动态适配全球隐私法规,智能屏蔽大模型中的敏感信息。
Adaptive PII Mitigation Framework for Large Language Models
- 基于上下文感知与策略驱动的动态遮蔽机制
- 护照号识别F1达0.95,显著优于现有工具
- 支持GDPR/CCPA等多法规,适合企业合规场景
人工智能面临日益严格的全球数据保护法规挑战。如GDPR和CCPA等法规对机器学习模型提出严格的数据使用要求,赋予个人数据更正与删除权,使依赖大规模数据训练的大语言模型(LLMs)在训练与部署中面临合规难题。公开数据未必可合法用于机器学习,加剧了这一问题。本文提出一种自适应的个人身份信息(PII)与敏感个人身份信息(SPI)缓解框架,能够动态匹配不同监管体系,并无缝集成至治理、风险与合规(GRC)系统。该系统结合先进自然语言处理技术、上下文感知分析与策略驱动的掩码机制,确保合规性。基准测试显示,其在护照号识别上取得0.95的F1分数,远超Microsoft Presidio(0.33)与Amazon Comprehend(0.54)。人类评估中,用户信任度平均达4.6/5,认可其准确性和透明性。观察发现,系统在GDPR下执行更严格匿名化,而于CCPA则允许伪匿名化与用户退出。结果验证了该系统作为企业级隐私合规的可扩展、强健解决方案的有效性。
原文摘要 · Abstract (English)
Artificial Intelligence (AI) faces growing challenges from evolving data protection laws and enforcement practices worldwide. Regulations like GDPR and CCPA impose strict compliance requirements on Machine Learning (ML) models, especially concerning personal data use. These laws grant individuals rights such as data correction and deletion, complicating the training and deployment of Large Language Models (LLMs) that rely on extensive datasets. Public data availability does not guarantee its lawful use for ML, amplifying these challenges. This paper introduces an adaptive system for mitigating risk of Personally Identifiable Information (PII) and Sensitive Personal Information (SPI) in LLMs. It dynamically aligns with diverse regulatory frameworks and integrates seamlessly into Governance, Risk, and Compliance (GRC) systems. The system uses advanced NLP techniques, context-aware analysis, and policy-driven masking to ensure regulatory compliance. Benchmarks highlight the system's effectiveness, with an F1 score of 0.95 for Passport Numbers, outperforming tools like Microsoft Presidio (0.33) and Amazon Comprehend (0.54). In human evaluations, the system achieved an average user trust score of 4.6/5, with participants acknowledging its accuracy and transparency. Observations demonstrate stricter anonymization under GDPR compared to CCPA, which permits pseudonymization and user opt-outs. These results validate the system as a scalable and robust solution for enterprise privacy compliance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。