LLM能复原隐私文本,也能提升隐私保护效果。
The Double-edged Sword of LLM-based Data Reconstruction: Understanding and Mitigating Contextual Vulnerability in Word-level Differential Privacy Text Sanitization
- 用大模型攻击差分隐私文本,发现上下文漏洞
- 大模型复原原文语义,但也能改善隐私与质量
- 建议将大模型作为后处理工具增强隐私防护
差分隐私文本净化是在差分隐私框架下对文本进行隐私化处理,提供可证明的隐私保障,并在实践中抵御隐私攻击。尽管方法简单,词级别差分隐私文本净化仍存在诸多缺陷,尤其在随机化过程中会留下原始文本的上下文线索——我们称之为‘上下文脆弱性’。鉴于大语言模型(LLMs)强大的上下文理解与推理能力,本文探究其是否可利用此类脆弱性重构原始文本。我们不仅引入先进的大模型,还测试了多种不同隐私水平下的净化机制。实验揭示了基于大模型的数据重建攻击的双重效应:一方面,大模型可还原原始语义,削弱实际隐私保护;另一方面,也可用于优化净化后的文本质量与隐私性。基于此,我们提出建议:将大模型重建作为后处理步骤,通过对抗性思维增强隐私保护。
原文摘要 · Abstract (English)
Differentially private text sanitization refers to the process of privatizing texts under the framework of Differential Privacy (DP), providing provable privacy guarantees while also empirically defending against adversaries seeking to harm privacy. Despite their simplicity, DP text sanitization methods operating at the word level exhibit a number of shortcomings, among them the tendency to leave contextual clues from the original texts due to randomization during sanitization $\unicode{x2013}$ this we refer to as $\textit{contextual vulnerability}$. Given the powerful contextual understanding and inference capabilities of Large Language Models (LLMs), we explore to what extent LLMs can be leveraged to exploit the contextual vulnerability of DP-sanitized texts. We expand on previous work not only in the use of advanced LLMs, but also in testing a broader range of sanitization mechanisms at various privacy levels. Our experiments uncover a double-edged sword effect of LLM-based data reconstruction attacks on privacy and utility: while LLMs can indeed infer original semantics and sometimes degrade empirical privacy protections, they can also be used for good, to improve the quality and privacy of DP-sanitized texts. Based on our findings, we propose recommendations for using LLM data reconstruction as a post-processing step, serving to increase privacy protection by thinking adversarially.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。