Built with and by Teycir Ben Soltane•
How to Use•FAQ•GitHub•arXiv.org•
Share:
ArXivCSExplorer
☆☆Bookmarks🏆RSSHow to UseFAQ
Back to Paper
cs.CR

Local ID: 2604.17238v2

AI Summary: gemma4:e4b

Breaking Euston: Recovering Private Inputs from Secure Inference by Exploiting Subspace Leakage

By Jiaqi Zhao, Fengwei Wang

Revision History Timeline

v14/19/2026
4/19/2026

“3 pages, 4 figures”

v24/25/2026
4/25/2026

“The authors have decided to withdraw this manuscript due to concerns regarding the timing and appropriateness of public disclosure. The work involves analysis of results that have not yet been formally presented, and releasing this version at the current stage may not be suitable. The manuscript will be further revised and may be resubmitted at a more appropriate time”

★ Version indexed in Explorer

Comparing v1 vs v2

Green = Added • Red = Removed

Title Comparison

Breaking Euston: Recovering Private Inputs from Secure Inference by Exploiting Subspace Leakage

Authors Comparison

No author changes.

v1 Comment

“3 pages, 4 figures”

v2 Comment

“The authors have decided to withdraw this manuscript due to concerns regarding the timing and appropriateness of public disclosure. The work involves analysis of results that have not yet been formally presented, and releasing this version at the current stage may not be suitable. The manuscript will be further revised and may be resubmitted at a more appropriate time”

Abstract Word Diff

In the 47th IEEE Symposium on Security and Privacy (IEEE S&P 2026), Gao et al. proposed an efficient and user-friendly secure transformer inference framework, namely Euston. In Euston, a singular value decomposition-based matrix transmission protocol is designed to efficiently transmit input matrices, reducing communication bandwidth by approximately 2.8 times. In this manuscript, we show that this transmission protocol introduces subspace leakage of random masks, enabling the model owner to recover private samples easily. We further validate the effectiveness of the recovery attack through simple experiments on image and language datasets, highlighting a fundamental privacy risk of the protocol design.
View Full Version History on arXiv