NeurIPS 2025poster0 citations

CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment

Qinfeng Li, Tianyue Luo, Xuhong Zhang, Yangfan Xie, Zhiqiang Shen, Lijun Zhang, Yier Jin, Hao Peng

Abstract

Proprietary large language models (LLMs) exhibit strong generalization capabilities across diverse tasks and are increasingly deployed on edge devices for efficiency and privacy reasons. However, deploying proprietary LLMs at the edge without adequate protection introduces critical security threats. Attackers can extract model weights and architectures, enabling unauthorized copying and misuse. Even when protective measures prevent full extraction of model weights, attackers may still perform advanced attacks, such as fine-tuning, to further exploit the model. Existing defenses against these threats typically incur significant computational and communication overhead, making them impractical for edge deployment. To safeguard the edge-deployed LLMs, we introduce CoreGuard, a computation- and communication-efficient protection method. CoreGuard employs an efficient protection protocol to reduce computational overhead and minimize communication overhead via a propagation protocol. Extensive experiments show that CoreGuard achieves upper-bound security protection with negligible overhead.

Intellectual Property ProtectionLarge Language ModelModel StealingProactive DefenseTrusted Execution Environment
BibTeX
@inproceedings{
li2025coreguard,
title={CoreGuard: Safeguarding Foundational Capabilities of {LLM}s Against Model Stealing in Edge Deployment},
author={Qinfeng Li and Tianyue Luo and Xuhong Zhang and Yangfan Xie and Zhiqiang Shen and Lijun Zhang and Yier Jin and Hao Peng and Xinkui Zhao and XianWei Zhu and Jianwei Yin},
booktitle={The Thirty-ninth Annual Conference on Neural Information Processing Systems},
year={2025},
url={https://openreview.net/forum?id=84dnGT4ajt}
}
CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment · NeurIPS 2025