Methods and systems for protecting privacy of large model inference data in confidential computing environments

CN122339679APending Publication Date: 2026-07-03HUIYUN ZHICE TECH (SUZHOU) CO LTD
View PDF -1 Cites 0 Cited by

Patent Information

Application Number
CN202610463620.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-09
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Existing trusted execution environments cannot effectively prevent network side-channel leakage in large model inference. Attackers can infer user information by analyzing the timing and size sequences of network traffic. Existing defense solutions affect the semantic coherence of streaming output and user experience.

Method used

Within a trusted execution environment, the streaming token stream is collected and semantically analyzed in real time to generate a sequence of token tuples carrying information entropy weights. Through dynamic aggregation planning of semantic equivalence classes and information entropy weights, token blocks are generated and their lengths are standardized and encrypted for transmission, eliminating the statistical correlation between data packet size and temporal characteristics and the semantics of the generated content.

Benefits of technology

Without affecting model inference performance, the risk of side channel leakage due to timing patterns and packet size is completely eliminated, the semantic coherence of streaming output and real-time interactive experience are maintained, and end-to-end privacy protection is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122339679A_ABST
    Figure CN122339679A_ABST
Patent Text Reader

Abstract

This invention relates to a method and system for protecting the privacy of large model inference data in a confidential computing environment. The method includes: real-time acquisition of the raw token stream generated by model inference, recording the conditional probability and generation time, and performing semantic correlation analysis to generate a sequence of raw token tuples; calculating information entropy weights based on conditional probabilities and appending them to the corresponding token tuples to generate a complete token tuple sequence; dynamically aggregating and planning the tokens based on semantic equivalence class identifiers and information entropy weights to generate a token block partitioning scheme; re-encapsulating the tokens based on the partitioning scheme to generate a token block sequence; and performing length standardization processing on each token block to generate network transmission packets with uniform length characteristics and sending them to the user terminal. This invention solves the problem that existing trusted execution environments cannot prevent network side-channel attacks by eliminating the statistical correlation of data packet timing and size through semantically preserved traffic shaping, while ensuring the semantic coherence of the output.
Need to check novelty before this filing date? Find Prior Art