PLANTWIN: Privacy-Preserving Planning Abstractions for Cloud-Assisted LLM Agents

Publisher:
Institute of Electrical and Electronics Engineers (IEEE)
Publication Type:
Journal Article
Citation:
IEEE Transactions on Services Computing, 2026, PP, (99), pp. 1-19
Issue Date:
2026-01-01
Full metadata record
Cloud-hosted large language models (LLMs) have become the de facto planners in agentic systems, coordinating tools and guiding execution over local environments. In many deployments, however, the environment being planned over is private, containing source code, files, credentials, and metadata that cannot be exposed to the cloud. Existing solutions address adjacent concerns, such as execution isolation, access control, or confidential inference, but they do not control what cloud planners observe during planning: within the permitted scope, raw environment state is still exposed. We introduce PLANTWIN, a schema-constrained projection based architecture for cloud-assisted planning that prevents raw local context from leaving the local boundary. The key idea is to project the real environment into a planning-oriented digital twin: a schema-constrained and de-identified abstract graph that preserves planning-relevant structure while removing reconstructable details. The cloud planner operates solely on this sanitized twin through a bounded capability interface, while a local gatekeeper enforces safety policies and cumulative disclo sure budgets. We further formalize the privacy–utility trade-off as a capability granularity problem, define architectural privacy goals using (k,δ)-anonymity and ϵ-unlinkability, and mitigate compositional leakage through multi-turn disclosure control. We implement PLANTWIN as middleware between local agents and cloud planners and evaluate it on 60 agentic tasks across ten domains with four cloud planners. PLANTWIN achieves SND = 1.0 against passive-observer adversaries, while maintaining planning quality close to full-context systems: three of four cloud planners achieve PQS > 0.79, within ∼4% of the no-privacy Raw Context baseline; the privacy-hardening pipeline stages add less than 2.2 percentage points of further PQS variation. Residual identifiability under stronger structural-fingerprint adversaries persists and is bounded by deployment-side controls rather than architecturally eliminated.
Please use this identifier to cite or link to this item: