- M(Q) is nearly the same as M(P)
- P is hard to reverse engineer from Q
As a applied crypto researcher, this feels like an "ML-based homomorphic encryption". Works with any model (that supports prompt_embeds) without changing anything on the model side. Very cool indeed.
Credit note: This method was invented by Protopia Labs and I don't have any affiliation there.