Toward Trustworthy LLM Router Ecosystems: Incentive-Compatible Cryptographic Mitigations
Abstract
LLM API routers make access to frontier models convenient, but they also create a hidden trust problem: the router that forwards a request can observe prompts, credentials, and tool calls and can rewrite outputs before they reach the client. We argue that this is a structural security and accountability problem that detection alone cannot solve and that workable defenses must align with the incentives of users, routers, and providers. We therefore assemble a progressively deployable trust-reduction stack from existing mechanisms, with each phase designed to provide an immediate adoption benefit. We then implement a LiteLLM-compatible proof of concept and show that it preserves LLM router utility with acceptable overhead while enhancing user-side privacy.