Paper 2025/1774
Adaptive-Controlled Mutual TLS for Large Language Model Systems
Abstract
Mutual Transport Layer Security (mTLS) under- pins authenticated, confidential communication across modern service meshes, but its deployment stance in machine-learning platforms is typically static—fixed cipher suites, certificate life- times, and re-authentication schedules chosen for worst-case threats rather than observed risk. Large Language Model (LLM) serving pipelines exacerbate this rigidity: traffic is bursty, topolo- gies reconfigure dynamically under autoscaling, and sensitive artifacts such as prompts, training features, and evaluation data traverse heterogeneous substrates. In this paper we argue that mTLS for LLM systems[1] should be governed by adaptive control rather than static policy. We formalize a feedback loop that ingests multi-modal telemetry—connection error codes, handshake latencies, anomaly scores from request semantics, workload attestation freshness, and service-level objective (SLO) drift—and outputs fine-grained adjustments to transport posture: client-certificate renewal cadence, certificate path length and key type selection, session resumption eligibility, early data gat- ing, proof-of-possession challenges, and revocation propagation thresholds. The controller targets two coupled objectives: maintain cryptographic assurances (mutual authentication, forward secrecy, and replay resistance) while bounding the cost of security on tail latency and throughput during high-load inference.
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Published elsewhere. Minor revision. 8th International Conference on Cryptography, Security and Privacy (CSP)
- DOI
- 10.1109/CSP62567.2024
- Keywords
- mutual tlsprivacy preserving mlencryption
- Contact author(s)
-
luizheng @ uchicago edu
roger z @ uchicago edu
amita @ scale ai
carolla @ scale ai - History
- 2025-10-03: revised
- 2025-09-28: received
- See all versions
- Short URL
- https://ia.cr/2025/1774
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2025/1774,
author = {Lui Zheng and Roger Zhu and Amit Agrawal and Carol Lamore},
title = {Adaptive-Controlled Mutual {TLS} for Large Language Model Systems},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1774},
year = {2025},
doi = {10.1109/CSP62567.2024},
url = {https://eprint.iacr.org/2025/1774}
}