Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees

📅 2026-09-18
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决文本发布中的身份泄露问题,提出了一种基于统计保证的校准框架CPA,以评估针对大语言模型增强攻击者的重新识别风险。
📝 Abstract
Empirical identity leakage from released text is increasingly driven by attackers that combine large language models (LLMs) with auxiliary knowledge to link documents to individuals. Existing audits typically report success rates for specific attack pipelines but lack finite-sample statistical guarantees, while training-time protections such as differential privacy are difficult to translate into release-time decisions for individual natural-language documents. We introduce Conformal Privacy Auditing(CPA), a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries. CPA outputs a conformal ambiguity set of candidate identities that is guaranteed to contain the true identity with user-chosen confidence under exchangeability, together with an interpretable leakage proxy derived from set size. CPA supports both logit-access and sampling-only attackers, enabling audits of open-source models and proprietary API models in a unified framework. Across multiple release benchmarks and attacker configurations, CPA achieves calibrated coverage and reveals sharp shifts in certified identifiability as auxiliary knowledge, LLM augmentation, and release mechanisms vary, providing a statistically grounded basis for reporting and comparing release-time linkage risk across attacker configurations, datasets, and release mechanisms alike.
Problem

Research questions and friction points this paper is trying to address.

Privacy Auditing
Re-identification Attacks
Statistical Guarantees
Large Language Models
Innovation

Methods, ideas, or system contributions that make the work stand out.

Conformal Privacy Auditing
Statistical Guarantees
Re-identification Risk
Large Language Models
Auxiliary Knowledge