CoTrust: Privacy-Preserving Collaboration Between Large and Small Language Models in Trusted Execution Environments
Zhenya Ma, Tingyi Wang, Yongheng Deng, Ziqing Qiao, Yinggui Wang, Tao Wei, Lei Wang, Ju Ren
Abstract
Services powered by large language models (LLMs) provide powerful text generation capabilities, but accessing sensitive user inputs raises serious privacy concerns. Trusted Execution Environments (TEEs) provide a secure computation environment, enabling sensitive inputs to be safely processed. However, directly deploying high-capacity LLMs in TEEs is often prohibitively expensive due to computation and memory constraints. To reconcile privacy, efficiency, and generation quality, we propose CoTrust, a privacy-preserving collaborative inference framework that combines LLMs with small language models (SLMs) inside TEE. CoTrust uses multiple de-identified views to let the LLM produce a consensus scaffold capturing answer reasoning without exposing private information, which the SLM then grounds in the full input to generate the final response. Experiments on multiple question answering and summarization benchmarks show that CoTrust approaches the performance of unconstrained LLMs, outperforms existing privacy-preserving baselines, and maintains strong privacy protection, while remaining efficient in a TDX-based TEE implementation.- Anthology ID:
- 2026.findings-acl.1078
- Volume:
- Findings of the Association for Computational Linguistics: ACL 2026
- Month:
- July
- Year:
- 2026
- Address:
- San Diego, California, United States
- Editors:
- Maria Liakata, Viviane P. Moreira, Jiajun Zhang, David Jurgens
- Venue:
- Findings
- SIG:
- Publisher:
- Association for Computational Linguistics
- Note:
- Pages:
- 21423–21440
- Language:
- URL:
- https://preview.aclanthology.org/ingest-acl/2026.findings-acl.1078/
- DOI:
- Cite (ACL):
- Zhenya Ma, Tingyi Wang, Yongheng Deng, Ziqing Qiao, Yinggui Wang, Tao Wei, Lei Wang, and Ju Ren. 2026. CoTrust: Privacy-Preserving Collaboration Between Large and Small Language Models in Trusted Execution Environments. In Findings of the Association for Computational Linguistics: ACL 2026, pages 21423–21440, San Diego, California, United States. Association for Computational Linguistics.
- Cite (Informal):
- CoTrust: Privacy-Preserving Collaboration Between Large and Small Language Models in Trusted Execution Environments (Ma et al., Findings 2026)
- PDF:
- https://preview.aclanthology.org/ingest-acl/2026.findings-acl.1078.pdf