arXiv:2604.21211cs.CL2026-04ACL

首次以个人为单位评估文本匿名化,发现90%信息遮蔽仍难防隐私泄露。

Subject-level Inference for Realistic Text Anonymization Evaluation

论文配图:Subject-level Inference for Realistic Text Anonymization Evaluation
图 1 · 摘自论文原文
  • 以个人而非文本片段为评估单位,更贴近真实攻击场景
  • 即使90%敏感信息被遮蔽,仍有超6成个人身份可被推断
  • 聚焦特定目标的匿名化反而让其他人暴露更多

当前文本匿名化评估依赖基于片段的指标,无法反映攻击者实际能推断的信息,且假设单一数据主体,忽略多主体场景。为此,我们提出SPIA(Subject-level PII Inference Assessment),首个将评估单位从文本片段转向个体的基准,包含675份法律与在线领域文档,并引入新型个体级保护度量。大量实验表明,即使超过90%的PII片段被遮蔽,个体级推理保护率仍低至33%,多数个人信息仍可通过上下文推断恢复。此外,针对特定目标的匿名化会使非目标主体暴露程度显著高于目标主体。结果表明,基于个体推理的评估对保障真实场景下文本匿名化安全至关重要。

原文摘要 · Abstract (English)

Current text anonymization evaluation relies on span-based metrics that fail to capture what an adversary could actually infer, and assumes a single data subject, ignoring multi-subject scenarios. To address these limitations, we present SPIA (Subject-level PII Inference Assessment), the first benchmark that shifts the unit of evaluation from text spans to individuals, comprising 675 documents across legal and online domains with novel subject-level protection metrics. Extensive experiments show that even when over 90% of PII spans are masked, subject-level inference protection drops as low as 33%, leaving the majority of personal information recoverable through contextual inference. Furthermore, target-subject-focused anonymization leaves non-target subjects substantially more exposed than the target subject. We show that subject-level inference-based evaluation is essential for ensuring safe text anonymization in real-world settings.

隐私保护匿名化评估推理攻击数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。