建立首个差分隐私文本生成基准,揭示大模型私有生成中的隐私漏洞。
SynBench: A Benchmark for Differentially Private Text Generation
- 构建统一评估框架,包含标准指标与隐私审计,覆盖9个专业领域数据集。
- 实验证明隐私保护越强,生成文本质量越差,尤其当训练数据与目标数据差异大时。
- 首次发现预训练数据含私有数据会破坏隐私保证,适合研究隐私安全的学者。
基于差分隐私(DP)的合成文本生成成为跨机构、跨监管边界共享敏感数据的可靠方法,可有效控制重识别和成员推断风险。尽管大语言模型(LLM)表现良好,但现有评估存在设置不一、私有数据集未公开、预训练污染未考虑及隐私保证缺乏验证等问题。为此,我们提出一个统一评估框架,包含标准化的效用与保真度指标以及隐私审计,涵盖九个具有领域特性的数据集,涵盖技术术语、长上下文依赖与专有文档结构。在大规模实证研究中,我们对1–80亿参数的主流DP文本生成模型进行了基准测试。结果表明,差分隐私合成文本生成仍是未解难题,生成质量随私有数据与生成器预训练语料差异增大而显著下降。我们提出的新型合成数据成员推断攻击(MIA)解释了这一现象:当模型在部分待生成的私有数据上进行无差分隐私的预训练时,会高估生成数据质量。最终,我们的工作首次提供了定量证据,证明‘公共预训练+私有生成’范式会破坏真实私有数据的隐私保障边界。
原文摘要 · Abstract (English)
Synthetic text generation with Differential Privacy (DP) guarantees emerges as a principled approach that can enable the sharing of sensitive datasets across institutional and regulatory boundaries, while bounding the risks of re-identification and membership inference. LLM-based methods deliver promising results; however, comparisons are exacerbated by differing evaluation setups and "private" datasets, potential pre-training contamination is not considered and guarantees are not verified with DP audits. To advance this field, we introduce a unified evaluation framework with standardised utility and fidelity metrics and privacy audits, encompassing nine curated datasets that capture domain-specific complexities such as technical jargon, long-context dependencies, and specialised document structures. In a large-scale empirical study, we benchmark LLM-based state-of-the-art DP text generators of varying sizes (between 1--8B). Our results indicate that DP synthetic text generation remains an unsolved challenge, with quality deteriorating more as the private datasets deviate further from the generators' pre-training corpora. Our novel synthetic text membership inference attack (MIA) explains this observation: Synthetic data quality is overestimated when LLMs have been pre-trained -- without DP -- on portions of the "private" data to be generated. Finally, our work provides the first quantitative evidence that this "public pre-training and private generation" paradigm invalidates the guaranteed privacy bounds of real-world private datasets.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。