arXiv:2509.12152cs.HCcs.AI2025-09被引 3

用户难预测大模型隐式推断,改写效果有限但比工具好。

Beyond PII: How Users Attempt to Estimate and Mitigate Implicit LLM Inference

  • 用户通过改写文本试图阻止模型推断个人信息,主要用替换和重述。
  • 仅28%的用户改写有效,优于工具Rescriber但不如ChatGPT生成的。
  • 抽象化和增加模糊性更有效,而简单替代表达最不靠谱。

大型语言模型(如ChatGPT)能从看似无害的文本中推断出个人属性,带来超越记忆数据泄露的隐私风险。现有研究虽揭示了此类风险,但对用户如何评估与应对尚不清楚。本研究对240名美国参与者进行调查,要求其判断文本片段的推断风险、报告担忧程度,并尝试改写以阻断推断。将用户改写结果与ChatGPT及Rescriber(当前最先进的净化工具)对比。结果显示,参与者难以准确预判推断,表现仅略优于随机猜测。用户改写在28%的情况下有效——优于Rescriber,但不及ChatGPT。分析发现,虽然改写中最常见的是同义替换,但效果最差;相比之下,抽象化与引入模糊性策略更为成功。研究强调在大模型交互中需重视推断意识设计。

原文摘要 · Abstract (English)

Large Language Models (LLMs) such as ChatGPT can infer personal attributes from seemingly innocuous text, raising privacy risks beyond memorized data leakage. While prior work has demonstrated these risks, little is known about how users estimate and respond. We conducted a survey with 240 U.S. participants who judged text snippets for inference risks, reported concern levels, and attempted rewrites to block inference. We compared their rewrites with those generated by ChatGPT and Rescriber, a state-of-the-art sanitization tool. Results show that participants struggled to anticipate inference, performing a little better than chance. User rewrites were effective in just 28\% of cases - better than Rescriber but worse than ChatGPT. We examined our participants' rewriting strategies, and observed that while paraphrasing was the most common strategy it is also the least effective; instead abstraction and adding ambiguity were more successful. Our work highlights the importance of inference-aware design in LLM interactions.

LLM隐私文本改写推断防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。