prinet

Paper · PRINET 0.01

The model is public. The prompt is not.

Measuring prompt recoverability in sharded inference, and closing it with secret-shared activations.

Abstract

Sharding a model across many machines solved the size problem: no single contributor needs to hold a whole model. It did not solve privacy. Every node in a sharded pipeline still handles real activation tensors, and those are enough to reconstruct a prompt.

We measure how much of a prompt an untrusted node can recover under five setups. Undefended inference and open-weight obfuscation both recover 100%. A single share in PRINET's two-party computation recovers 0.21%, against a chance baseline of 0.2%. The bound costs 2.42 MiB per token.

1. The problem

In a sharded network a request passes through a chain of machines, each running a contiguous block of layers. The prompt never has to exist in one place, which is often mistaken for privacy.

promptoutputEntrylayers 0-15exposedNode 2layers 16-31Node 3layers 32-47Exitlayers 48-63exposed
Figure 1. A prompt crosses four nodes, each running 16 layers. Entry and exit are the most exposed.

The activations each node receives are a deterministic function of the prompt and public weights. With the weights in hand, an operator can work backwards to the tokens that produced them.

2. Threat model

We assume an operator who runs their node honestly but records everything it sees, and who has the same public weights the network serves. The question is simple: given one node's view, how much of the prompt comes back?

Recoverability is scored against live model shares in the harness, not estimated. A setup counts as private only if a single node's view recovers no more than chance.

3. Approach

PRINET splits the activations between nodes as secret shares in a two-party computation (2PC). Each node computes on its share; neither holds the real tensor. On its own, one share is noise.

This moves privacy from a policy (“we don't log”) to a property you can measure: what a node can recover from what it actually receives.

4. Results

Prompt recovery from a single node's view, by setup:

SetupKindRecoveredWhy
Hosted APIhosted100%Prompt arrives in plaintext and is logged.
Open weights, locallocal100%Raw activations at every layer.
Open-weight obfuscationopen100%Invertible when the weights are public.
Sharded, multi-nodemulti94–100%Each hop sees real activation tensors.
PRINET, one 2PC share2PC0.21%At chance (0.2%).

Obfuscation fails for a structural reason: if the weights are public, any transform the network applies is one the attacker can apply too. Only splitting the data itself drops recovery to chance.

5. Cost

Privacy is not free. Keeping activations secret-shared adds 2.42 MiB of traffic per token between the parties. That is the price of the bound in Section 4.

6. Limitations

  • Entry and exit see the most. The first and last nodes sit closest to the tokens. That exposure is stated here, not hidden.
  • No product receipt yet. The bound is measured in the harness; there is not yet a per-request proof a user can check.
  • The bound is a gate. A cycle that does not meet it does not count as private.

7. Economics

Inference is metered in $PRINET. Tokens are the billing unit; there is no prompt history and no profile. 30% of every settlement underwrites the research that proves the bound. Nothing is charged on a failed job.