Architecture
Secret-shared activations
Two-party computation: each node computes on a share, never the real tensor.
PRINET passes activations between nodes as secret shares in a two-party computation (2PC). The real activation tensor is split into two shares. Each party computes on its own share, and neither ever holds the real tensor.
One share is noise
A single share on its own carries no usable information about the prompt. Only both shares together lead back to the real values. That is what moves privacy from a policy (“we don't log”) to a property you can measure: what a node can recover from what it actually receives.
Why not obfuscation?
Obfuscating activations with a transform does not help when the weights are public. Any transform the network applies is one an attacker with the weights can apply too, so open-weight obfuscation recovers 100% of the prompt in the measurements. Only splitting the data itself drops recovery to chance.
Cost
Keeping activations secret-shared adds about 2.42 MiB of traffic per token between the parties. That is the price of the privacy bound, and it is published rather than hidden.