# LLM Encryption & Privacy Approaches

## Overview

This article summarises the current approaches to protecting prompt/dialog privacy when using LLMs, plus a proposed approach inspired by the Navajo code talkers (WWII).

## Current Approaches

| Approach | How it works | Provider can see content? | Production ready? | Cost |
|----------|-------------|--------------------------|-------------------|------|
| **Standard API (TLS only)** | TLS encrypts data in transit. Provider decrypts for inference. | ✅ Yes | ✅ Yes | Low |
| **TEE (Trusted Execution Environment)** | Hardware-level encrypted memory (Intel SGX / AMD SEV). RAM is encrypted; decryption only inside CPU. | ❌ No (hardware isolated) | ✅ Azure OpenAI, Google Vertex AI | ~2-3x |
| **Local model (self-hosted)** | Run model on your own hardware. Data never leaves your machine. | ❌ No | ✅ Ollama, vLLM, llama.cpp | Hardware cost |
| **Homomorphic Encryption** | Mathematical encryption allowing computation on encrypted data without decryption. | ❌ No | ❌ Research only (1000-10000x slower) | N/A |

### TEE — How it works

```
Prompt (encrypted) → TLS → Provider (encrypted)
  → TEE (CPU encrypted enclave)
    → Decrypt inside TEE → Inference → Encrypt inside TEE
  → TEE (encrypted output)
→ Provider (encrypted) → TLS → You (decrypt)
```

Physical RAM dumping reads encrypted garbage. The decryption key exists only inside the CPU die.

### TEE — The GPU gap

LLM inference (7B+ models) requires GPU. **NVIDIA GPUs do not support TEE.** When data moves from CPU TEE to GPU VRAM for matrix multiplication, it is decrypted in VRAM (plaintext). This is the current weakest point in TEE-based LLM inference.

## Proposed Approach: Private Encoding (Navajo Code Talker Method)

Inspired by the WWII Navajo code talkers — using a language known only to a small group, resisting all frequency analysis and cryptanalysis.

### How it works

1. **Invent a private encoding scheme.** A deterministic mapping from natural language tokens to ciphertext tokens. This mapping is known only to you and your group.
2. **Transform the entire training dataset.** All plaintext → encoded text using the private mapping.
3. **Train an LLM from scratch** on this encoded dataset. The model learns the statistical structure of the encoding, not the underlying natural language.
4. **Inference is in the encoded domain.** You encode your prompt, send it to the model, receive encoded output, decode it yourself.

```
You: Encode("What is the capital of France?") → "Zx7 Qm3 ..."
Model: "1B8D ..." (inference in encoded space)
You: Decode("1B8D ...") → "Paris"
```

### Security properties

| Threat | Protection |
|--------|-----------|
| Provider sees prompt | Encoded text only — no mapping exists to decode |
| Provider steals model weights | Useless without the decoding key |
| Frequency analysis | Encoding scheme designed to be uncorrelated with any natural language |
| Man-in-the-middle | Encoded text meaningless without key |

### Comparison with other approaches

| | TEE | Homomorphic Encryption | Private Encoding |
|--|-----|----------------------|-----------------|
| Security layer | Hardware isolation | Mathematics | Private knowledge |
| Inference speed | ~10-20% overhead | ~1000x slower | Normal speed |
| GPU support | ❌ Gap exists | ❌ Not practical | ✅ Works |
| Training cost | Pre-trained model | N/A | Must train from scratch |
| Key management | Provider manages | Mathematical | You manage |
| Historical precedent | Modern tech | Research | ✅ WWII Navajo code talkers |

### Practical considerations

- **Requires training from scratch.** Pre-trained models cannot be used because they don't know the encoding.
- **Training cost.** Depending on model size, this is the main barrier.
- **Proof of concept.** No known implementation exists for LLMs. The concept is validated by the Navajo code talker precedent, but has not been built at LLM scale.

## Conclusion

| If you want... | Use... |
|---------------|--------|
| Convenience + low cost | Standard API (TLS) |
| Strong privacy + willing to pay | Azure TEE / Google Vertex AI |
| Maximum security + tech capable | Local model (self-hosted) |
| Ultimate privacy + willing to train | Private encoding (proposed approach) |

The private encoding approach is a valid concept, validated by historical precedent. Its feasibility depends on whether the training cost is justified by the required level of privacy.