arXiv:2506.23603cs.CRcs.AI2025-06被引 5

揭示大模型语义隐私风险,提出全生命周期防护框架

SoK: Semantic Privacy in Large Language Models

  • 构建输入到对齐各阶段的语义隐私风险分析框架
  • 发现上下文推理和隐表示泄露是主要防护短板
  • 适合关注大模型隐私安全的研究者与开发者

随着大语言模型在敏感领域广泛应用,传统数据隐私措施难以保护隐含、上下文或可推断的信息——即语义隐私。本文提出一种以生命周期为中心的系统化知识框架,分析大模型在输入处理、预训练、微调和对齐阶段中语义隐私风险的产生机制。我们分类了关键攻击向量,并评估差分隐私、嵌入加密、边缘计算和遗忘技术等现有防御手段的有效性。分析显示,当前方法在应对上下文推理和潜在表示泄露方面存在显著缺口。最后,本文提出若干开放挑战:量化语义泄漏程度、保护多模态输入、平衡去标识化与生成质量,以及确保隐私执行的透明性。本工作旨在为未来设计鲁棒、语义感知的隐私保护技术提供指导。

原文摘要 · Abstract (English)

As Large Language Models (LLMs) are increasingly deployed in sensitive domains, traditional data privacy measures prove inadequate for protecting information that is implicit, contextual, or inferable - what we define as semantic privacy. This Systematization of Knowledge (SoK) introduces a lifecycle-centric framework to analyze how semantic privacy risks emerge across input processing, pretraining, fine-tuning, and alignment stages of LLMs. We categorize key attack vectors and assess how current defenses, such as differential privacy, embedding encryption, edge computing, and unlearning, address these threats. Our analysis reveals critical gaps in semantic-level protection, especially against contextual inference and latent representation leakage. We conclude by outlining open challenges, including quantifying semantic leakage, protecting multimodal inputs, balancing de-identification with generation quality, and ensuring transparency in privacy enforcement. This work aims to inform future research on designing robust, semantically aware privacy-preserving techniques for LLMs.

语义隐私大模型安全隐私保护生命周期分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。