arXiv:2412.12040cs.CL2024-12EMNLP被引 3

语言模型在摘要生成中易泄露个人信息,远不如人类谨慎。

How Private are Language Models in Abstractive Summarization?

  • 对比多种模型与策略,测试其摘要中的隐私泄露风险。
  • 模型摘要泄露率显著高于人工摘要,尤其在医疗法律领域。
  • 适合关注数据隐私与大模型安全的研究者与从业者参考。

在医疗、法律等敏感领域,保护个人数据至关重要,相关法规严格禁止信息泄露。这给共享病历报告、案件摘要等有价值数据带来挑战。尽管语言模型在文本摘要任务中表现优异,但其能否生成保护隐私的摘要仍不明确。本文系统评估了两种闭源和四种开源语言模型(不同规模与架构)在摘要生成中的隐私风险,涵盖医疗、法律等多个数据集,采用提示工程与微调策略。定量与定性分析(含人工评估)显示,模型生成的摘要频繁泄露可识别个人信息,而人工摘要则展现出更高水平的隐私保护。结果表明,当前语言模型在隐私敏感摘要任务中的能力与专家人类表现存在显著差距。

原文摘要 · Abstract (English)

In sensitive domains such as medical and legal, protecting sensitive information is critical, with protective laws strictly prohibiting the disclosure of personal data. This poses challenges for sharing valuable data such as medical reports and legal cases summaries. While language models (LMs) have shown strong performance in text summarization, it is still an open question to what extent they can provide privacy-preserving summaries from non-private source documents. In this paper, we perform a comprehensive study of privacy risks in LM-based summarization across two closed- and four open-weight models of different sizes and families. We experiment with both prompting and fine-tuning strategies for privacy-preservation across a range of summarization datasets including medical and legal domains. Our quantitative and qualitative analysis, including human evaluation, shows that LMs frequently leak personally identifiable information in their summaries, in contrast to human-generated privacy-preserving summaries, which demonstrate significantly higher privacy protection levels. These findings highlight a substantial gap between current LM capabilities and expert human expert performance in privacy-sensitive summarization tasks.

语言模型隐私保护摘要生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。