为大模型设计隐私合规框架,防止敏感数据泄露。
LLM Access Shield: Domain-Specific LLM Framework for Privacy Policy Compliance
- 用大模型自动生成检测规则,精准识别领域敏感信息。
- 实时动态调整安全策略,适配交互中变化的合规要求。
- 保留数据格式的加密技术,确保隐私与可用性兼顾。
大语言模型在金融、教育和治理等领域广泛应用,因其生成类人文本和适应专业任务的能力。然而,其普及带来了数据隐私与安全风险,包括敏感信息泄露。本文提出一个安全框架,以强化策略合规并降低交互风险。方法包含三项创新:(i) 基于大模型的策略执行:可定制机制,提升领域敏感数据检测能力;(ii) 动态策略定制:在用户-大模型交互过程中实时调整并执行策略,确保符合不断变化的安全要求;(iii) 敏感数据匿名化:一种保持格式的加密技术,在保护敏感信息的同时维持上下文完整性。实验表明,该框架有效缓解安全风险,同时保持大模型任务的功能准确性。
原文摘要 · Abstract (English)
Large language models (LLMs) are increasingly applied in fields such as finance, education, and governance due to their ability to generate human-like text and adapt to specialized tasks. However, their widespread adoption raises critical concerns about data privacy and security, including the risk of sensitive data exposure. In this paper, we propose a security framework to enforce policy compliance and mitigate risks in LLM interactions. Our approach introduces three key innovations: (i) LLM-based policy enforcement: a customizable mechanism that enhances domain-specific detection of sensitive data. (ii) Dynamic policy customization: real-time policy adaptation and enforcement during user-LLM interactions to ensure compliance with evolving security requirements. (iii) Sensitive data anonymization: a format-preserving encryption technique that protects sensitive information while maintaining contextual integrity. Experimental results demonstrate that our framework effectively mitigates security risks while preserving the functional accuracy of LLM-driven tasks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。