I’m pretty sure your query will effectively still be derivable on the server side, as it has to syntactically/semantically interact with the model. To truly disguise it, at least part of the model/weights would have to be transferred to the client side (so that the server doesn’t learn the adjustment), which would in turn leak the model.