Paper 2026/2005

SoK: Private Transformer Inference Across Systems, Models, and Cryptography

Andes Y. L. Kei, Chinese University of Hong Kong
Sherman S. M. Chow, Chinese University of Hong Kong
Abstract

Private inference can protect user queries and model weights without trusted hardware or statistical privacy relaxations, but transformers combine large secret matrix multiplications, costly nonlinearities, and sequential autoregressive execution. Prior surveys organize the literature mainly by cryptographic backend, deployment setting, or supported operation, obscuring when techniques remain applicable or composable across execution phases, model adaptations, or security boundaries. We systematize 58 cryptographic private transformer frameworks (2022--2026) across three interacting levels: systems (execution and optimization), models (cryptography--machine learning co-design and adaptation), and cryptography (secure realization of transformer operations). This analysis reveals two recurring cross-backend applicability constraints: optimizations do not transfer unchanged across execution phases when they require values not yet available, while data-dependent pruning, cache management, routing, and sparsity require private execution structure to be hidden, constrained, predicted, or disclosed. Against an output-only reference baseline, we identify four classes of security concerns affecting 5 frameworks and synthesize composition boundaries in maliciously secure designs. We find that 16 frameworks rely on empirically calibrated or distribution-specific mechanisms and 21 require additional training, limiting generalization and cross-framework comparability. We distill these findings into 12 open problems and 16 outlooks spanning protocol efficiency, cross-level co-design, dynamic execution, security, evaluation, and scalability.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
privacy-preserving MLprivate transformer inferencesecure multiparty computationLLMscryptography-ML co-design
Contact author(s)
kyl022 @ ie cuhk edu hk
smchow @ ie cuhk edu hk
History
2026-09-14: last of 2 revisions
2026-09-13: received
See all versions
Short URL
https://ia.cr/2026/2005
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2005,
      author = {Andes Y. L. Kei and Sherman S. M. Chow},
      title = {{SoK}: Private Transformer Inference Across Systems, Models, and Cryptography},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2005},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2005}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.