arXiv:2502.18545cs.CRcs.AI2025-02ACL被引 10

首个评估查询相关隐私保护的基准,发现大模型难判信息是否敏感。

PII-Bench: Evaluating Query-Aware Privacy Protection Systems

  • 提出不依赖查询的隐私信息屏蔽策略
  • 在55类隐私信息上测试,复杂多主体场景准确率低
  • 适合隐私安全与LLM评测方向研究者

大型语言模型(LLMs)广泛应用引发了用户提示中个人身份信息(PII)泄露的隐私担忧。为此,我们提出一种与查询无关的PII屏蔽策略,并构建了PII-Bench——首个全面评估隐私保护系统的基准框架。该框架包含2,842个测试样本,覆盖55种细粒度的PII类别,涵盖从单一主体描述到复杂多方交互的多样化场景。每个样本均配有用户查询、上下文描述及标注出与查询相关的标准答案。实证评估显示,尽管当前模型在基础PII检测上表现尚可,但在判断PII与查询的相关性方面存在显著不足。即使是顶尖的大模型,在处理复杂多主体场景时也表现不佳,表明实现智能PII屏蔽仍有巨大改进空间。

原文摘要 · Abstract (English)

The widespread adoption of Large Language Models (LLMs) has raised significant privacy concerns regarding the exposure of personally identifiable information (PII) in user prompts. To address this challenge, we propose a query-unrelated PII masking strategy and introduce PII-Bench, the first comprehensive evaluation framework for assessing privacy protection systems. PII-Bench comprises 2,842 test samples across 55 fine-grained PII categories, featuring diverse scenarios from single-subject descriptions to complex multi-party interactions. Each sample is carefully crafted with a user query, context description, and standard answer indicating query-relevant PII. Our empirical evaluation reveals that while current models perform adequately in basic PII detection, they show significant limitations in determining PII query relevance. Even state-of-the-art LLMs struggle with this task, particularly in handling complex multi-subject scenarios, indicating substantial room for improvement in achieving intelligent PII masking.

隐私保护大模型评测数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。