arXiv:2506.00964cs.CL2025-06ACL被引 1

让大模型学会识别数据敏感度,避免越权访问。

ACCESS DENIED INC: The First Benchmark Environment for Sensitivity Awareness

  • 提出敏感度感知机制,让模型理解数据访问权限。
  • 发现不同模型处理越权请求差异大,部分表现不佳。
  • 适合研究企业级隐私保护与AI安全的团队使用。

大型语言模型(LLMs)在企业数据管理中日益重要,因其能处理多种文档格式并支持自然语言查询。然而,在与员工交互时,必须考虑信息敏感性及访问限制。仅依赖用户权限等级过滤存在性能与隐私隐患。为此,我们提出敏感度感知(Sensitivity Awareness, SA)概念,使模型能遵守预设的访问规则。同时,构建了名为ACCESS DENIED INC的基准测试环境用于评估SA能力。实验表明,模型在应对未经授权的数据请求时行为差异显著,对合法请求仍可有效响应。本工作为敏感度感知语言模型的评测奠定基础,并为企业级隐私导向AI系统提供优化思路。

原文摘要 · Abstract (English)

Large language models (LLMs) are increasingly becoming valuable to corporate data management due to their ability to process text from various document formats and facilitate user interactions through natural language queries. However, LLMs must consider the sensitivity of information when communicating with employees, especially given access restrictions. Simple filtering based on user clearance levels can pose both performance and privacy challenges. To address this, we propose the concept of sensitivity awareness (SA), which enables LLMs to adhere to predefined access rights rules. In addition, we developed a benchmarking environment called ACCESS DENIED INC to evaluate SA. Our experimental findings reveal significant variations in model behavior, particularly in managing unauthorized data requests while effectively addressing legitimate queries. This work establishes a foundation for benchmarking sensitivity-aware language models and provides insights to enhance privacy-centric AI systems in corporate environments.

大模型安全敏感度感知企业AI

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。