OSNIP employs a key-dependent stochastic mapping that generates distinct perturbations under fresh keys. Evaluations on generative and classification benchmarks show that OSNIP achieves state-of-the-art performance, sharply reducing attack success rates while maintaining strong model utility under strict security constraints.
APA
Cao, Z., Ma, Z., Yang, C., Zheng, H. & Chen, M.. (2026). OSNIP: Balancing the Privacy-Utility-Efficiency Trilemma in LLM Inference via Obfuscated Semantic Null Space. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:11433-11455 Available from https://proceedings.mlr.press/v306/cao26q.html.

Related Material