{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T04:47:00Z","timestamp":1782535620665,"version":"3.54.5"},"reference-count":195,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000001","name":"U.S. National Science Foundation","doi-asserted-by":"crossref","award":["CNS-2231519"],"award-info":[{"award-number":["CNS-2231519"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100000001","name":"U.S. National Science Foundation","doi-asserted-by":"crossref","award":["DUE-2225229"],"award-info":[{"award-number":["DUE-2225229"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]},{"award":["CNS-2231519"],"award-info":[{"award-number":["CNS-2231519"]}],"id":[{"id":"https:\/\/ror.org\/021nxhr62","id-type":"ROR","asserted-by":"publisher"}]},{"award":["DUE-2225229"],"award-info":[{"award-number":["DUE-2225229"]}],"id":[{"id":"https:\/\/ror.org\/021nxhr62","id-type":"ROR","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>LLM privacy risks arise across different lifecycle stages and architectural boundaries, and existing protection mechanisms provide only partial coverage. This paper analyzes the main families of privacy-preserving approaches for LLM systems through a two-axis structure that crosses lifecycle stages with system architecture layers. Some safeguards are operationally mature; others, such as confidential computing, have moved into production practice; stronger cryptographic methods, while most promising in principle, remain research-heavy in practice. No single mechanism provides complete end-to-end protection: different methods protect different assets, operate at different lifecycle stages, span distinct system layers, and carry distinct trust, performance, and deployment trade-offs. Practical LLM privacy is therefore a problem of layered system design rather than the search for a universal primitive, and hybrid architectures are emerging as the most realistic deployable pattern. Building on this analysis, we propose a six-dimensional evaluation framework for privacy in hybrid LLM deployments (a 0\u20135 ordinal scoring rubric designed for reproducible application, with explicit anchor language and per-score evidence requirements) and apply it to five representative confidential AI deployments, deriving the scores in full for two of them. The framework feeds a three-tier gap-closure roadmap and design principles for architecture-time use, connecting what privacy technologies promise, what they actually protect, and what is realistically deployable in modern LLM systems.<\/jats:p>","DOI":"10.3390\/a19060500","type":"journal-article","created":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T03:09:17Z","timestamp":1782270557000},"page":"500","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A System-Level Framework for Evaluating Privacy in Hybrid LLM Deployments"],"prefix":"10.3390","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-8502-0319","authenticated-orcid":false,"given":"Shuwen","family":"Liang","sequence":"first","affiliation":[{"name":"Independent Researcher, Kirkland, WA 98033, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9588-3181","authenticated-orcid":false,"given":"Zhi","family":"Qiao","sequence":"additional","affiliation":[{"name":"Microsoft Corporation, Redmond, WA 98052, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0954-0667","authenticated-orcid":false,"given":"Tianyu","family":"Bai","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of North Texas, Denton, TX 76203, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-6456-4997","authenticated-orcid":false,"given":"Ying","family":"He","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of North Texas, Denton, TX 76203, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6238-7529","authenticated-orcid":false,"given":"Dong\u2019er","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of North Texas, Denton, TX 76203, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7705-0829","authenticated-orcid":false,"given":"Song","family":"Fu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of North Texas, Denton, TX 76203, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"ref_1","unstructured":"Zhao, W.X., Zhou, K., Li, J., Tang, T., Wang, X., Hou, Y., Min, Y., Zhang, B., Zhang, J., and Dong, Z. (2023). A Survey of Large Language Models. arXiv."},{"key":"ref_2","unstructured":"Google Cloud (2026, March 26). Generative AI on Vertex AI. Available online: https:\/\/docs.cloud.google.com\/docs\/generative-ai."},{"key":"ref_3","unstructured":"Google Cloud (2026, March 26). Gemini Code Assist Standard and Enterprise Overview. Available online: https:\/\/docs.cloud.google.com\/gemini\/docs\/codeassist\/overview."},{"key":"ref_4","unstructured":"OpenAI (2026, March 26). Reasoning Models. Available online: https:\/\/developers.openai.com\/api\/docs\/guides\/reasoning\/."},{"key":"ref_5","unstructured":"Mei, L., Yao, J., Ge, Y., Wang, Y., Bi, B., Cai, Y., Liu, J., Li, M., Li, Z.Z., and Zhang, D. (2025). A Survey of Context Engineering for Large Language Models. arXiv."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1007\/s44336-025-00024-x","article-title":"Tool learning with language models: A comprehensive survey of methods, pipelines, and benchmarks","volume":"2","author":"Chen","year":"2025","journal-title":"Vicinagearth"},{"key":"ref_7","unstructured":"Miranda, M., Ruzzetti, E.S., Santilli, A., Zanzotto, F.M., Brati\u00e8res, S., and Rodol\u00e0, E. (2026, March 21). Preserving Privacy in Large Language Models: A Survey on Current Threats and Solutions. Transactions on Machine Learning Research, Available online: https:\/\/openreview.net\/forum?id=Ss9MTTN7OL."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"100211","DOI":"10.1016\/j.hcc.2024.100211","article-title":"A Survey on Large Language Model (LLM) Security and Privacy: The Good, the Bad, and the Ugly","volume":"4","author":"Yao","year":"2024","journal-title":"High Confid. Comput."},{"key":"ref_9","unstructured":"Pan, J.J., and Li, G. (2025). A Survey of LLM Inference Systems. arXiv."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Chrapek, M., Copik, M., Mettaz, E., and Hoefler, T. (2025). Confidential LLM Inference: Performance and Cost Across CPU and GPU TEEs. arXiv.","DOI":"10.1109\/IISWC66894.2025.00017"},{"key":"ref_11","unstructured":"Neel, S., and Chang, P. (2024). Privacy Issues in Large Language Models: A Survey. arXiv."},{"key":"ref_12","unstructured":"Google (2026, April 29). Private AI Compute: Our Next Step in Building Private and Helpful AI. Available online: https:\/\/blog.google\/innovation-and-ai\/products\/google-private-ai-compute\/."},{"key":"ref_13","unstructured":"(2018). The Transport Layer Security (TLS) Protocol Version 1.3 (Standard No. RFC8446)."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"McKay, K.A., and Cooper, D.A. (2019). Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations, NIST Special Publication 800-52 Revision 2.","DOI":"10.6028\/NIST.SP.800-52r2"},{"key":"ref_15","unstructured":"Joint Task Force (2020). Security and Privacy Controls for Information Systems and Organizations, NIST Special Publication 800-53 Revision 5."},{"key":"ref_16","unstructured":"OpenAI (2026, March 21). Business Data Privacy, Security, and Compliance. Available online: https:\/\/openai.com\/business-data\/."},{"key":"ref_17","unstructured":"Microsoft (2026, March 21). Data, Privacy, and Security for Azure Direct Models in Microsoft Foundry. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/foundry\/responsible-ai\/openai\/data-privacy."},{"key":"ref_18","unstructured":"Google Cloud (2026, March 21). Vertex AI and Zero Data Retention. Available online: https:\/\/docs.cloud.google.com\/vertex-ai\/generative-ai\/docs\/vertex-ai-zero-data-retention."},{"key":"ref_19","unstructured":"Amazon Web Services (2026, March 21). Amazon Bedrock FAQs. Available online: https:\/\/aws.amazon.com\/bedrock\/faqs\/."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Scarfone, K., and Souppaya, M. (2007). Guide to Storage Encryption Technologies for End User Devices, NIST Special Publication 800-111.","DOI":"10.6028\/NIST.SP.800-111"},{"key":"ref_21","unstructured":"OpenAI (2026, March 21). Data Controls in the OpenAI Platform. Available online: https:\/\/developers.openai.com\/api\/docs\/guides\/your-data."},{"key":"ref_22","unstructured":"Das, B.C., Amini, M.H., and Wu, Y. (2024). Security and Privacy Challenges of Large Language Models: A Survey. arXiv."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Liang, S., Qiao, Z., Tang, S., Hochstetler, J., Fu, S., Shi, W., and Chen, H.-B. (2019, January 9\u201312). An Empirical Study of Quad-Level Cell (QLC) NAND Flash SSDs for Big Data Applications. Proceedings of the IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA.","DOI":"10.1109\/BigData47090.2019.9006406"},{"key":"ref_24","unstructured":"Li, H., Chen, Y., Luo, J., Wang, J., Peng, H., Kang, Y., Zhang, X., Hu, Q., Chan, C., and Xu, Z. (2024). Privacy in Large Language Models: Attacks, Defenses and Future Directions. arXiv."},{"key":"ref_25","unstructured":"Asthana, S., Zhang, B., Mahindru, R., DeLuca, C., Gentile, A.L., and Gopisetty, S. (2025). Deploying Privacy Guardrails for LLMs: A Comparative Analysis of Real-World Applications. arXiv."},{"key":"ref_26","unstructured":"Confidential Computing Consortium (2026, March 23). Confidential Computing: Hardware-Based Trusted Execution for Protecting Data in Use. Available online: https:\/\/confidentialcomputing.io\/wp-content\/uploads\/sites\/85\/2022\/06\/CCC_Confidential_Computing_Whitepaper.pdf."},{"key":"ref_27","unstructured":"Bara\u0144ski, S. (2024). A Survey on Privacy-Preserving Machine Learning Inference. TASK Q., 28."},{"key":"ref_28","unstructured":"Google Cloud (2026, March 23). Confidential Computing Overview. Available online: https:\/\/docs.cloud.google.com\/confidential-computing\/docs\/confidential-computing-overview."},{"key":"ref_29","unstructured":"NVIDIA (2026, March 23). Confidential Compute on NVIDIA Hopper H100. Available online: https:\/\/images.nvidia.com\/aem-dam\/en-zz\/Solutions\/data-center\/HCC-Whitepaper-v1.0.pdf."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Bartock, M., Souppaya, M., Savino, R., Knoll, T., Shetty, U., Cherfaoui, M., Yeluri, R., Malhotra, A., Banks, D., and Jordan, M. (2026, March 23). Hardware-Enabled Security: Enabling a Layered Approach to Platform Security for Cloud and Edge Computing Use Cases, Available online: https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2022\/NIST.IR.8320.pdf.","DOI":"10.6028\/NIST.IR.8320"},{"key":"ref_31","unstructured":"Baumann, A., Peinado, M., and Hunt, G. (2014, January 6\u20138). Shielding Applications from an Untrusted Cloud with Haven. Proceedings of the 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI \u201914), Broomfield, CO, USA."},{"key":"ref_32","unstructured":"Costan, V., and Devadas, S. (2026, March 23). Intel SGX Explained. Available online: https:\/\/eprint.iacr.org\/2016\/086.pdf."},{"key":"ref_33","unstructured":"Intel (2026, June 15). Intel Trust Domain Extensions (Intel TDX). Available online: https:\/\/cdrdv2-public.intel.com\/690419\/TDX-Whitepaper-February2022.pdf."},{"key":"ref_34","unstructured":"Advanced Micro Devices (2026, March 23). SEV-SNP: Strengthening VM Isolation with Integrity Protection and More. Available online: https:\/\/www.amd.com\/system\/files\/TechDocs\/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Xu, Y., Cui, W., and Peinado, M. (2015, January 18\u201320). Controlled-Channel Attacks: Deterministic Side Channels for Untrusted Operating Systems. Proceedings of the 2015 IEEE Symposium on Security and Privacy, San Jose, CA USA.","DOI":"10.1109\/SP.2015.45"},{"key":"ref_36","unstructured":"Bulck, J.V., Minkin, M., Weisse, O., Genkin, D., Kasikci, B., Piessens, F., Silberstein, M., Wenisch, T.F., Yarom, Y., and Strackx, R. (2018, January 15\u201317). Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. Proceedings of the 27th USENIX Security Symposium, Baltimore, MD, USA."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"281","DOI":"10.1145\/3670007","article-title":"Machine Learning with Confidential Computing: A Systematization of Knowledge","volume":"56","author":"Mo","year":"2024","journal-title":"ACM Comput. Surv."},{"key":"ref_38","unstructured":"Microsoft Azure (2026, March 23). About Azure Confidential VMs. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/confidential-vm-overview."},{"key":"ref_39","unstructured":"Microsoft Azure (2026, March 23). Confidential VM Guest Attestation Design Detail. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/guest-attestation-confidential-virtual-machines-design."},{"key":"ref_40","unstructured":"Google Cloud (2026, March 23). Confidential VM Overview. Available online: https:\/\/docs.cloud.google.com\/confidential-computing\/confidential-vm\/docs\/confidential-vm-overview."},{"key":"ref_41","unstructured":"Amazon Web Services (2026, March 23). AMD SEV-SNP for Amazon EC2 Instances. Available online: https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/sev-snp.html."},{"key":"ref_42","unstructured":"Amazon Web Services (2026, March 23). Attest an Amazon EC2 Instance with AMD SEV-SNP. Available online: https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/snp-attestation.html."},{"key":"ref_43","unstructured":"Amazon Web Services (2026, May 28). How to Make Attested Calls to AWS KMS. Available online: https:\/\/docs.aws.amazon.com\/kms\/latest\/developerguide\/attested-calls.html."},{"key":"ref_44","unstructured":"Apple Security Engineering and Architecture (SEAR), User Privacy, Core Operating Systems (Core OS), Services Engineering (ASE), and Machine Learning and AI (AIML) (2026, April 29). Private Cloud Compute: A New Frontier for AI Privacy in the Cloud. Available online: https:\/\/security.apple.com\/blog\/private-cloud-compute\/."},{"key":"ref_45","unstructured":"NVIDIA (2026, March 23). Announcing NVIDIA Secure AI General Availability. Available online: https:\/\/developer.nvidia.com\/blog\/announcing-nvidia-secure-ai-general-availability\/."},{"key":"ref_46","unstructured":"NVIDIA (2026, May 28). NVIDIA Vera Rubin Platform: Rack-Scale Confidential Computing. Available online: https:\/\/www.nvidia.com\/en-us\/data-center\/technologies\/rubin\/."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Gentry, C. (2009). A Fully Homomorphic Encryption Scheme. [Ph.D. Thesis, Stanford University].","DOI":"10.1145\/1536414.1536440"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Yao, A.C.C. (1986, January 27\u201329). How to Generate and Exchange Secrets. Proceedings of the IEEE Symposium on Foundations of Computer Science (FOCS), Toronto, ON, Canada.","DOI":"10.1109\/SFCS.1986.25"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Mohassel, P., and Zhang, Y. (2017, January 22\u201326). SecureML: A System for Scalable Privacy-Preserving Machine Learning. Proceedings of the 2017 IEEE Symposium on Security and Privacy (S&P), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.12"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Rathee, D., Rathee, M., Goli, R.K.K., Gupta, D., Sharma, R., Chandran, N., and Rastogi, A. (2021, January 24\u201327). SiRNN: A Math Library for Secure RNN Inference. Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP), Virtual.","DOI":"10.1109\/SP40001.2021.00086"},{"key":"ref_51","unstructured":"Li, Y., Zhou, X., Wang, Y., Qian, L., and Zhao, J. (2024). A Survey on Private Transformer Inference. arXiv."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"103555","DOI":"10.1016\/j.sysarc.2025.103555","article-title":"Safeguarding User Data Privacy in Online Large Language Model Services","volume":"168","author":"Bai","year":"2025","journal-title":"J. Syst. Archit."},{"key":"ref_53","unstructured":"Albrecht, M., Chase, M., Chen, H., Ding, J., Goldwasser, S., Gorbunov, S., Halevi, S., Hoffstein, J., Laine, K., and Lauter, K. (2026, April 29). Homomorphic Encryption Standard. Version 1.1. Available online: https:\/\/homomorphicencryption.org\/wp-content\/uploads\/2024\/08\/Homomorphic-Encryption-Standard-v1.1.pdf."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Goldreich, O., Micali, S., and Wigderson, A. (2019). How to play any mental game, or a completeness theorem for protocols with honest majority. Providing Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali, Association for Computing Machinery.","DOI":"10.1145\/3335741.3335759"},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1145\/3387108","article-title":"Secure Multiparty Computation","volume":"64","author":"Lindell","year":"2020","journal-title":"Commun. ACM"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"139","DOI":"10.2478\/popets-2021-0064","article-title":"SoK: Privacy-Preserving Computation Techniques for Deep Learning","volume":"2021","author":"Pastrana","year":"2021","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Cheon, J.H., Kim, A., Kim, M., and Song, Y. (2017, January 3\u20137). Homomorphic Encryption for Arithmetic of Approximate Numbers. Proceedings of the ASIACRYPT 2017, Hong Kong, China.","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"ref_58","unstructured":"Dowlin, N., Gilad-Bachrach, R., Laine, K., Lauter, K., Naehrig, M., and Wernsing, J. (2016, January 19\u201324). CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy. Proceedings of the 33rd International Conference on International Conference on Machine Learning\u2014ICML\u201916, New York, NY, USA."},{"key":"ref_59","unstructured":"Ran, R., Luo, X., Wang, W., Liu, T., Quan, G., Xu, X., Ding, C., and Wen, W. (2023, January 23\u201329). SpENCNN: Orchestrating Encoding and Sparsity for Fast Homomorphically Encrypted Neural Network Inference. Proceedings of the 40th International Conference on Machine Learning (PMLR), Honolulu, HI, USA."},{"key":"ref_60","unstructured":"Bassit, A., and Boddeti, V. (2025, January 6). SecureRAG: End-to-End Secure Retrieval-Augmented Generation. Proceedings of the GenAI4Health 2025 Poster, San Diego, CA USA."},{"key":"ref_61","first-page":"26","article-title":"SecureNN: 3-Party Secure Computation for Neural Network Training and Inference","volume":"2019","author":"Wagh","year":"2019","journal-title":"Proc. Priv. Enhancing Technol. PoPETs"},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Rathee, D., Rathee, M., Kumar, N., Chandran, N., Gupta, D., Rastogi, A., and Sharma, R. (2020, January 9\u201313). CrypTFlow2: Practical 2-Party Secure Inference. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA.","DOI":"10.1145\/3372297.3417274"},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H.B., Patel, S., Ramage, D., Segal, A., and Seth, K. (November, January 30). Practical Secure Aggregation for Privacy-Preserving Machine Learning. Proceedings of the CCS 2017, New York, NY, USA.","DOI":"10.1145\/3133956.3133982"},{"key":"ref_64","unstructured":"Amazon Web Services (2026, April 29). AWS Clean Rooms. Available online: https:\/\/aws.amazon.com\/clean-rooms\/."},{"key":"ref_65","unstructured":"McMahan, H.B., Moore, E., Ramage, D., Hampson, S., and y Arcas, B.A. (2017, January 20\u201322). Communication-Efficient Learning of Deep Networks from Decentralized Data. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS, Fort Lauderdale, FL, USA."},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006, January 4\u20137). Calibrating Noise to Sensitivity in Private Data Analysis. Proceedings of the Theory of Cryptography Conference (TCC), Berlin\/Heidelberg, Germany.","DOI":"10.1007\/11681878_14"},{"key":"ref_67","unstructured":"Carlini, N., Tram\u00e8r, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., and Erlingsson, U. (2021). Extracting Training Data from Large Language Models. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), USENIX Association."},{"key":"ref_68","doi-asserted-by":"crossref","first-page":"12:1","DOI":"10.1145\/3298981","article-title":"Federated Machine Learning: Concept and Applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Trans. Intell. Syst. Technol."},{"key":"ref_69","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1038\/s41746-020-00323-1","article-title":"The future of digital health with federated learning","volume":"3","author":"Rieke","year":"2020","journal-title":"npj Digit. Med."},{"key":"ref_70","doi-asserted-by":"crossref","unstructured":"Byrd, D., and Polychroniadou, A. (2020, January 15\u201316). Differentially Private Secure Multi-Party Computation for Federated Learning in Financial Applications. Proceedings of the First ACM International Conference on AI in Finance (ICAIF \u201920), New York, NY, USA.","DOI":"10.1145\/3383455.3422562"},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"Mim, S.S., Logofatu, D., Guerrero-Contreras, G., and Medina-Bulo, I. (2025). Privacy-Preserving Federated Learning for Finance: Challenges, Benchmarks, and Strategic Recommendations. Proceedings of the 2025 International Conference on Innovations in Intelligent Systems and Applications (INISTA), IEEE.","DOI":"10.1109\/INISTA68122.2025.11249513"},{"key":"ref_72","unstructured":"Zhang, Z., Hu, X., Zhang, J., Zhang, Y., Wang, H., Qu, L., and Xu, Z. (2025). FEDLEGAL: The First Real-World Federated Learning Benchmark for Legal NLP. Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (ACL), Springer."},{"key":"ref_73","unstructured":"Wu, Y., Tian, C., Li, J., Sun, H., Tam, K., Zhou, Z., Liao, H., Xiong, J., Guo, Z., and Li, L. (2025). A Survey on Federated Fine-Tuning of Large Language Models. arXiv."},{"key":"ref_74","unstructured":"Hu, E.J., Shen, Y., Wallis, P., Allen-Zhu, Z., Li, Y., Wang, S., Wang, L., and Chen, W. (2022, January 25\u201329). LoRA: Low-Rank Adaptation of Large Language Models. Proceedings of the International Conference on Learning Representations (ICLR), Virtual."},{"key":"ref_75","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The Algorithmic Foundations of Differential Privacy","volume":"9","author":"Dwork","year":"2014","journal-title":"Found. Trends Theor. Comput. Sci."},{"key":"ref_76","doi-asserted-by":"crossref","unstructured":"Abadi, M., Chu, A., Goodfellow, I., McMahan, H.B., Mironov, I., Talwar, K., and Zhang, L. (2016, January 24\u201328). Deep Learning with Differential Privacy. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978318"},{"key":"ref_77","unstructured":"Zhao, G., and Song, E. (2024). Privacy-Preserving Large Language Models: Mechanisms, Applications, and Future Directions. arXiv."},{"key":"ref_78","unstructured":"McMahan, H.B., Ramage, D., Talwar, K., and Zhang, L. (May, January 30). Learning Differentially Private Recurrent Language Models. Proceedings of the 6th International Conference on Learning Representations: ICLR Conference Track Proceedings, Vancouver, BC, Canada."},{"key":"ref_79","unstructured":"Yu, D., Naik, S., Backurs, A., Gopi, S., Inan, H.A., Kamath, G., Kulkarni, J., Lee, Y.T., Manoel, A., and Wutschitz, L. (2021). Differentially Private Fine-tuning of Language Models. arXiv."},{"key":"ref_80","unstructured":"Charles, Z., Ganesh, A., McKenna, R., McMahan, H.B., Mitchell, N., Pillutla, K., and Rush, K. (2024). Fine-Tuning Large Language Models with User-Level Differential Privacy. arXiv."},{"key":"ref_81","unstructured":"Chua, L., Ghazi, B., Huang, Y., Kamath, P., Kumar, R., Liu, D., Manurangsi, P., Sinha, A., and Zhang, C. (2024). Mind the Privacy Unit! User-Level Differential Privacy for Language Model Fine-Tuning. arXiv."},{"key":"ref_82","unstructured":"Xu, J., Saravanan, K., van Dalen, R., Mehmood, H., Tuckey, D., and Ozay, M. (2025). DP-DyLoRA: Fine-Tuning Transformer-Based Models On-Device under Differentially Private Federated Learning using Dynamic Low-Rank Adaptation. arXiv."},{"key":"ref_83","doi-asserted-by":"crossref","first-page":"965","DOI":"10.1145\/293347.293350","article-title":"Private Information Retrieval","volume":"45","author":"Chor","year":"1998","journal-title":"J. ACM"},{"key":"ref_84","doi-asserted-by":"crossref","unstructured":"Bourtoule, L., Chandrasekaran, V., Choquette-Choo, C.A., Jia, H., Travers, A., Zhang, B., Lie, D., and Papernot, N. (2021, January 24\u201327). Machine Unlearning. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA.","DOI":"10.1109\/SP40001.2021.00019"},{"key":"ref_85","doi-asserted-by":"crossref","unstructured":"Hayes, J., Shumailov, I., Triantafillou, E., Khalifa, A., and Papernot, N. (2024). Inexact Unlearning Needs More Careful Evaluations to Avoid a False Sense of Privacy. arXiv.","DOI":"10.1109\/SaTML64287.2025.00034"},{"key":"ref_86","unstructured":"Ashok, P. (2026, April 01). The Goldilocks Standard: Machine Unlearning and the Right to be Forgotten Under Emerging Legal Frameworks. Available online: https:\/\/cep-project.org\/wp-content\/uploads\/2025\/11\/Pratiksha-Ashok-THE-GOLDILOCKS-STANDARD-Machine-Unlearning-and-the-Right-to-be-Forgotten-Under-Emerging-Legal-Frameworks.pdf."},{"key":"ref_87","doi-asserted-by":"crossref","unstructured":"Morris, J.X., Kuleshov, V., Shmatikov, V., and Rush, A.M. (2023, January 6\u201310). Text Embeddings Reveal (Almost) As Much As Text. Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing (EMNLP), Singapore.","DOI":"10.18653\/v1\/2023.emnlp-main.765"},{"key":"ref_88","doi-asserted-by":"crossref","unstructured":"Zeng, S., Zhang, J., He, P., Xing, J., Xue, Y., Chen, Z., Yu, W., Gao, Y., and Xu, D. (2024). The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG). Proceedings of the Findings of the Association for Computational Linguistics (ACL), Association for Computational Linguistics.","DOI":"10.18653\/v1\/2024.findings-acl.267"},{"key":"ref_89","unstructured":"Wang, B., Lou, Q., Zheng, M., and Zhao, D. (2025). PIR-RAG: A System for Private Information Retrieval in Retrieval-Augmented Generation. arXiv."},{"key":"ref_90","first-page":"10","article-title":"Tee-based key-value stores: A survey","volume":"34","year":"2024","journal-title":"VLDB J."},{"key":"ref_91","doi-asserted-by":"crossref","unstructured":"Yue, X., Inan, H., Li, X., Kumar, G., McAnallen, J., Shajari, H., Sun, H., Levitan, D., and Sim, R. (2023, January 9\u201314). Synthetic Text Generation with Differential Privacy: A Simple and Practical Recipe. Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), Toronto, ON, Canada.","DOI":"10.18653\/v1\/2023.acl-long.74"},{"key":"ref_92","unstructured":"Kurakin, A., Ponomareva, N., Syed, U., MacDermed, L., and Terzis, A. (2024). Harnessing large-language models to generate private synthetic text. arXiv."},{"key":"ref_93","unstructured":"Jordon, J., Szpruch, L., Houssiau, F., Bottarelli, M., Cherubin, G., Maple, C., Cohen, S.N., and Weller, A. (2022). Synthetic Data\u2014What, Why and How?. arXiv."},{"key":"ref_94","doi-asserted-by":"crossref","first-page":"11676","DOI":"10.1109\/TNNLS.2024.3486109","article-title":"Exploring the Landscape of Machine Unlearning: A Comprehensive Survey and Taxonomy","volume":"36","author":"Shaik","year":"2024","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_95","unstructured":"Zhang, D., Finckenberg-Broman, P., Hoang, T., Pan, S., Xing, Z., Staples, M., and Xu, X. (2023). Right to be Forgotten in the Era of Large Language Models. arXiv."},{"key":"ref_96","doi-asserted-by":"crossref","unstructured":"Cao, Y., and Yang, J. (2015, January 18\u201320). Towards Making Systems Forget with Machine Unlearning. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Jose, CA, USA.","DOI":"10.1109\/SP.2015.35"},{"key":"ref_97","unstructured":"Thudi, A., Jia, H., Shumailov, I., and Papernot, N. (2022). On the Necessity of Auditable Algorithmic Definitions for Machine Unlearning. Proceedings of the 31st USENIX Security Symposium (USENIX Security 22), USENIX Association."},{"key":"ref_98","doi-asserted-by":"crossref","unstructured":"Ross, R., Winstead, M., and McEvilley, M. (2022). Engineering Trustworthy Secure Systems, Technical Report.","DOI":"10.6028\/NIST.SP.800-160v1r1.fpd"},{"key":"ref_99","doi-asserted-by":"crossref","unstructured":"Ross, R., Pilliteri, V., Graubart, R., Bodeau, D., and Mcquaid, R. (2021). Developing Cyber-Resilient Systems: A Systems Security Engineering Approach, Technical Report.","DOI":"10.6028\/NIST.SP.800-160v2r1"},{"key":"ref_100","unstructured":"Lewis, P., Perez, E., Piktus, A., Petroni, F., Karpukhin, V., Goyal, N., K\u00fcttler, H., Lewis, M., Yih, W.t., and Rockt\u00e4schel, T. (2020, January 6\u201312). Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks. Proceedings of the 34th International Conference on Neural Information Processing Systems, Red Hook, NY, USA."},{"key":"ref_101","unstructured":"Yao, S., Zhao, J., Yu, D., Du, N., Shafran, I., Narasimhan, K., and Cao, Y. (2023, January 1\u20135). ReAct: Synergizing Reasoning and Acting in Language Models. Proceedings of the 11th International Conference on Learning Representations (ICLR), Kigali, Rwanda."},{"key":"ref_102","unstructured":"Packer, C., Wooders, S., Lin, K., Fang, V., Patil, S.G., Stoica, I., and Gonzalez, J.E. (2024). MemGPT: Towards LLMs as Operating Systems. arXiv."},{"key":"ref_103","unstructured":"Obiefuna, N., Oyeneye, S., Odunaiya, S., Oyelaja, I., and Kolawole, S. (2025). Privacy Isn\u2019t Free: Benchmarking the Systems Cost of Privacy-Preserving ML. Proceedings of the 3rd Workshop on Efficient Systems for Foundation Models (ES-FoMo III), International Conference on Machine Learning (ICML), PMLR."},{"key":"ref_104","doi-asserted-by":"crossref","unstructured":"Zhang, X., Pang, Y., Kang, Y., Chen, W., Fan, L., Jin, H., and Yang, Q. (2025). No Free Lunch Theorem for Privacy-Preserving LLM Inference. arXiv.","DOI":"10.1016\/j.artint.2025.104293"},{"key":"ref_105","unstructured":"Microsoft (2026, April 29). Azure Confidential Computing Overview. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/overview."},{"key":"ref_106","unstructured":"Microsoft (2026, April 29). Best Practices for Azure RBAC. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/role-based-access-control\/best-practices."},{"key":"ref_107","unstructured":"Google (2026, April 29). Distributed Differential Privacy for Federated Learning. Available online: https:\/\/research.google\/blog\/distributed-differential-privacy-for-federated-learning\/."},{"key":"ref_108","doi-asserted-by":"crossref","unstructured":"Xiao, H., Zhang, Q., Pei, Q., and Shi, W. (2021, January 7\u201310). Privacy-Preserving Neural Network Inference Framework via Homomorphic Encryption and SGX. Proceedings of the 2021 IEEE 41st International Conference on Distributed Computing Systems (ICDCS), Washington, DC, USA.","DOI":"10.1109\/ICDCS51616.2021.00077"},{"key":"ref_109","doi-asserted-by":"crossref","unstructured":"Natarajan, D., Loveless, A., Dai, W., and Dreslinski, R. (2023, January 3\u20137). Chex-Mix: Combining Homomorphic Encryption with Trusted Execution Environments for Two-party Oblivious Inference in the Cloud. Proceedings of the 2023 IEEE 8th European Symposium on Security and Privacy(EuroS&P), Delft, The Netherlands.","DOI":"10.1109\/EuroSP57164.2023.00014"},{"key":"ref_110","unstructured":"Xu, T., Lu, W.j., Yu, J., Chen, Y., Lin, C., Wang, R., and Li, M. (2025, January 13\u201315). Breaking the Layer Barrier: Remodeling Private Transformer Inference with Hybrid CKKS and MPC. Proceedings of the USENIX Security Symposium (SEC \u201925), Seattle, WA, USA."},{"key":"ref_111","doi-asserted-by":"crossref","unstructured":"Xu, Z., Zhang, Y., Andrew, G., Choquette-Choo, C.A., Kairouz, P., McMahan, H.B., Rosenstock, J., and Zhang, Y. (2023, January 9\u201314). Federated Learning of Gboard Language Models with Differential Privacy. Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 5: Industry Track), Toronto, ON, Canada.","DOI":"10.18653\/v1\/2023.acl-industry.60"},{"key":"ref_112","doi-asserted-by":"crossref","unstructured":"Near, J.P., Darais, D., Lefkovitz, N., and Howarth, G.S. (2025). Guidelines for Evaluating Differential Privacy Guarantees, Technical Report SP 800-226.","DOI":"10.6028\/NIST.SP.800-226"},{"key":"ref_113","unstructured":"NVIDIA (2026, March 27). AI Security with Confidential Computing. Available online: https:\/\/www.nvidia.com\/en-us\/data-center\/solutions\/confidential-computing\/."},{"key":"ref_114","unstructured":"NVIDIA (2026, March 27). Building a Zero-Trust Architecture for Confidential AI Factories. Available online: https:\/\/developer.nvidia.com\/blog\/building-a-zero-trust-architecture-for-confidential-ai-factories\/."},{"key":"ref_115","unstructured":"Microsoft Azure (2026, March 27). Confidential AI\u2014Azure Confidential Computing. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/confidential-ai."},{"key":"ref_116","unstructured":"Phillips, D. (2026, May 28). Announcing General Availability of Azure Confidential Computing (ACC) Virtual Machines for U.S. Government Environments. Available online: https:\/\/devblogs.microsoft.com\/azuregov\/azure-confidential-computing-for-us-gov\/."},{"key":"ref_117","unstructured":"Google Cloud (2026, March 27). Secure AI Innovation Without Interruption. Available online: https:\/\/cloud.google.com\/security\/resources\/secure-ai-innovation."},{"key":"ref_118","unstructured":"Amazon Web Services (2026, March 27). AWS Nitro Enclaves. Available online: https:\/\/aws.amazon.com\/ec2\/nitro\/nitro-enclaves\/."},{"key":"ref_119","unstructured":"Apple Security Research (2026, March 27). Security Research on Private Cloud Compute. Available online: https:\/\/security.apple.com\/blog\/pcc-security-research\/."},{"key":"ref_120","unstructured":"Bonawitz, K., Eichner, H., Grieskamp, W., Huba, D., Ingerman, A., Ivanov, V., Kiddon, C., Kone\u010dn\u00fd, J., Mazzocchi, S., and McMahan, H.B. (April, January 31). Towards Federated Learning at Scale: System Design. Proceedings of the Machine Learning and Systems (MLSys), Stanford, CA, USA."},{"key":"ref_121","unstructured":"Zhang, Y., Ramage, D., Xu, Z., Zhang, Y., Zhai, S., and Kairouz, P. (2023). Private Federated Learning in Gboard. arXiv."},{"key":"ref_122","unstructured":"Google Research (2026, March 27). Fine-Tuning LLMs with User-Level Differential Privacy. Available online: https:\/\/research.google\/blog\/fine-tuning-llms-with-user-level-differential-privacy\/."},{"key":"ref_123","unstructured":"Li, Y., Zhou, X., Wang, Y., Qian, L., and Zhao, J. (2025). Private Transformer Inference in MLaaS: A Survey. arXiv."},{"key":"ref_124","unstructured":"Zhang, Y., Xue, J., Zheng, M., Xie, M., Zhang, M., Jiang, L., and Lou, Q. (2025, January 24\u201328). CipherPrune: Efficient and Scalable Private Transformer Inference. Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore."},{"key":"ref_125","unstructured":"Zeng, W., Dong, Y., Zhou, J., Ma, J., Tan, J., Wang, R., and Li, M. (2025, January 2\u20137). MPCache: MPC-Friendly KV Cache Eviction for Efficient Private LLM Inference. Proceedings of the Advances in Neural Information Processing Systems (NeurIPS), San Diego, CA, USA."},{"key":"ref_126","doi-asserted-by":"crossref","first-page":"113150","DOI":"10.1016\/j.asoc.2025.113150","article-title":"Efficient and performant Transformer private inference with heterogeneous attention mechanisms","volume":"176","author":"Hu","year":"2025","journal-title":"Appl. Soft Comput."},{"key":"ref_127","unstructured":"Apple (2026, April 01). Private Cloud Compute Security Guide. Available online: https:\/\/security.apple.com\/documentation\/private-cloud-compute."},{"key":"ref_128","unstructured":"Microsoft (2026, April 01). Azure AI Confidential Inferencing: Technical Deep-Dive. Available online: https:\/\/techcommunity.microsoft.com\/blog\/azureconfidentialcomputingblog\/azure-ai-confidential-inferencing-technical-deep-dive\/4253150."},{"key":"ref_129","unstructured":"Microsoft (2026, June 11). General Availability: Azure Confidential VMs with NVIDIA H100 Tensor Core GPUs. Available online: https:\/\/techcommunity.microsoft.com\/blog\/azureconfidentialcomputingblog\/general-availability-azure-confidential-vms-with-nvidia-h100-tensor-core-gpus\/4242644."},{"key":"ref_130","unstructured":"Google (2026, June 11). Private AI Compute in the Cloud. Available online: https:\/\/services.google.com\/fh\/files\/misc\/private_ai_compute_technical_brief.pdf."},{"key":"ref_131","unstructured":"NCC Group (2026, June 09). Public Report: Google Private AI Compute Review. Available online: https:\/\/www.nccgroup.com\/research\/public-report-google-private-ai-compute-review\/."},{"key":"ref_132","unstructured":"Google Research (2026, March 28). Discovering New Words with Confidential Federated Analytics. Available online: https:\/\/research.google\/blog\/discovering-new-words-with-confidential-federated-analytics\/."},{"key":"ref_133","unstructured":"Amazon Web Services (2026, April 01). Building Zero Trust Generative AI Applications in Healthcare with AWS Nitro Enclaves. Available online: https:\/\/aws.amazon.com\/blogs\/compute\/building-zero-trust-generative-ai-applications-in-healthcare-with-aws-nitro-enclaves\/."},{"key":"ref_134","unstructured":"Marlinspike, M. (2026, May 29). Confer: End-to-End Encrypted AI Architecture. Available online: https:\/\/confer.to\/blog\/2026\/01\/private-inference\/."},{"key":"ref_135","unstructured":"Marlinspike, M. (2026, June 11). Confer is Bringing Foundational AI Privacy to Meta. Available online: https:\/\/confer.to\/blog\/2026\/03\/encrypted-meta\/."},{"key":"ref_136","unstructured":"Gu, Z., Valdez, E., Ahmed, S., Stephen, J.J., Le, M., Jamjoom, H., Zhao, S., and Lin, Z. (2026, January 18\u201322). Blueprint, Bootstrap, and Bridge: A Security Look at NVIDIA GPU Confidential Computing. Proceedings of the Machine Learning and Systems (MLSys), Bellevue, WA, USA."},{"key":"ref_137","doi-asserted-by":"crossref","unstructured":"Mohan, A., Ye, M., Franke, H., Srivatsa, M., Liu, Z., and Gonzalez, N.M. (2024, January 7\u201313). Securing AI Inference in the Cloud: Is CPU-GPU Confidential Computing Ready?. Proceedings of the 2024 IEEE 17th International Conference on Cloud Computing (CLOUD), Shenzhen, China.","DOI":"10.1109\/CLOUD62652.2024.00028"},{"key":"ref_138","unstructured":"Malekmohammadi, S., and Farnadi, G. (2026). LoRA Provides Differential Privacy by Design via Random Sketching. arXiv."},{"key":"ref_139","doi-asserted-by":"crossref","unstructured":"Xu, H., Shrestha, S., Chen, W., Li, Z., and Cai, Z. (2025). DP-FedLoRA: Privacy-Enhanced Federated Fine-Tuning for On-Device Large Language Models. arXiv.","DOI":"10.1109\/ICDM65498.2025.00089"},{"key":"ref_140","unstructured":"Koga, T., Wu, R., Zhang, Z., and Chaudhuri, K. (2025). Privacy-Preserving Retrieval-Augmented Generation with Differential Privacy. arXiv."},{"key":"ref_141","doi-asserted-by":"crossref","first-page":"105885","DOI":"10.1016\/j.clsr.2023.105885","article-title":"Algorithms that forget: Machine unlearning and the right to erasure","volume":"51","author":"Juliussen","year":"2023","journal-title":"Comput. Law Secur. Rev."},{"key":"ref_142","doi-asserted-by":"crossref","unstructured":"Wei, A., Haghtalab, N., and Steinhardt, J. (2023, January 10\u201316). Jailbroken: How Does LLM Safety Training Fail?. Proceedings of the Advances in Neural Information Processing Systems (NeurIPS), New Orleans, LO, USA.","DOI":"10.52202\/075280-3508"},{"key":"ref_143","unstructured":"Yuan, Y., Jiao, W., Wang, W., Huang, J.t., He, P., Shi, S., and Tu, Z. (2024, January 7\u201311). GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher. Proceedings of the International Conference on Learning Representations (ICLR), Vienna, Austria."},{"key":"ref_144","doi-asserted-by":"crossref","unstructured":"Song, C., and Raghunathan, A. (2020). Information Leakage in Embedding Models. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security (CCS), ACM.","DOI":"10.1145\/3372297.3417270"},{"key":"ref_145","unstructured":"Zharmagambetov, A., Guo, C., Evtimov, I., Pavlova, M., Salakhutdinov, R., and Chaudhuri, K. (2025, January 2\u20137). AgentDAM: Privacy Leakage Evaluation for Autonomous Web Agents. Proceedings of the Advances in Neural Information Processing Systems (NeurIPS), Datasets and Benchmarks Track, San Diego, CA, USA."},{"key":"ref_146","doi-asserted-by":"crossref","unstructured":"El Yagoubi, F., Badu-Marfo, G., and Al Mallah, R. (2026). AgentLeak: A Full-Stack Benchmark for Privacy Leakage in Multi-Agent LLM Systems. arXiv.","DOI":"10.1109\/ACCESS.2026.3704541"},{"key":"ref_147","unstructured":"Patil, V., Stengel-Eskin, E., and Bansal, M. (2025). The Sum Leaks More Than Its Parts: Compositional Privacy Risks and Mitigations in Multi-Agent Collaboration. arXiv."},{"key":"ref_148","unstructured":"Qiao, Y., Liu, D., Yang, H., Zhou, W., and Hu, S. (2025). Agent Tools Orchestration Leaks More: Dataset, Benchmark, and Mitigation. arXiv."},{"key":"ref_149","doi-asserted-by":"crossref","unstructured":"Wang, S., Yu, F., Liu, X., Qin, X., Zhang, J., Lin, Q., Zhang, D., and Rajmohan, S. (2025). Privacy in Action: Towards Realistic Privacy Mitigation and Evaluation for LLM-Powered Agents. arXiv.","DOI":"10.18653\/v1\/2025.findings-emnlp.925"},{"key":"#cr-split#-ref_150.1","unstructured":"European Parliament and Council of the European Union (2024). Regulation"},{"key":"#cr-split#-ref_150.2","unstructured":"(EU) 2024\/1689 of the European Parliament and of the Council Laying Down Harmonised Rules on Artificial Intelligence (AI Act), European Parliament and Council of the European Union. Technical Report."},{"key":"ref_151","unstructured":"(2024). Artificial Intelligence Risk Management Framework: Generative AI Profile (Standard No. NIST AI 600-1)."},{"key":"ref_152","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Sinha, A., and Wellman, M.P. (2018). SoK: Security and Privacy in Machine Learning. Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P), IEEE.","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"ref_153","doi-asserted-by":"crossref","first-page":"972","DOI":"10.1007\/s42979-025-04482-4","article-title":"SoK: Towards Privacy-Centric Collaborative Machine Learning\u2014A Classification Framework for Privacy Solutions","volume":"6","author":"Boar","year":"2025","journal-title":"SN Comput. Sci."},{"key":"ref_154","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1561\/2200000083","article-title":"Advances and Open Problems in Federated Learning","volume":"14","author":"Kairouz","year":"2021","journal-title":"Found. Trends Mach. Learn."},{"key":"ref_155","doi-asserted-by":"crossref","unstructured":"Mironov, I. (2017). R\u00e9nyi Differential Privacy. Proceedings of the 2017 IEEE 30th Computer Security Foundations Symposium (CSF), IEEE.","DOI":"10.1109\/CSF.2017.11"},{"key":"ref_156","first-page":"635","article-title":"Concentrated Differential Privacy: Simplifications, Extensions, and Lower Bounds","volume":"Volume 9985","author":"Bun","year":"2016","journal-title":"Proceedings of the Theory of Cryptography Conference (TCC)"},{"key":"ref_157","doi-asserted-by":"crossref","unstructured":"Canetti, R. (2001). Universally Composable Security: A New Paradigm for Cryptographic Protocols. Proceedings of the 42nd IEEE Symposium on Foundations of Computer Science (FOCS), IEEE.","DOI":"10.1109\/SFCS.2001.959888"},{"key":"ref_158","doi-asserted-by":"crossref","unstructured":"Vadhan, S., and Wang, T. (2021). Concurrent Composition of Differential Privacy. Proceedings of the Theory of Cryptography Conference (TCC), Springer.","DOI":"10.1007\/978-3-030-90453-1_20"},{"key":"ref_159","unstructured":"Jayaraman, B., and Evans, D. (2019). Evaluating Differentially Private Machine Learning in Practice. Proceedings of the 28th USENIX Security Symposium, USENIX Association."},{"key":"ref_160","unstructured":"Sailer, R., Zhang, X., Jaeger, T., and van Doorn, L. (2004). Design and Implementation of a TCG-based Integrity Measurement Architecture. Proceedings of the 13th USENIX Security Symposium, USENIX Association."},{"key":"ref_161","doi-asserted-by":"crossref","unstructured":"M\u00e9n\u00e9trey, J., G\u00f6ttel, C., Pasin, M., Felber, P., and Schiavoni, V. (2022). An Exploratory Study of Attestation Mechanisms for Trusted Execution Environments. arXiv.","DOI":"10.1007\/978-3-031-16092-9_7"},{"key":"ref_162","unstructured":"Ozga, W., Sagmeister, P., Visegrady, T., and Dragone, S. (2023). Scalable Attestation of Virtualized Execution Environments in Hybrid- and Multi-Cloud. arXiv."},{"key":"ref_163","unstructured":"Shang, K., Lin, J., Qin, Y., Shen, M., Ma, H., Feng, W., and Feng, D. (2024). CCxTrust: Confidential Computing Platform Based on TEE and TPM Collaborative Trust. arXiv."},{"key":"ref_164","unstructured":"Sun, S., and Evans, S. (2026). Composable Attestation: A Generalized Framework for Continuous and Incremental Trust in AI-Driven Distributed Systems. arXiv."},{"key":"ref_165","unstructured":"Chuang, J., Seto, A., Berrios, N., van Schaik, S., Garman, C., and Genkin, D. (2026, January 18\u201321). TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA."},{"key":"ref_166","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2019). Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP.2019.00065"},{"key":"ref_167","unstructured":"Nasr, M., Hayes, J., Steinke, T., Balle, B., Tram\u00e8r, F., Jagielski, M., Carlini, N., and Terzis, A. (2023). Tight Auditing of Differentially Private Machine Learning. Proceedings of the Proceedings of the 32nd USENIX Security Symposium, USENIX Association."},{"key":"ref_168","doi-asserted-by":"crossref","first-page":"3123","DOI":"10.1109\/TIFS.2021.3075843","article-title":"Unexpected Information Leakage of Differential Privacy Due to the Linear Property of Queries","volume":"16","author":"Huang","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_169","doi-asserted-by":"crossref","unstructured":"Rose, S., Borchert, O., Mitchell, S., and Connelly, S. (2020). Zero Trust Architecture, Technical Report.","DOI":"10.6028\/NIST.SP.800-207-draft2"},{"key":"ref_170","unstructured":"Microsoft Azure (2026, March 28). Trusted Computing Base (TCB) in Azure Confidential Computing. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/trusted-compute-base."},{"key":"ref_171","unstructured":"(2026). Information Security, Cybersecurity and Privacy Protection\u2014Evaluation Criteria for IT Security (Standard No. ISO\/IEC 15408-1:2026)."},{"key":"ref_172","doi-asserted-by":"crossref","unstructured":"Dittmar, Y., Stephan, M.J., V\u00f6lkl, T., Hollick, M., and Classen, J. (2026). Unlocking Apple\u2019s Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence. Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2026), Association for Computing Machinery.","DOI":"10.1145\/3765613.3811691"},{"key":"ref_173","unstructured":"NCC Group (2026, June 11). Public Report: AWS Nitro System API & Security Claims. Available online: https:\/\/www.nccgroup.com\/research\/public-report-aws-nitro-system-api-security-claims\/."},{"key":"ref_174","doi-asserted-by":"crossref","unstructured":"Kazman, R., Klein, M., and Clements, P. (2000). ATAM: Method for Architecture Evaluation, Software Engineering Institute, Carnegie Mellon University. Technical Report CMU\/SEI-2000-TR-004.","DOI":"10.21236\/ADA382629"},{"key":"ref_175","unstructured":"Shostack, A. (2014). Threat Modeling: Designing for Security, Wiley."},{"key":"ref_176","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","article-title":"A Privacy Threat Analysis Framework: Supporting the Elicitation and Fulfillment of Privacy Requirements","volume":"16","author":"Deng","year":"2011","journal-title":"Requir. Eng."},{"key":"ref_177","unstructured":"NVIDIA (2026, June 10). NVIDIA Blackwell Architecture: TEE-I\/O Confidential Computing with Protected NVLink. Available online: https:\/\/www.nvidia.com\/en-us\/data-center\/technologies\/blackwell-architecture\/."},{"key":"ref_178","unstructured":"Opaque Systems (2026, May 28). Confidential Agents for RAG. Available online: https:\/\/www.opaque.co\/confidential-agents-for-rag."},{"key":"ref_179","unstructured":"Zhou, P., Feng, Y., and Yang, Z. (2025). Provably Secure Retrieval-Augmented Generation. arXiv."},{"key":"ref_180","doi-asserted-by":"crossref","unstructured":"Li, H., Guo, D., Li, D., Fan, W., Hu, Q., Liu, X., Chan, C., Yao, D., Yao, Y., and Song, Y. (2024). PrivLM-Bench: A Multi-level Privacy Evaluation Benchmark for Language Models. arXiv.","DOI":"10.18653\/v1\/2024.acl-long.4"},{"key":"ref_181","unstructured":"National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), Technical Report NIST AI 100-1."},{"key":"ref_182","unstructured":"Google Cloud (2026, March 28). RAG Infrastructure for Generative AI Using Vertex AI and Vector Search. Available online: https:\/\/docs.cloud.google.com\/architecture\/gen-ai-rag-vertex-ai-vector-search."},{"key":"ref_183","unstructured":"Google Cloud (2026, March 28). Private Connectivity for RAG-Capable Generative AI Applications. Available online: https:\/\/docs.cloud.google.com\/architecture\/private-connectivity-rag-capable-gen-ai."},{"key":"ref_184","unstructured":"Amazon Web Services (2026, May 28). Observability and Monitoring (Building Serverless Architectures for Agentic AI on AWS). Available online: https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/agentic-ai-serverless\/observability-and-monitoring.html."},{"key":"ref_185","unstructured":"Microsoft Azure (2026, March 28). Machine Learning Operations (MLOps) v2. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/architecture\/ai-ml\/guide\/machine-learning-operations-v2."},{"key":"ref_186","unstructured":"Google Cloud (2026, March 28). Choose Your Agentic AI Architecture Components. Available online: https:\/\/docs.cloud.google.com\/architecture\/choose-agentic-ai-architecture-components."},{"key":"ref_187","unstructured":"Amazon Web Services (2026, March 28). Generative AI Lifecycle Operational Excellence Framework on AWS. Available online: https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/gen-ai-lifecycle-operational-excellence\/gen-ai-lifecycle-operational-excellence.pdf."},{"key":"ref_188","unstructured":"OpenTelemetry (2026, March 28). OpenTelemetry for Generative AI. Available online: https:\/\/opentelemetry.io\/blog\/2024\/otel-generative-ai\/."},{"key":"ref_189","unstructured":"OpenTelemetry (2026, March 28). AI Agent Observability\u2014Evolving Standards and Best Practices. Available online: https:\/\/opentelemetry.io\/blog\/2025\/ai-agent-observability\/."},{"key":"ref_190","unstructured":"Inan, H., Upasani, K., Chi, J., Rungta, R., Iyer, K., Mao, Y., Tontchev, M., Hu, Q., Fuller, B., and Testuggine, D. (2023). Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations. arXiv."},{"key":"ref_191","unstructured":"Mankins, J.C. (1995). Technology Readiness Levels: A White Paper, Technical Report."},{"key":"ref_192","unstructured":"OSD Manufacturing Technology Program, and Joint Service\/Industry MRL Working Group (2022). Manufacturing Readiness Level (MRL) Deskbook, Technical Report."},{"key":"ref_193","doi-asserted-by":"crossref","unstructured":"Sauser, B.J., Long, M., Forbes, E., and McGrory, S.E. (2009, January 19\u201323). Defining an Integration Readiness Level for Defense Acquisition. Proceedings of the INCOSE International Symposium, Singapore.","DOI":"10.1002\/j.2334-5837.2009.tb00953.x"},{"key":"ref_194","unstructured":"Sauser, B., Verma, D., Ramirez-Marquez, J., and Gove, R. (2006, January 7\u20138). From TRL to SRL: The Concept of Systems Readiness Levels. Proceedings of the Conference on Systems Engineering Research (CSER), Los Angeles, CA, USA."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-4893\/19\/6\/500\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T04:23:50Z","timestamp":1782534230000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-4893\/19\/6\/500"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":195,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2026,6]]}},"alternative-id":["a19060500"],"URL":"https:\/\/doi.org\/10.3390\/a19060500","relation":{},"ISSN":["1999-4893"],"issn-type":[{"value":"1999-4893","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,22]]}}}