用公开数据提升私有上下文学习的性能与安全性
Public Data Assisted Differentially Private In-Context Learning
- 引入任务相关公开数据增强私有上下文学习
- 在保持差分隐私的前提下显著提升模型效果
- 有效抵御成员推理攻击,适合隐私敏感场景
大型语言模型(LLM)的上下文学习(ICL)在无需微调的情况下展现出优异性能。然而,近期研究指出,通过提示词可能泄露私有数据,尤其在面对恶意攻击时风险更高。尽管差分隐私(DP)能提供强隐私保障,但常导致上下文学习效用大幅下降。为此,本文在保持差分隐私的前提下,将任务相关的公开数据融入ICL框架,提出一种新的私有上下文学习算法,有效平衡隐私保护与模型性能。实验表明,该方法在公开数据辅助下显著提升了私有ICL的实用性,且对成员推理攻击具有鲁棒性,验证了其实际隐私保护能力。
原文摘要 · Abstract (English)
In-context learning (ICL) in Large Language Models (LLMs) has shown remarkable performance across various tasks without requiring fine-tuning. However, recent studies have highlighted the risk of private data leakage through the prompt in ICL, especially when LLMs are exposed to malicious attacks. While differential privacy (DP) provides strong privacy guarantees, it often significantly reduces the utility of in-context learning (ICL). To address this challenge, we incorporate task-related public data into the ICL framework while maintaining the DP guarantee. Based on this approach, we propose a private in-context learning algorithm that effectively balances privacy protection and model utility. Through experiments, we demonstrate that our approach significantly improves the utility of private ICL with the assistance of public data. Additionally, we show that our method is robust against membership inference attacks, demonstrating empirical privacy protection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。