arXiv:2512.16059cs.CRcs.CL2025-12被引 6

首个检测大模型上下文学习隐私泄露的实证框架

ContextLeak: Auditing Leakage in Private In-Context Learning Methods

  • 用特制密探令牌插入敏感数据,通过针对性查询探测泄露
  • 发现隐私预算越大,泄露越严重,且现有方法多无法兼顾隐私与性能
  • 适合关注大模型隐私安全的研究者和应用开发者

上下文学习(ICL)已成为利用大语言模型适应特定任务的标准方法,通过在提示中提供任务相关的示例实现。然而,当这些示例包含敏感信息时,可靠的隐私保护机制至关重要,以防止模型输出中的意外信息泄露。尽管已有多种隐私保护方法被提出,但针对这些方法的审计研究仍较少。本文提出 ContextLeak,首个用于实证测量 ICL 中最坏情况信息泄露的框架。该框架采用密探插入策略,在敏感数据集中嵌入唯一可识别的标记,并设计针对性查询以检测其存在。我们在多种私有 ICL 技术上应用 ContextLeak,涵盖基于启发式提示的防御方法以及具有形式化保障的差分隐私方法。结果表明,ContextLeak 能可靠检测各类方法中的泄露现象,且泄露程度随理论隐私预算单调上升,为最坏情况隐私风险提供了实用信号。进一步分析显示,现有方法在隐私与效用之间权衡不佳,要么完全泄露敏感信息,要么严重损害性能。

原文摘要 · Abstract (English)

In-Context Learning (ICL) has become a standard technique for adapting Large Language Models (LLMs) to specialized tasks by supplying task-specific exemplars within the prompt. However, when these exemplars contain sensitive information, reliable privacy-preserving mechanisms are essential to prevent unintended leakage through model outputs. Many privacy-preserving methods have been proposed to protect against information leakage in this context, but there are fewer efforts on how to audit these methods. We introduce ContextLeak, the first framework to empirically measure the worst-case information leakage in ICL. ContextLeak uses canary insertion, embedding uniquely identifiable tokens in the sensitive dataset and crafting targeted queries to detect their presence. We apply ContextLeak across a range of private ICL techniques, including both heuristic prompt-based defenses and differentially private methods with formal guarantees. We show that ContextLeak reliably detects leakage across methods, and the leakage increases monotonically with the theoretical privacy budget, offering a practical signal of worst-case privacy risk. Our analysis further reveals that existing methods strike poor privacy-utility trade-offs, either completely leaking sensitive information or severely degrading performance.

隐私保护大模型差分隐私漏洞检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。