提出新方法评估文本重写中的隐私泄露,让不同保护机制可比。
Beyond Theoretical Bounds: Empirical Privacy Loss Calibration for Text Rewriting Under Local Differential Privacy
- 用假设检验框架在表层和嵌入空间审计文本可区分性,实现隐私泄露实测
- 发现相同ε值下不同机制的可区分性差异巨大,说明理论ε不可靠
- 适合关注隐私-效用权衡的模型开发者和部署者使用
大语言模型的广泛应用推动了对隐私保护文本数据共享的需求。一种主流方法是在本地差分隐私(LDP)下进行文本重写,即在发布前对输入文本进行本地扰动以获得形式化隐私保证。这些保证通常由参数ε表示,用于界定最坏情况下的隐私损失。然而,名义上的ε值往往难以理解且跨机制无法比较。本文研究如何在LDP下的文本重写机制间进行经验校准,提出TeDA方法:通过假设检验框架,在表面空间和嵌入空间中实例化文本可区分性审计,实现对隐私化文本不可区分性的实证评估。对多个代表性机制的应用表明,相似的名义ε值可能对应截然不同的可区分性水平。因此,经验校准为评估隐私-效用权衡提供了更可比的基础,并成为真实世界LDP文本重写部署中机制比较与分析的实用工具。
原文摘要 · Abstract (English)
The growing use of large language models has increased interest in sharing textual data in a privacy-preserving manner. One prominent line of work addresses this challenge through text rewriting under Local Differential Privacy (LDP), where input texts are locally obfuscated before release with formal privacy guarantees. These guarantees are typically expressed by a parameter $\varepsilon$ that upper bounds the worst-case privacy loss. However, nominal $\varepsilon$ values are often difficult to interpret and compare across mechanisms. In this work, we investigate how to empirically calibrate across text rewriting mechanisms under LDP. We propose TeDA, which formulates calibration via a hypothesis-testing framework that instantiates text distinguishability audits in both surface and embedding spaces, enabling empirical assessment of indistinguishability from privatized texts. Applying this calibration to several representative mechanisms, we demonstrate that similar nominal $\varepsilon$ bounds can imply very different levels of distinguishability. Empirical calibration thus provides a more comparable footing for evaluating privacy-utility trade-offs, as well as a practical tool for mechanism comparison and analysis in real-world LDP text rewriting deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。