Paper 2025/1774

Adaptive-Controlled Mutual TLS for Large Language Model Systems

Lui Zheng, University of Chicago
Roger Zhu, University of Chicago
Amit Agrawal
Carol Lamore
Abstract

Mutual Transport Layer Security (mTLS) under- pins authenticated, confidential communication across modern service meshes, but its deployment stance in machine-learning platforms is typically static—fixed cipher suites, certificate life- times, and re-authentication schedules chosen for worst-case threats rather than observed risk. Large Language Model (LLM) serving pipelines exacerbate this rigidity: traffic is bursty, topolo- gies reconfigure dynamically under autoscaling, and sensitive artifacts such as prompts, training features, and evaluation data traverse heterogeneous substrates. In this paper we argue that mTLS for LLM systems[1] should be governed by adaptive control rather than static policy. We formalize a feedback loop that ingests multi-modal telemetry—connection error codes, handshake latencies, anomaly scores from request semantics, workload attestation freshness, and service-level objective (SLO) drift—and outputs fine-grained adjustments to transport posture: client-certificate renewal cadence, certificate path length and key type selection, session resumption eligibility, early data gat- ing, proof-of-possession challenges, and revocation propagation thresholds. The controller targets two coupled objectives: maintain cryptographic assurances (mutual authentication, forward secrecy, and replay resistance) while bounding the cost of security on tail latency and throughput during high-load inference.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. Minor revision. 8th International Conference on Cryptography, Security and Privacy (CSP)
DOI
10.1109/CSP62567.2024
Keywords
mutual tlsprivacy preserving mlencryption
Contact author(s)
luizheng @ uchicago edu
roger z @ uchicago edu
amita @ scale ai
carolla @ scale ai
History
2025-10-03: revised
2025-09-28: received
See all versions
Short URL
https://ia.cr/2025/1774
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2025/1774,
      author = {Lui Zheng and Roger Zhu and Amit Agrawal and Carol Lamore},
      title = {Adaptive-Controlled Mutual {TLS} for Large Language Model Systems},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1774},
      year = {2025},
      doi = {10.1109/CSP62567.2024},
      url = {https://eprint.iacr.org/2025/1774}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.