Score
Designs and implements systems — including ML models, rule-based engines, and annotation schemas — that detect, label, and segment sensitive information in structured and unstructured datasets (for example personally identifiable information, health data, credentials, or confidential text). Evaluates and analyzes classifier performance and label quality, builds ingestion/annotation/deployment pipelines, and incorporates privacy-preserving and compliance controls for handling labeled sensitive data.
Existing sensitive data detection methods predominantly focus on personally identifiable information (PII), overlooking the contextual dependency of data sensitivity. This paper proposes a novel context-aware paradigm for sensitive data detection, introducing— for the first time—type contextualization and domain contextualization mechanisms. The approach integrates semantic type identification, document-level contextual modeling, sensitive rule retrieval, and large language model (LLM)-driven reasoning into an end-to-end detection framework. Evaluated on non-standard data domains—such as humanitarian datasets—the method achieves a 94% recall in type contextualization, outperforming commercial tools by 31 percentage points. Domain contextualization significantly enhances adaptability to complex, real-world scenarios. Furthermore, LLM-generated interpretive explanations substantially improve inter-annotator agreement during manual review. Collectively, this work advances sensitive data detection by grounding sensitivity assessment in rich, multi-granular contextual signals rather than static, syntax-driven patterns.
This study addresses the challenge of balancing data availability for cybercrime analysis with privacy protection under regulations such as the GDPR by proposing an end-to-end multimodal data processing pipeline. The pipeline integrates speech enhancement, high-precision named entity recognition (NER), and structure-preserving anonymization techniques to construct a compliant dataset from Telegram-collected text, audio, and images. Experimental results demonstrate that the Parakeet model achieves optimal speech transcription performance, while the proposed Transformer-based NER approach attains the highest F1 score in identifying sensitive information. Furthermore, the anonymized data retains essential semantic structures while satisfying regulatory compliance requirements, thereby effectively supporting research on social engineering attack detection.
Existing social media sensitive content detection tools suffer from limited customizability, narrow category coverage—particularly lacking long-tail classes such as drug-related and self-harm content—high privacy risks, and the absence of a unified evaluation benchmark. To address these issues, this work introduces the first high-quality, uniformly annotated dataset covering six sensitive content categories: conflict language, abuse, pornography, drug-related content, self-harm, and spam. We establish standardized protocols for data collection and human annotation. Leveraging this dataset, we supervise fine-tuning of open-source large language models (e.g., LLaMA) and design a comprehensive, multi-dimensional evaluation benchmark. Experimental results demonstrate that our approach consistently outperforms both the LLaMA baseline and the OpenAI API across all six detection tasks, achieving average improvements of 10–15%. Gains are especially pronounced for scarce categories (e.g., drug-related and self-harm content), validating the effectiveness and deployability of open-source LLM fine-tuning for fine-grained sensitive content identification.
To address copyright infringement and transparency concerns arising from unauthorized use of third-party data in machine learning model training, this paper proposes the first general-purpose, task-agnostic data usage auditing framework for black-box models. Methodologically, it innovatively integrates arbitrary black-box membership inference techniques with a custom sequential probability ratio test (SPRT), enabling zero assumptions about downstream tasks, strict control over false positive rates (tunable within 0.5%–5%), and cross-model generalization. The framework features a model-agnostic interface, supporting heterogeneous architectures including image classifiers and multimodal large language models. Extensive experiments on ImageNet classifiers and multimodal foundation models demonstrate an average detection accuracy exceeding 92%, with false positive rates consistently meeting user-specified thresholds. This work significantly enhances the quantifiability and reliability of training data provenance auditing.
Existing privacy research is fragmented across isolated technical domains (e.g., CV, NLP, networking), failing to address real-world, cross-contextual privacy concerns. Method: We propose a human-centered privacy modeling framework grounded in Contextual Integrity (CI) theory—first systematically integrating CI into large language models (LLMs). Our approach constructs the first multi-ontology privacy checklist incorporating social identities, sensitive attributes, and the full HIPAA regulatory framework. Leveraging expert-annotated, multi-source ontology fusion, it extends beyond traditional PII definitions to enable context-aware, human-interpretable privacy assessment. Contribution/Results: Experiments demonstrate LLMs’ efficacy in structured regulatory comprehension and context-sensitive privacy reasoning. Our framework establishes a novel paradigm for generalizable, cross-domain privacy risk identification—bridging theoretical privacy principles with scalable, deployable AI-driven assessment.
High-risk NLP systems—particularly in healthcare, finance, and public administration—face critical challenges stemming from inadequate security, privacy, and regulatory compliance governance. To address this gap, we propose SC-NLP-LMF, the first framework integrating NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001, the EU AI Act, and MITRE ATLAS to establish a six-stage, end-to-end lifecycle governance paradigm spanning development, deployment, monitoring, adaptation, decommissioning, and retirement. Our approach innovatively unifies terminology drift detection, compliance-driven dynamic model updating, and secure model retirement, augmented by differential privacy, federated learning, eXplainable AI (XAI), and bias auditing. Evaluated on a COVID-19 clinical NLP use case, SC-NLP-LMF successfully identified linguistic drift and enabled compliant iterative model refinement. The framework delivers actionable, cross-stage governance protocols that support accountable operations for high-risk NLP systems—bridging a pivotal gap at the intersection of RegTech and AI governance.
This study addresses the compliance challenges faced by data practitioners in machine learning systems under regulations such as the GDPR and the AI Act, particularly concerning data quality. Through semi-structured interviews with practitioners in the European Union, combined with thematic analysis of regulatory texts and engineering workflows, the research systematically uncovers a structural disconnect between regulation-driven data quality requirements and ML engineering practices. It identifies five core challenges: misalignment between legal principles and engineering implementation, fragmented data pipelines, lack of purpose-built compliance tools, ambiguous accountability, and reactive responses to audits. Building on these findings, the work proposes directions for designing compliance-oriented tooling, establishing effective governance mechanisms, and fostering cultural transformation to bridge the gap between regulatory mandates and practical ML development.
This work addresses the challenge of contextual privacy leakage in retrieval-augmented generation (RAG) systems caused by unconventional combinations of personally identifiable information (PII) attributes, which existing PII filters struggle to mitigate. The authors propose T3+OCSVM, a privacy policy enforcement framework that integrates textual embeddings with one-class support vector machine (OCSVM) density estimation, enhanced by a calibrated rejection region to robustly handle out-of-distribution inputs. A hierarchical, axis-aligned multi-LLM synthetic data pipeline is developed for training and validation. Under boundary security stress tests, the method achieves an AUROC exceeding 0.93 and reduces false positive rates by 44–55 percentage points compared to baselines, while maintaining millisecond-level latency. These results demonstrate substantial improvements over supervised classifiers and LLM-based adjudication approaches, offering both high detection efficacy and practical deployability.
This study identifies critical privacy risks in large language model (LLM) development, including opaque data collection practices, unauthorized use of children’s data, inadequate handling of sensitive information, and indefinite retention of user chat data—stemming from industry-wide default assumptions that user inputs may be used for model training. Method: Leveraging the California Consumer Privacy Act (CCPA), we develop the first qualitative coding framework tailored to LLM training contexts and conduct a cross-sectional content analysis and legal interpretation of privacy policies from six leading AI companies. Contribution/Results: We systematically demonstrate that none provide an effective opt-out mechanism for training data usage; four explicitly process children’s data; five impose no storage duration limits; and all employ ambiguous language while concealing key data practices. The framework serves as an actionable assessment tool for regulators and informs industry-wide reform toward “collection-by-exception” and purpose limitation principles.
The deployment of large language models (LLMs) in high-stakes domains—such as law, healthcare, and finance—introduces underexplored compliance risks, including sensitive information leakage, intellectual property infringement, and uncontrolled outputs; existing NLP tools lack domain-specific compliance adaptation. Method: Through semi-structured interviews and qualitative analysis with frontline domain experts, we systematically identify real-world risk perceptions and emergent mitigation strategies, uncovering a structural misalignment between current tools and human-centered compliance requirements. Contribution/Results: We propose a human-centered RegTech compliance design framework for LLM-based NLP systems, centered on three core mechanisms: sensitive data protection, intellectual property security, and output quality controllability. This framework provides empirically grounded, actionable design principles to support the development of compliance-embedded NLP systems.