六家大模型公司默认用用户聊天数据训练模型,隐私政策透明度不足。
User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies
- 基于加州隐私法构建编码框架,分析六家美国前沿公司政策。
- 所有公司默认使用聊天数据训练模型,部分无限期保留敏感信息。
- 涉及儿童数据与跨产品数据,建议加强监管与透明度设计。
数亿人通过聊天机器人频繁使用大语言模型。为提升模型能力并争夺市场份额,模型开发者积极获取高质量训练数据。本文分析六家美国前沿AI开发者的隐私政策,探究其如何利用用户聊天数据训练模型。主要依据《加州消费者隐私法》(CCPA),构建新颖的定性编码框架,对各公司相关隐私政策进行比较分析。结果发现,六家公司均默认将用户聊天数据用于模型训练与优化,部分公司无限期保留这些数据。开发者可能收集并训练包含生物特征、健康信息等敏感内容的聊天数据,以及用户上传的文件。四家公司明确包含儿童聊天数据及其它产品客户数据用于训练。整体来看,开发者隐私政策普遍缺乏关键实践细节,凸显透明度与问责机制的缺失。本文探讨了用户未授权即被用于训练带来的隐私风险、无限期数据留存引发的安全隐患,以及针对儿童数据训练的伦理问题,并向政策制定者与开发者提出改进建议。
原文摘要 · Abstract (English)
Hundreds of millions of people now regularly interact with large language models via chatbots. Model developers are eager to acquire new sources of high-quality training data as they race to improve model capabilities and win market share. This paper analyzes the privacy policies of six U.S. frontier AI developers to understand how they use their users' chats to train models. Drawing primarily on the California Consumer Privacy Act, we develop a novel qualitative coding schema that we apply to each developer's relevant privacy policies to compare data collection and use practices across the six companies. We find that all six developers appear to employ their users' chat data to train and improve their models by default, and that some retain this data indefinitely. Developers may collect and train on personal information disclosed in chats, including sensitive information such as biometric and health data, as well as files uploaded by users. Four of the six companies we examined appear to include children's chat data for model training, as well as customer data from other products. On the whole, developers' privacy policies often lack essential information about their practices, highlighting the need for greater transparency and accountability. We address the implications of users' lack of consent for the use of their chat data for model training, data security issues arising from indefinite chat data retention, and training on children's chat data. We conclude by providing recommendations to policymakers and developers to address the data privacy challenges posed by LLM-powered chatbots.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。