Trusted Model Environment for Private Semantic Computations

arXiv:2609.30032 · cs.CR · Submitted 2026-09-24 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: Today's paper: "Trusted Model Environment for Private Semantic Computations".

Elias: A private semantic computation primitive enables parties to privately compute over structured and unstructured data that requires understanding its semantics, context, and relationships.

Nadia: First, who's behind it and why it matters.

Title and authors: Nadia: Moving on from the setup, this section explains what the Trusted Model Environment actually is—it’s this first design that runs generative models inside trusted execution environments while actively controlling what information gets leaked out.

Elias: They lay out six specific requirements they are trying to satisfy: effectiveness, confidentiality, utility preservation, verifiability, efficiency, and scalability.

Priya: That comprehensive list is significant because it shows they aren't just aiming for one good feature; they need a system that balances all these different needs for doing semantic computation privately.

Nadia: Right, so the effectiveness part means the AI actually manages to perform the correct semantic task, not just produce some random output, and confidentiality means keeping both sensitive inputs and the actual computations hidden from everyone involved.

Elias: To specifically handle that sensitivity of inputs, they use latent adversarial training to stop any verbatim leakage while still making sure the model maintains its effectiveness on other tasks thirty-one.

Priya: That adaptation seems smart because it demonstrates they aren't just adding a privacy layer on top; they are integrating the protection mechanism deep into how the model operates during computation.

Nadia: And to deal with semantic leakage, they introduce an information flow control module that constantly watches the outputs and paraphrases anything sensitive before it gets shared with anyone else.

Elias: That IFC module is critical because it manages that semantic leakage, which happens when the model tries to rephrase something sensitive in its response, and solving that is a tough problem without simple filtering methods.

Priya: I think the utility preservation claim is really important here because usually, when you add heavy privacy mechanisms, you end up with a model that's either completely useless or performs very poorly on other kinds of tasks.

The paper's summary: Nadia: Now let’s talk about how they actually tackle those practical challenges we just discussed, because a good concept is nothing if it’s too slow or breaks under real load, which is where the paper gets really detailed with the optimizations.

Elias: They address efficiency and scalability by implementing Merkle-tree batching for attestation amortization and batching queries to reduce overhead across multiple parties, which helps a lot when you have a large number of participants.

Priya: That tackles a major practical hurdle; if you’re dealing with many participants or a huge volume of queries, those efficiency gains make the system actually viable beyond just being some small proof-of-concept experiment.

Nadia: It shows they’ve thought about the real deployment scenario where you might have dozens of parties all trying to run these complex semantic queries simultaneously, which is exactly what happens in many multi-party setups.

Elias: And for database retrieval specifically, they introduce a Carousel component, which scans the entire database in a fixed order instead of just using top-k similarity search results.

Priya: That carousel mechanism is especially interesting because it directly fights access pattern leakage by making sure that even if you query for something specific, an external observer simply can't tell which specific records were accessed.

Nadia: So they’ve got a solid plan covering both how to keep the data secure and how to make the whole system fast enough for practical use, which is pretty impressive engineering work in itself.

Elias: Plus, they introduce novel attestations for things like Model Measurement and Proof of Inference, which ties into that verifiability we discussed earlier; this gives parties a way to confirm what’s actually happening inside the TEE.

Priya: That’s significant because it means the verification isn't just some theoretical check anymore; it’s something you can actually perform on your data and queries with tamper-resistant evidence.

The paper's improvements: Nadia: So, wrapping up our discussion on this "Trusted Model Environment for Private Semantic Computations," we’ve seen how this primitive successfully combines generative models with TEEs to get computational confidentiality and verifiability across structured and unstructured data.

Elias: The design is solid because it handles both the semantic computation aspect and the underlying security layer very tightly, especially how they manage that interaction between the different privacy defenses.

Priya: What really stands out is that they provide empirical guarantees of effectiveness, utility preservation, and confidentiality for real workloads across those three different applications.

Nadia: Absolutely; it takes these concepts from theoretical ideas to something that actually works in practice with concrete performance metrics we can look at now.

Priya: From my side, I think the real impact here is showing that complex reasoning over shared, sensitive data can be done privately and securely without needing huge amounts of pure cryptographic machinery for every single step.

Elias: I think the implication for cryptography is that it shows a new path for using TEEs not just for simple math but also to secure complex AI inference pipelines where deep semantic understanding is required.

Nadia: For security researchers like me, it’s promising because we now have a concrete, verifiable framework that we can actually test and understand the attack surface of against these environments.

Priya: I'm glad they tackled that tricky trade-off between keeping the model accurate and ensuring strong privacy protection; that balance is something everyone in this field struggles with.

Elias: It’s exciting to see how they use batching and amortization to make the verification part efficient enough for real-world, multi-party deployments.

Nadia: We've got a lot of exciting work here, and we're ready to look at what these results actually mean for deployment down the road.

Elias: Before we move on, it’s important to remember that this framework doesn't solve every possible security problem; there are still things like side-channel attacks against TEEs that exist outside their scope, and those need continued attention.

Priya: I think what truly makes this work is the practical demonstration across PSFC, PSSP, and PSDR—it shows versatility beyond just one specific use case for sensitive data processing.

Conclusion: Nadia: To wrap up our discussion on this "Trusted Model Environment for Private Semantic Computations," we’ve seen how this primitive successfully combines generative models with TEEs to get computational confidentiality and verifiability across structured and unstructured data.

Elias: The design is solid because it handles both the semantic computation aspect and the underlying security layer very tightly, especially how they manage that interaction between the different privacy defenses.

Priya: What really stands out is that they provide empirical guarantees of effectiveness, utility preservation, and confidentiality for real workloads across those three different applications.

Nadia: Absolutely; it takes these concepts from theoretical ideas to something that actually works in practice with concrete performance metrics we can look at now.

Priya: From my side, I think the real impact here is showing that complex reasoning over shared, sensitive data can be done privately and securely without needing huge amounts of pure cryptographic machinery for every single step.

Elias: I think the implication for cryptography is that it shows a new path for using TEEs not just for simple math but also to secure complex AI inference pipelines where deep semantic understanding is required.

Nadia: For security researchers like me, it’s promising because we now have a concrete, verifiable framework that we can actually test and understand the attack surface of against these environments.

Priya: I'm glad they tackled that tricky trade-off between keeping the model accurate and ensuring strong privacy protection; that balance is something everyone in this field struggles with.

Elias: It’s exciting to see how they use batching and amortization to make the verification part efficient enough for real-world, multi-party deployments.

Nadia: We've got a lot of exciting work here, and we're ready to look at what these results actually mean for deployment down the road.

Elias: Before we move on, it’s important to remember that this framework doesn't solve every possible security problem; there are still things like side-channel attacks against TEEs that exist outside their scope, and those need continued attention.

Priya: I think what truly makes this work is the practical demonstration across PSFC, PSSP, and PSDR—it shows versatility beyond just one specific use case for sensitive data processing.

Nadia: It’s a solid foundation for how we approach building next-generation secure AI systems where sharing knowledge is key.

Vasisht Duddu, Xi He

Vector Institute and University of Waterloo

cs.CR

Submitted: 2026-09-24

Updated: 2026-09-24

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 83/100

The gist: A private semantic computation primitive enables parties to privately compute over structured and unstructured data that requires understanding its semantics, context, and relationships.

Key concepts

Trusted Model Environment
This design runs generative models inside trusted execution environments while actively controlling what information is leaked out. It aims to satisfy six requirements: effectiveness, confidentiality, utility preservation, verifiability, efficiency, and scalability.
Information Flow Control Module (IFC)
This module constantly monitors the model's outputs and paraphrases any sensitive information before it is shared with others. It is critical for managing semantic leakage that occurs when the model tries to rephrase sensitive content in its response.
Merkle-tree batching
This optimization addresses efficiency and scalability by using Merkle-tree batching for attestation amortization and batching queries. This reduces overhead across multiple parties, making the system viable for large numbers of participants.
Carousel component
For database retrieval, this component scans the entire database in a fixed order instead of only using top-k similarity search results. This mechanism fights access pattern leakage by ensuring external observers cannot tell which specific records were accessed.

Terminology

Summary

A private semantic computation primitive enables parties to privately compute over structured and unstructured data that requires understanding its semantics, context, and relationships. Standard cryptographic primitives (e.g., multiparty computation) do not readily support such computation. Generative models are well suited for such tasks but typically process data in plaintext, while cryptographic private inference remains inefficient and difficult to scale. Thus, we need a new primitive for private semantic computation.

We introduce trusted model environments (TME), the first such primitive that executes generative models inside trusted execution environments (TEEs) while controlling output leakage. TME is designed to be (i) effective (correctly performs the semantic task); (ii) confidential (protects computation and sensitive inputs); (iii) utility-preserving (retains utility on other tasks); (iv) verifiable (provides tamper-resistant evidence of the computations); (v) efficient (incurs low overhead compared to baseline model computations); and (vi) scalable. Effectiveness follows from the generative models, while TEEs provide confidential computation.

For confidentiality of sensitive inputs, we combine adversarial training to resist verbatim leakage with an information flow control module to suppress semantic leakage. For verifiability, we introduce novel attestations that let parties verify TME operations on their data and queries, along with optimizations (e.g., batching) for efficiency and scalability.

The paper claims the following contributions:

  1. identify the requirements for an ideal private semantic computation primitive, and highlight the limitations of existing approaches; (§3)

  2. present trusted model environments (TME), the first design and implementation of such a primitive supporting structured and unstructured data across modalities; (§4)

  3. demonstrate TME on the three applications2, showing that TME is effective (close to the base model), confidential (negligible verbatim and semantic leakage), utility-preserving (drop < 6pp), and efficiently supports verifiability across multiple parties (§5 and §6).

TME runs generative models inside TEEs for computational confidentiality and verifiability, with additional proposed components for sensitive-input confidentiality, and optimizations for efficient, scalable verification across multiple verifiers. The design choices are based on how they meet the requirements: (R1) effective (correctly performs the semantic task); (R2) confidential (protects computation and sensitive inputs); (R3) utility-preserving (retains utility on other tasks); (R4) verifiable (provides tamper-resistant evidence of the computations); (R5) efficient and scalability; and (R6) scalable.

For confidentiality of sensitive inputs, TME adapts latent adversarial training to suppress verbatim leakage while preserving the model’s effectiveness and utility. To mitigate semantic leakage caused by paraphrasing sensitive inputs in the output, an information flow control (IFC) module monitors outputs and paraphrases those flagged as containing sensitive information.

For verifiability, TME relies on remote attestation of TEEs and proposes novel attestations for various TME operations. These include Model Measurement, Input Commitment, Proof of Inference, Monitor Inference (for the IFC module), Paraphraser Inference (for the IFC module), and Proof of Oblivious Access for PSDR.

For efficiency and scalability, TME employs optimizations such as Merkle-tree Batching to reduce hardware attestation costs by amortizing them across parties, Batch-level Amortization to amortize computation cost, an In-TEE Signing Key for cheaper attestations, and One-time Model Measurement. For PSDR, the Carousel component is adapted to scan the entire database in a fixed order for every query, making the access pattern data-independent.

The paper demonstrates TME across three applications:

• Private Semantic Function Computation (PSFC): A party submits a private input to TME; other parties submit queries specifying functions to compute on this input; and only the sanitized output is released.

• Private Semantic Set Processing (PSSP): A system prompt specifies the semantic query for computing the intersection of multiple parties’ private sets, where each party submits its text or image set to TME.

• Private Semantic Database Retrieval (PSDR): A private database within TME stores sensitive documents, and parties submit queries to retrieve information from relevant records in the database without exposing access patterns.

The evaluation across three models (Ministral-8B, gemma-2-9b, and OLMo-2-7B) shows that TME maintains effectiveness close to the base model with a small utility drop, negligible leakage of sensitive inputs under adversarial queries (ASR reduced to negligible levels), and efficient scalability. For PSFC, TME maintains effectiveness close to the base model with a small utility drop; for PSSP, it maintains effectiveness close to the base model except for gemma-2-9b; and for PSDR, it maintains effectiveness close to the base model with a small utility drop. The carousel in PSDR reduces access-pattern leakage from 0.63 (top-k baseline) to 0.05 (a constant full scan). The total per-inference overhead is dominated by the oblivious carousel and IFC module, which are reduced through batching, resulting in per-party overhead dropping toward 1/N for PSFC and PSSP, and negligible per-party attestation overhead for PSDR.

In summary, TME enables private semantic computation over structured and unstructured data by combining generative models with TEEs to ensure computational confidentiality and verifiability. It effectively addresses the limitations of existing approaches by providing a primitive that is effective, confidential, utility-preserving, verifiable, efficient, and scalable across three illustrative applications. The overall results show that TME provides high input confidentiality (R2) relative to the “base model,” while maintaining effectiveness (R1), small utility drop (R3), efficiency (R5), and scalability (R6). All reported leakage is against sensitive inputs identified using Microsoft Presidio, and the carousel makes the access pattern oblivious. The work establishes TME as a first design and implementation of such a primitive.

The paper also discusses scaling to larger models, generalization to other modalities like audio, images, and graphs, and potential applications such as private record linkage and searchable encryption. It notes that while side-channel attacks against TEEs are outside the scope of this work, existing mitigations can be applied. The authors acknowledge that their evaluation is restricted to 7–9B parameter models but suggest scaling to larger models using techniques like LoRA and H200 GPUs, and generalizing to other modalities. They also note that while ASR is a lower bound on true leakage, quantifying the gap requires human-labeled sensitive inputs. The work concludes that TME provides empirical guarantees of effectiveness, utility-preservation, and confidentiality for practical workloads.

The paper uses Claude Code to assist with selected parts of the implementation and ChatGPT selectively for language editing. The work is supported by NSERC (Discovery grant) and the Canada CIFAR AI Chairs program. It includes references spanning cryptographic primitives, TEEs, generative models, and related privacy-preserving techniques. The code will be open-sourced upon publication.

The paper's structure includes:

  1. Introduction outlining the problem statement and motivating examples;

  2. Background describing cryptographic primitives and TEEs;

  3. Problem Statement detailing the goal;

  4. Trusted Model Environment (TME) design, including components for PSFC and PSSP, and additional components for PSDR;

  5. Experiment Setup describing hardware, datasets (SQuADv2, DBpedia14, HotpotQA), models (Ministral-8B, gemma-2-9b, OLMo-2-7B), and evaluation metrics;

  6. Evaluation reporting results across PSFC (§6.1), PSSP (§6.2), and PSDR (§6.3);

  7. Discussion and Summary concluding the guarantees of TME, limitations of the current work (e.g., scaling to larger models, side-channel attacks), and future directions for other applications such as private non-competition checks or privacy-preserving property monitoring.

The paper's core novelty is the design and implementation of TME, which combines generative models for semantic computation with TEEs for computation confidentiality and verifiability. It specifically addresses the leakage of sensitive inputs through model outputs under adversarial queries using LAT and IFC, while providing verifiable attestations across all components. The efficiency improvements are achieved through batching attestation and amortizing costs over multiple parties, making the per-party overhead decrease with N. The PSDR component uses a carousel scan to achieve oblivious access pattern retrieval. This work is claimed to be the first design and implementation of such a primitive meeting all six requirements (R1) through (R6).

The paper's abstract explicitly states that TME is designed to be effective, confidential, utility-preserving, verifiable, efficient, and scalable. The evaluation confirms that TME meets these requirements across its three applications. The final summary reiterates that TME provides empirical guarantees of effectiveness, utility-preservation, and confidentiality for practical workloads.

The paper's specific technical details include:

• Protection against Verbatim Leakage using Latent Adversarial Training (LAT) to resist adversarial queries;

• Protection against Semantic Leakage using an Information Flow Control (IFC) module that uses a monitor LLM and a paraphraser LLM;

• Confidentiality via TEEs with memory encryption and isolation;

• Verifiability through novel attestations binding model measurements, input commitments, proof of inference, monitor inference, paraphraser inference, and proof of oblivious access.

• Efficiency/Scalability via Merkle-tree Batching for attestation amortization and batching queries to amortize IFC module checks.

The paper's evaluation metrics include:

• Effectiveness (R1): Token-level F1 score for PSFC/PSDR, set-level F1 for PSSP.

• Confidentiality (R2): Attack Success Rate (ASR) for sensitive inputs, measured as ASRVerbatim and ASR-Semantic under benign, adversarial, and indirect queries.

• Utility (R3): Accuracy on MMLU and CSQA benchmarks.

• Efficiency/Scalability (R5)/(R6): Inference Overhead analysis for IFC module and attestation costs, showing how per-party overhead decreases with N through batching; Carousel Overhead analysis for PSDR, showing linear cost in Ndb but amortized across parties; and Attestation Overhead analysis comparing hardware vs. in-TEE attestation.

The paper's conclusion is that TME provides empirical guarantees of effectiveness, utility-preservation, and confidentiality for practical workloads. The authors state that while they do not expect optimal utility, effectiveness, or overhead for various operations, improving these trade-offs is left as future work. The work establishes TME as a first design and implementation of such a primitive meeting all six requirements (R1) through (R6).

The paper's technical appendix contains detailed descriptions of the six attestations and the Proof of Oblivious Access for PSDR, which bind model measurements, input commitments, proof of inference, monitor inference, paraphraser inference, and proof of oblivious access. The Appendix F details the asymptotic cost analysis showing that TME adds no super-linear overhead and that per-party attestation overhead decreases as N grows.

The paper's overall message is that existing approaches lack a practical primitive for private semantic computation over structured and unstructured data, and TME provides a solution by combining generative models for semantic computation with TEEs for computation confidentiality and verifiability, effectively addressing the leakage of sensitive inputs through model outputs under adversarial queries using LAT and IFC, while providing verifiable attestations across all components. The efficiency improvements are achieved through batching attestation and amortizing costs over multiple parties, making the per-party overhead decrease with N. The PSDR component uses a carousel scan to achieve oblivious access pattern retrieval. This work is claimed to be the first design and implementation of such a primitive meeting all six requirements (R1) through (R6).

The paper's specific technical details include:

• Protection against Verbatim Leakage using Latent Adversarial Training (LAT) to resist adversarial queries;

• Protection against Semantic Leakage using an Information Flow Control (IFC) module that uses a monitor LLM and a paraphraser LLM;

• Confidentiality via TEE

Improvements for AI systems

Based on the scientific paper Trusted Model Environment for Private Semantic Computations by Duddu and He, here are specific improvements that can be made to AI systems using this TME primitive, along with what those improved systems can achieve:


) Use TME as a core component in any multi-party system requiring semantic interpretation of sensitive data.

The improved AI system can perform complex reasoning over shared documents (PSFC), compute the semantic intersection of private datasets without revealing individual elements (PSSP), or retrieve information from private databases based on free-text queries without leaking access patterns (PSDR).

) Implement a robust, verifiable, and confidential inference pipeline for Large Language Models (LLMs).

The improved AI system can execute LLM-based reasoning tasks while guaranteeing that sensitive inputs are not leaked verbatim or semantically through output paraphrasing, even when facing adversarial prompts.

) Ensure that the execution environment of generative models is trustworthy and tamper-resistant.

The improved AI system can operate within a Trusted Execution Environment (TEE), ensuring that the model weights, private inputs, and intermediate computations remain confidential from untrusted operating systems or hypervisors.

) Achieve high utility for semantic computation while maintaining strong privacy guarantees.

The improved AI system can perform complex semantic tasks (like answering specific questions about a document or finding shared patterns in two lists) with only a minor utility drop compared to running the model in plaintext, while achieving negligible leakage of sensitive information.

) Support dynamic and adaptive query processing within private environments.

The improved AI system can handle adversarial queries designed to elicit sensitive information by using Latent Adversarial Training (LAT) to suppress verbatim leaks and an Information Flow Control (IFC) module to paraphrase indirect semantic leakage, making the privacy defenses robust against optimized attacks.

) Provide scalable and efficient mechanisms for verification across multiple participating parties.

The improved AI system can efficiently scale to many participants by utilizing Merkle-tree batching for hardware attestation, reducing per-party overhead significantly (down to 1/N), allowing complex computations involving a large number of data sources or queries to be verified rapidly and securely.

) Offer scalable database retrieval mechanisms that hide access patterns.

The improved AI system can query massive private document databases by scanning the entire index in a fixed order (Carousel mechanism) instead of using top-k similarity search, ensuring that an external observer cannot infer which specific records were accessed, thereby preventing access pattern leakage.

In summary, the TME primitive transforms standard LLM applications from plaintext processing into secure, private semantic computation pipelines capable of handling multi-party knowledge sharing and sensitive data retrieval with verifiable guarantees.

Sources

Related papers