Unresolved cross-tensor attacks on the split-LLM protocol
Investigate whether cross-tensor attacks other than the implemented rotation-invariant cross-Gram feature can extract private information from the concatenated forward activation and returned-gradient views of the two-node split-LLM training system.
References
Under the two implemented emitters, the joint-view effect therefore runs through the concatenated gradient block's own content, not through the rotation-cancelling cross-term; other cross-tensor attacks remain open.
— Privacy Failure in Split-LLM Training, The Returned Gradient Nullifies the Decoys
(2609.04382 - Politis et al., 3 Sep 2026) in Section 5.2, subsection “Does the leak survive a configuration worth deploying?”