须知:基于语境完整性的隐私意识LLM委托查询重写
Need to Know: Contextual-Integrity-Grounded Query Rewriting for Privacy-Conscious LLM Delegation
查看机构详情
- Sun Yat-sen University(中山大学)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
针对LLM委托中查询隐私泄露问题,提出基于语境完整性的查询重写框架,通过CI引导的强化学习训练重写器,在保留任务关键信息的同时抑制非必要敏感披露,实现最佳隐私-效用权衡。
中文摘要 AI 辅助
随着LLM日益融入日常工作流程,发送到云端LLM的用户查询通常混合了任务必需内容和任务非必需的敏感披露,但基于类型的PII编辑是上下文无关的,可能引发两个问题:过度披露未类型化的敏感上下文和过度移除承载答案的片段。我们在语境完整性下重新定义隐私保护查询重写:只有当某个片段对任务必要时才应转发。我们引入了DelegateCI-Bench,这是首个基于任务的语境完整性基准,用于隐私意识委托,包含3,167个样本,结合了涵盖11个任务和20种任务类型的高质量合成数据、基于WildChat的真实用户查询以及一个包含密集敏感信息的医学挑战集。基于此基准,我们提出了一个CI引导的强化学习框架,将必要和非必要的敏感片段转化为可验证的优化信号,并训练一个查询重写器,以保留任务关键信息同时抑制不必要的敏感披露。实验表明,我们学习的重写器实现了最佳的隐私-效用权衡,与设备端基线相比,平均效用提升高达+10.1。
英文摘要
As LLMs become increasingly woven into everyday workflows, user queries sent to cloud hosted LLMs routinely mix task-essential content with task non-essential sensitive disclosures, yet type based PII redaction is context agnostic and may raise two issues: over disclosing untyped sensitive context and over removing answer bearing spans. We recast privacy preserving query rewriting under Contextual Integrity: a span should be forwarded only if it is necessary for the task. We introduce DelegateCI-Bench, the first task based Contextual Integrity benchmark for privacy-conscious delegation, comprising 3,167 samples that combine high quality synthetic data spanning 11 tasks and 20 task types, WildChat based real user queries, and a medical challenge set with dense sensitive information. Building on this benchmark, we propose a CI-guided reinforcement learning framework that converts essential and non-essential sensitive spans into verifiable optimization signals, and train a query rewriter to preserve task critical information while suppressing unnecessary sensitive disclosure. Experiments show that our learned rewriter achieves the best privacy-utility tradeoff, achieving up to +10.1 average utility over on-device baselines.