[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-a-framework-that-swaps-your-words-before-the-ai-sees-them":10,"sections":45},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":34,"tags":35,"sources":40,"feedback":44,"feedback_at":22,"cost_usd":44,"total_tokens":44},7341,"a-framework-that-swaps-your-words-before-the-ai-sees-them","A Framework That Swaps Your Words Before the AI Sees Them","CROSS-MAP swaps a prompt's real content for a decoy with the same structure, letting cloud AI models process it without ever seeing your actual words.","A new privacy scheme for AI prompts doesn't hide your words. It replaces them with different ones entirely, then swaps the real meaning back in after the model responds.\n\nThe framework, called CROSS-MAP, comes from a paper posted to arXiv this week. It targets a specific problem: when you send a prompt to an LLM API, the provider sees the raw text, and privacy tricks that just tweak or redact that text still leave enough clues for someone to reconstruct the original. CROSS-MAP instead maps your input into a different semantic domain before it ever reaches the model, then recovers the intended output on your end afterward. A local model handles both directions, trained to make the swapped version as semantically distant from the original as possible while keeping the underlying structure the reasoning model needs intact - and trained separately to make sure the recovery step doesn't lose meaning along the way. The researchers report it cuts down successful reconstruction attempts across several attack scenarios while still beating existing privacy baselines on task performance.\n\nThis matters because most privacy add-ons for LLMs trade off usefulness for protection - anonymize too aggressively and the model's answers get worse. CROSS-MAP's pitch is that separating \"structure\" from \"meaning\" lets you keep both, since the cloud model still gets something it can reason over even though it's not your actual content.\n\nIt's a preprint, not a shipped product, and \"reduces reconstruction success\" is not the same as \"reconstruction-proof\" - worth watching how it holds up once someone tries to break it in production.","[\"llm privacy\",\"ai security\",\"prompt privacy\",\"arxiv research\"]","2026-09-23T04:00:00.000Z","2026-09-23T08:25:38.288Z","2026-09-23T08:25:42.940Z","published",null,[24,30],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Cut or attribute the closing claim that attacker-awareness of CROSS-MAP 'is still an open question the paper does not fully settle' and the interpretive gloss that recovered answers held up 'about as well as unprotected ones' — neither is stated in the provided source abstract, so both read as invented claims rather than reported findings.","resolved",{"id":31,"reviewer":26,"round":32,"reason":33,"status":29},"editor-r2",2,"Fix the contradiction between the dek's claim that the framework 'hides a prompt's real meaning' and the body's opening line that it explicitly does not hide meaning but substitutes it entirely — align the dek with the swap\u002Fsubstitution framing used throughout the piece.","security",[36,37,38,39],"llm privacy","ai security","prompt privacy","arxiv research",[41],{"name":42,"url":43},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.23193",0,{"sections":46},[47,51,54,59,64,68,72,77,82,87,92,97,102,107],{"name":48,"slug":49,"count":50,"latest_published_at":18},"AI","ai",4297,{"name":52,"slug":34,"count":53,"latest_published_at":18},"Security",710,{"name":55,"slug":56,"count":57,"latest_published_at":58},"Policy","policy",369,"2026-09-23T02:13:52.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":63},"Deals","deals",202,"2026-09-22T23:00:04.000Z",{"name":65,"slug":66,"count":67,"latest_published_at":18},"Hardware","hardware",169,{"name":69,"slug":70,"count":71,"latest_published_at":18},"Science","science",133,{"name":73,"slug":74,"count":75,"latest_published_at":76},"Consumer Tech","consumer-tech",110,"2026-09-22T20:00:00.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Software","software",80,"2026-09-22T23:32:52.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Dev Tools","dev-tools",79,"2026-09-22T22:21:13.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Startups","startups",65,"2026-09-22T22:06:48.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Gaming","gaming",45,"2026-09-22T15:35:06.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"General","general",43,"2026-09-21T23:48:56.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"Reviews","reviews",27,"2026-09-22T13:00:00.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]