Truthful Text Sanitization Guided by Inference Attacks

πŸ“… 2024-12-17
πŸ›οΈ arXiv.org
πŸ“ˆ Citations: 1
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
Text anonymization must balance privacy preservation with semantic utility. This paper proposes an automated anonymization method based on abstraction-based generalization: first, instruction-tuned large language models (LLMs) generate fidelity-preserving substitution candidates and rank them by abstraction level; second, an LLM-driven inference attack simulation quantifies each candidate’s resistance to re-identification; finally, authenticity, abstraction, and privacy robustness are jointly optimized to select the optimal substitution. Key contributions include: (i) the first integration of inference attacks into the anonymization decision loop; (ii) a novel, annotation-free metric jointly evaluating utility and privacy; and (iii) end-to-end multi-objective co-optimization. On the Text Anonymization Benchmark, our method achieves significantly higher utility than baselines, incurs only marginally higher re-identification risk than full suppression, and yields substitutions with superior fidelity and abstraction.

Technology Category

Machine Learning: PrivacyNatural Language Processing: Safety and RobustnessSearch and Optimization: Learning to Search

Application Category

User Modeling, Personalization and Recommendation: User privacy protection in personalized systemsSecurity and Privacy: Large-scale security measurementsSearch and Retrieval-Augmented AI: Web learning to rank, online learning, and counterfactual learning for ranking
πŸ“ Abstract
The purpose of text sanitization is to rewrite those text spans in a document that may directly or indirectly identify an individual, to ensure they no longer disclose personal information. Text sanitization must strike a balance between preventing the leakage of personal information (privacy protection) while also retaining as much of the document's original content as possible (utility preservation). We present an automated text sanitization strategy based on generalizations, which are more abstract (but still informative) terms that subsume the semantic content of the original text spans. The approach relies on instruction-tuned large language models (LLMs) and is divided into two stages. The LLM is first applied to obtain truth-preserving replacement candidates and rank them according to their abstraction level. Those candidates are then evaluated for their ability to protect privacy by conducting inference attacks with the LLM. Finally, the system selects the most informative replacement shown to be resistant to those attacks. As a consequence of this two-stage process, the chosen replacements effectively balance utility and privacy. We also present novel metrics to automatically evaluate these two aspects without the need to manually annotate data. Empirical results on the Text Anonymization Benchmark show that the proposed approach leads to enhanced utility, with only a marginal increase in the risk of re-identifying protected individuals compared to fully suppressing the original information. Furthermore, the selected replacements are shown to be more truth-preserving and abstractive than previous methods.
Problem

Research questions and friction points this paper is trying to address.

Balancing privacy protection and content utility in text sanitization
Preventing personal information leakage while preserving document semantics
Developing truth-preserving replacements resistant to inference attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Two-stage LLM generalization for text sanitization
Instruction-tuned models generate truth-preserving replacements
Inference attack evaluation ensures privacy protection
πŸ”Ž Similar Papers
No similar papers found.
πŸ’Ό Related Jobs
No related jobs found.
Norwegian Computing Center | Universitat Rovira i Virgili
I
Ildik'o Pil'an
Norwegian Computing Center, Postboks 114 Blindern, Oslo, NO-0314, Norway
Benet Manzanares-Salor
Benet Manzanares-Salor
Department of Computer Engineering and Mathematics. CYBERCAT., Universitat Rovira i Virgili, Tarragona, 43007, Spain
D
David S'anchez
Department of Computer Engineering and Mathematics. CYBERCAT., Universitat Rovira i Virgili, Tarragona, 43007, Spain
Pierre Lison
Pierre Lison
Chief Research Scientist, Norsk Regnesentral
Natural Language ProcessingMachine LearningSpoken Dialogue SystemsMultilingual NLPLanguage