构建文本匿名化评估基准,量化真实世界再识别风险
RAT-Bench: A Comprehensive Benchmark for Text Anonymization
- 基于美国人口统计生成带多类标识符的合成文本
- 发现顶级工具仍存在显著再识别风险,尤其在非标准写法时
- 支持跨语言评估,建议未来工具兼顾隐私与效率
随着包含个人信息的数据被广泛用于训练或查询大型语言模型(LLMs),文本匿名化成为关键挑战。现有工具如Microsoft Presidio和Anthropic PII Purifier主要针对特定标识符(如姓名)的移除能力进行评估,但其防止再识别的实际效果尚不明确。本文提出RAT-Bench,一个基于再识别风险的综合性文本匿名化基准。利用美国人口统计数据,生成涵盖多个领域、语言及难度级别的合成文本,包含直接与间接标识符。评估多种基于命名实体识别(NER)和大语言模型(LLM)的匿名化工具,并通过分析攻击者从匿名文本中正确推断出的属性,报告在美国人群中的再识别风险,同时考虑标识符的差异化影响。结果表明,尽管性能差异显著,即使最优工具在直接标识符非标准表达或间接标识符可引发再识别时仍表现不佳。总体而言,基于LLM的匿名化工具(包括新型迭代方法)在隐私-效用权衡上更优,尽管计算成本更高,且跨语言表现良好。最后,本文提出未来改进方向,并将公开基准,鼓励社区扩展至其他地理区域。
原文摘要 · Abstract (English)
Data containing personal information is increasingly used to train, fine-tune, or query Large Language Models (LLMs). Text is typically scrubbed of identifying information prior to use, often with tools such as Microsoft's Presidio or Anthropic's PII purifier. These tools have traditionally been evaluated on their ability to remove specific identifiers (e.g., names), yet their effectiveness at preventing re-identification remains unclear. We introduce RAT-Bench, a comprehensive benchmark for text anonymization tools based on re-identification risk. Using U.S. demographic statistics, we generate synthetic text containing various direct and indirect identifiers across domains, languages, and difficulty levels. We evaluate a range of NER- and LLM-based text anonymization tools and, based on the attributes an LLM-based attacker is able to correctly infer from the anonymized text, we report the risk of re-identification in the U.S. population, while properly accounting for the disparate impact of identifiers. We find that, while capabilities vary widely, even the best tools are far from perfect in particular when direct identifiers are not written in standard ways and when indirect identifiers enable re-identification. Overall we find LLM-based anonymizers, including new iterative anonymizers, to provide a better privacy-utility trade-off albeit at a higher computational cost. Importantly, we also find them to work well across languages. We conclude with recommendations for future anonymization tools and will release the benchmark and encourage community efforts to expand it, in particular to other geographies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。