LoREnc: Low-Rank Encryption for Securing Foundation Models and LoRA Adapters
Beomjin Ahn, Jungmin Kwon, Chanyong Jung, Jaewook Chung
Samsung Research · Samsung Electronics · Amazon Web Services · University of Michigan
cs.CR, cs.CV, cs.LG
Submitted: 2026-05-13
Updated: 2026-08-18
Comments: Accepted to ICIP 2026
Code: https://github.com/tylin/coco-caption
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 92/100
Terminology
Summary
Summary
LoREnc (Low-Rank Encryption) is a training-free framework proposed to secure both foundation models (FMs) and their LoRA adapters against unauthorized reuse, model recovery attacks, and intellectual property leakage. The paper states: "We propose LoREnc, a training-free framework that secures both FMs and adapters via spectral truncation and compensation. LoREnc suppresses dominant low-rank components of FM weights, compensates for the missing information in authorized adapters, and further applies orthogonal reparameterization to obscure structural fingerprints of the protected adapter. Unauthorized users produce structurally collapsed outputs, while authorized users recover exact performance."
The framework operates in the model's weight space rather than at the bit level, described as in the spirit of perceptual encryption [3], where unauthorized access leads to severe semantic degradation of model outputs.
It is inspired by the Eckart–Young theorem, and "mathematically suppresses the dominant low-rank components of FM weights to structurally degrade unauthorized inference outputs. Conversely, it compensates for these components in authorized adapters to enable theoretically exact recovery of original performance. LoREnc is data-independent:
LoREnc operates purely on post-training weights without accessing the original dataset, thereby ensuring data-independence suitable for privacy-sensitive on-device deployment."
The threat model assumes "restoration keys are protected in a hardware-backed environment such as a Trusted Execution Environment (TEE), while the deployed artifacts (encrypted FM weights and encrypted adapters) are accessible to an unauthorized party. The adversary attempts restoration via
ML-level weight-extraction methods such as Spectral DeTuning (SDT) [10] or limited fine-tuning. LoREnc targets
practical empirical resistance against such ML-level extraction, rather than formal cryptographic unrecoverability."
The method has three main components. First, Spectral Truncation: For a weight matrix W, the low-rank component L is extracted via truncated SVD: L = U FM Σ FM V FM T = TSVD Δr(W). The truncated weight is W̃ = W − L, and L is never deployed. The paper proves via Lemma 1 that among all subsets S ⊆ I with S = Δr, the set T = 1,..., Δr maximizes ∥X S∥ F,
meaning truncating the top singular components maximizes the Frobenius-norm distance between original and truncated weights.
Second, Spectral Compensation via LoRA: To preserve downstream functionality, the compensated adapters satisfy W̃ + B̃ k à k = W + B k A k, yielding B̃ k à k = L + B k A k. This is achieved via rank expansion: B̃ k = [B k, U FM Σ FM 1/2] and à k = [A k, Σ FM 1/2 V FM T] T, where B̃ k ∈ R m×(r+Δr) and à k ∈ R(r+Δr)×n. This ensures exact downstream recovery while effectively fusing the low-rank component into the LoRA adapters.
Third, LoRA Adapter Encryption: The compensated adapters are further protected. SVD is applied to B̃ k à k = U Lo Σ Lo V Lo T, and split into restoration keys (K B̃k, K Ãk) and encrypted adapter weights (B̃ k*, à k*). This reduces the rank back from r+Δr to r. Then, an Orthogonal LoRA Reparameterization is applied: B̃ k′ = B̃ k* M k, à k′ = M k T à k*, with a random orthogonal matrix M k ∈ R r×r. This induces an isometric rotation in the parameter space, creating infinite equivalent factorizations for the same product,
preventing adversaries from detecting the protection via structural fingerprints.
For Authorized Downstream Inference, the decrypted weight is reconstructed on-the-fly as W̃ + B̃ k′ Ã k′ + K B̃k K Ãk = W + B k A k, requiring no additional memory for restored FM weights. Notably, even authorized users cannot directly access the original FM weight W, as the low-rank component L is never deployed to the device.
The paper defines six design requirements: Effectiveness (unauthorized inference yields semantically meaningless outputs), Integrity (authorized inference exactly matches baseline), Stealthiness (protected weights not structurally distinct), Efficiency (minimal overhead), Resilience (unrecoverable under model separation and restoration attacks), and Data-independence (no training data required).
Experiments were conducted primarily on Stable Diffusion v1.5 (SD 1.5) for comparison with Spectral DeTuning, plus GPT-2 and Llama 3 for autoregressive models, and Sana-0.6B (a DiT model) for architecture-agnostic validation. Key results:
-
Q1 (Efficacy): Unauthorized foundation inference shows severe degradation (CLIP score drops from 0.267 to 0.118; LPIPS of 0.827), while authorized users recover baseline outputs
up to negligible floating-point errors
(∆CLIP = 0.000, LPIPS = 0.000). For autoregressive models, LoREnc induceshigh perplexity
(GPT-2: +120.0 PPL; Llama 3: +8793 PPL) for unauthorized access, with 0.000 ∆PPL for authorized users. -
Q2 (Fine-tuning attack): LoREnc outperforms NNSplitter across all data regimes (0.1k–100k samples). Even with 100k samples, CLIP score remains 0.231 vs. baseline 0.267, showing
LoREnc consistently prevents meaningful FM recovery.
-
Q3 (Spectral DeTuning attack): LoREnc maintains
consistently high W-Error
even under large-scale adapter collection, while random keys and self-derived keys fail because theydo not capture the structural dependencies and critical spectral information (L) of the foundation model.
-
Q4 (Efficiency): With Δr=4, overhead is under 1%: +0.19% parameters, +0.40% GFLOPs, +0.22% inference time on a commercial smartphone (Galaxy Fold 4). The paper notes a non-linear latency jump at Δr=16 due to
memory access overheads exceeding cache thresholds or suboptimal kernel tiling.
For DiT architectures (Sana-0.6B), the paper notes that a minimal spectral truncation (Δr = 4) leads to partial information leakage
due to dense spectral information, but at Δr = 16, the global structural information is completely lost,
with parameter overhead still negligible at approximately 0.69%.
The paper concludes: "LoREnc satisfies all six design requirements—Effectiveness, Integrity, and Resilience—verified through extensive experiments, while maintaining Stealthiness, Data-independence, and Efficiency essential for practical edge deployment."
Improvements for AI systems
Based on the paper, here are the specific improvements I can implement in an AI system, along with what the improved system can do:
1. Add a Spectral Truncation
module to any deployed foundation model (FM)
-
Implementation: Before deployment, apply truncated SVD (rank
∆r, e.g., 4) to each weight matrixWof the FM. Store the low-rank componentL = U FM Σ FM V FM Tas a secret key, and deploy onlyW̃ = W − Lto the edge device. -
What the improved system can do: Without the key, the model produces structurally collapsed outputs (e.g., repeated tokens in text, noise-like images) instead of coherent generations. This prevents unauthorized inference and model stealing.
2. Add a Spectral Compensation
mechanism to authorized LoRA adapters
- Implementation: For each authorized LoRA adapter
(B k, A k), expand its rank fromrtor + ∆rby concatenating the spectral key components:
B̃ k = [B k, U FM Σ FM 1/2], Ã k = [A k; Σ FM 1/2 V FM T].
This ensures W̃ + B̃ k à k = W + B k A k exactly.
- What the improved system can do: Authorized users with the key achieve numerically identical performance to the original model (verified by zero CLIP/LPIPS difference in experiments), while unauthorized users cannot recover the original weights even with fine-tuning or Spectral DeTuning attacks.
3. Add a Secure Adapter Encoding
stage to prevent key leakage from adapters
- Implementation:
(a) Apply SVD to the compensated adapter product B̃ k à k = U Lo Σ Lo V Lo T.
(b) Split into restoration keys (K B, K A) (size ∆r) and encrypted adapter weights (B enc, A enc) (size r).
(c) Apply a random orthogonal reparameterization: B final = B enc M, A final = M T A enc, where M is a random r × r orthogonal matrix.
- What the improved system can do: Even if an adversary steals the encrypted adapter, they cannot extract the spectral key or distinguish it from a standard Gaussian-initialized adapter (stealthiness). The orthogonal reparameterization removes the SVD structural fingerprint that would reveal the protection.
4. Add a Training-Free, Data-Independent
protection pipeline
-
Implementation: All operations (TSVD, concatenation, SVD, orthogonal rotation) are performed on post-training weights only—no access to the original training dataset, no retraining, no fine-tuning of the FM.
-
What the improved system can do: The system can be applied to any existing FM (e.g., GPT-2, Llama 3, Stable Diffusion, Sana) within minutes, without needing the original data or compute for retraining. This makes it practical for privacy-sensitive edge deployments where data is unavailable.
5. Add a Low-Overhead Inference
path for authorized users
-
Implementation: During the forward pass, reconstruct the effective weight on-the-fly:
W eff = W̃ + B final A final + K B K A. No need to store the full restored FM in memory. -
What the improved system can do: Authorized inference incurs less than 1% overhead in parameters, FLOPs, and latency (measured on a Galaxy Fold 4: +0.19% params, +0.40% GFLOPs, +0.22% latency). This is suitable for real-time on-device generative AI.
6. Add a Resilience Layer
against adaptive attacks
-
Implementation: The spectral key
Lis never deployed; only the truncated weights and encrypted adapters are on-device. The key is stored in a TEE (Trusted Execution Environment). -
What the improved system can do: The system resists:
-
Fine-tuning attacks: Even with 100k samples, CLIP score remains 0.231 vs. baseline 0.267 (vs. NNSplitter’s 0.251).
-
Spectral DeTuning (SDT): W-Error stays high (around −12 to −15 dB) even with 15 LoRA weights collected, while random-key and self-derived-key baselines fail (W-Error drops to −4 to −6 dB).
-
Model recovery: The Frobenius-norm distance between original and truncated weights is provably maximized (Lemma 1 in the supplement), making reconstruction infeasible.
-
For a model owner: Deploy a protected FM and LoRA adapters to edge devices with no retraining, no data access, and <1% overhead. Only authorized users (with TEE-stored keys) get exact performance; unauthorized users get garbage outputs.
-
For an authorized user: Run the FM with LoRA adapters at full baseline quality (zero degradation in CLIP, LPIPS, perplexity) on a smartphone, with no memory spike.
-
For an adversary: Even with physical memory access, fine-tuning, or state-of-the-art weight-recovery attacks (SDT), the original FM weights are unrecoverable, and the adapter appears indistinguishable from a normal LoRA.
Key technical guarantee: The system provably maximizes the distance between original and truncated weights (via Eckart–Young theorem), ensures exact recovery for authorized users (via spectral compensation), and removes structural fingerprints (via orthogonal reparameterization)—all without any training or data.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs