提出动态合规框架,解决大模型跨境数据隐私难题。
Cross-Border Data Security and Privacy Risks in Large Language Models and IoT Systems
- 按管辖权动态加密+自适应差分隐私+密码学证明
- 违规暴露率低于5%,零合规违规,模型效用超90%
- 适合跨国AI部署与合规团队参考
大型语言模型与物联网系统依赖全球分布的数据流,带来系统性安全与隐私挑战。数据跨境时受欧盟GDPR与中国PIPL等法律冲突影响,叠加模型记忆等技术漏洞,现有静态加密与数据本地化手段碎片化且被动。本文提出一种管辖权感知、隐私优先的设计架构,通过局部加密、自适应差分隐私及基于密码学证明的实时合规验证实现动态协同。多司法辖区模拟验证显示,该架构将未授权数据暴露率降至5%以下,实现零合规违规,模型效用保持在90%以上,计算开销可控。结果表明,主动集成管控可实现安全且全球合规的AI部署。
原文摘要 · Abstract (English)
The reliance of Large Language Models and Internet of Things systems on massive, globally distributed data flows creates systemic security and privacy challenges. When data traverses borders, it becomes subject to conflicting legal regimes, such as the EU's General Data Protection Regulation and China's Personal Information Protection Law, compounded by technical vulnerabilities like model memorization. Current static encryption and data localization methods are fragmented and reactive, failing to provide adequate, policy-aligned safeguards. This research proposes a Jurisdiction-Aware, Privacy-by-Design architecture that dynamically integrates localized encryption, adaptive differential privacy, and real-time compliance assertion via cryptographic proofs. Empirical validation in a multi-jurisdictional simulation demonstrates this architecture reduced unauthorized data exposure to below five percent and achieved zero compliance violations. These security gains were realized while maintaining model utility retention above ninety percent and limiting computational overhead. This establishes that proactive, integrated controls are feasible for secure and globally compliant AI deployment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。