arXiv:2506.12241cs.AIcs.LG2025-06NeurIPS被引 14

让大模型在模糊情境中更准判断该不该透露隐私信息

Privacy Reasoning in Ambiguous Contexts

  • 通过分析模型推理过程发现上下文模糊是隐私判断失误主因
  • 用新框架Camber系统消歧后,准确率最高提升22.3%、精确率升13.3%
  • 适合研究智能体隐私安全或提示工程的开发者参考

我们研究语言模型在信息披露决策中的隐私推理能力——这是智能体隐私领域的重要课题。以往工作多关注模型是否符合人类判断,本文则聚焦模糊与缺失上下文对模型表现的影响。我们发现上下文模糊是隐私评估高精度的主要障碍。为此设计了Camber框架,用于上下文消歧:模型生成的决策理由可揭示模糊点,基于这些理由系统性地消除歧义,使隐私判断的精确度最高提升13.3%,召回率最高提升22.3%,同时显著降低对提示敏感度。结果表明,上下文消歧是提升智能体隐私推理能力的可行方向。

原文摘要 · Abstract (English)

We study the ability of language models to reason about appropriate information disclosure - a central aspect of the evolving field of agentic privacy. Whereas previous works have focused on evaluating a model's ability to align with human decisions, we examine the role of ambiguity and missing context on model performance when making information-sharing decisions. We identify context ambiguity as a crucial barrier for high performance in privacy assessments. By designing Camber, a framework for context disambiguation, we show that model-generated decision rationales can reveal ambiguities and that systematically disambiguating context based on these rationales leads to significant accuracy improvements (up to 13.3% in precision and up to 22.3% in recall) as well as reductions in prompt sensitivity. Overall, our results indicate that approaches for context disambiguation are a promising way forward to enhance agentic privacy reasoning.

隐私推理上下文消歧大模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。