prinet
Docs menuSecret-shared activations

Architecture

Secret-shared activations

Two-party computation: each node computes on a share, never the real tensor.

PRINET passes activations between nodes as secret shares in a two-party computation (2PC). The real activation tensor is split into two shares. Each party computes on its own share, and neither ever holds the real tensor.

One share is noise

A single share on its own carries no usable information about the prompt. Only both shares together lead back to the real values. That is what moves privacy from a policy (“we don't log”) to a property you can measure: what a node can recover from what it actually receives.

Why not obfuscation?

Obfuscating activations with a transform does not help when the weights are public. Any transform the network applies is one an attacker with the weights can apply too, so open-weight obfuscation recovers 100% of the prompt in the measurements. Only splitting the data itself drops recovery to chance.

Cost

Keeping activations secret-shared adds about 2.42 MiB of traffic per token between the parties. That is the price of the privacy bound, and it is published rather than hidden.