The public key is the LLM distribution, and the private key is the secret prompt. While there's no proven one-way property like in "public key cryptography," the complexity of the model distribution effectively acts as a trapdoor function. This is not about the model itself encrypting anything, but rather a Steganography protocol that uses the LLM's probability space as a public key.
arxiv.org
https://arxiv.org/pdf/2510.20075v3

Seonglae Cho