CoTrust: Privacy-Preserving Collaboration Between Large and Small Language Models in Trusted Execution Environments

Zhenya Ma, Tingyi Wang, Yongheng Deng, Ziqing Qiao, Yinggui Wang, Tao Wei, Lei Wang, Ju Ren


Abstract
Services powered by large language models (LLMs) provide powerful text generation capabilities, but accessing sensitive user inputs raises serious privacy concerns. Trusted Execution Environments (TEEs) provide a secure computation environment, enabling sensitive inputs to be safely processed. However, directly deploying high-capacity LLMs in TEEs is often prohibitively expensive due to computation and memory constraints. To reconcile privacy, efficiency, and generation quality, we propose CoTrust, a privacy-preserving collaborative inference framework that combines LLMs with small language models (SLMs) inside TEE. CoTrust uses multiple de-identified views to let the LLM produce a consensus scaffold capturing answer reasoning without exposing private information, which the SLM then grounds in the full input to generate the final response. Experiments on multiple question answering and summarization benchmarks show that CoTrust approaches the performance of unconstrained LLMs, outperforms existing privacy-preserving baselines, and maintains strong privacy protection, while remaining efficient in a TDX-based TEE implementation.
Anthology ID:
2026.findings-acl.1078
Volume:
Findings of the Association for Computational Linguistics: ACL 2026
Month:
July
Year:
2026
Address:
San Diego, California, United States
Editors:
Maria Liakata, Viviane P. Moreira, Jiajun Zhang, David Jurgens
Venue:
Findings
SIG:
Publisher:
Association for Computational Linguistics
Note:
Pages:
21423–21440
Language:
URL:
https://preview.aclanthology.org/ingest-acl/2026.findings-acl.1078/
DOI:
Bibkey:
Cite (ACL):
Zhenya Ma, Tingyi Wang, Yongheng Deng, Ziqing Qiao, Yinggui Wang, Tao Wei, Lei Wang, and Ju Ren. 2026. CoTrust: Privacy-Preserving Collaboration Between Large and Small Language Models in Trusted Execution Environments. In Findings of the Association for Computational Linguistics: ACL 2026, pages 21423–21440, San Diego, California, United States. Association for Computational Linguistics.
Cite (Informal):
CoTrust: Privacy-Preserving Collaboration Between Large and Small Language Models in Trusted Execution Environments (Ma et al., Findings 2026)
Copy Citation:
PDF:
https://preview.aclanthology.org/ingest-acl/2026.findings-acl.1078.pdf
Checklist:
 2026.findings-acl.1078.checklist.pdf