Privacy
Threat model
Who we defend against, and how privacy is scored.
PRINET assumes an operator who runs their node honestly but records everything it sees, and who has the same public weights the network serves. The question is simple: given one node's view, how much of the prompt comes back?
How it is scored
Recoverability is scored against live model shares in the test harness, not estimated. The score is the share of prompt tokens an attacker recovers from a single node's view.
The privacy gate
A setup counts as private only if a single node's view recovers no more than chance. The chance baseline is 0.2%. A run that does not meet the bound does not count as private.