arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

感知去噪的反演:揭示受噪声保护的文本嵌入中的隐私风险

Denoising-Aware Inversion: Revealing Privacy Risks in Noise-Protected Text Embeddings

Yubo Wang, Shujie Cui, James Bailey, Hongzhi Yin, Wenyu Liang, Min Tang, Shiyue Qin, Weiqing Wang

arXiv 2608.18610首次发表:更新:

发表机构

Monash University; The University of Queensland; Northeastern University(莫纳什大学; 昆士兰大学; 东北大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文针对受噪声保护的文本嵌入,提出感知去噪的反演方法DAEI,突破双重噪声陷阱,在反演性能上大幅优于基线,挑战了高斯扰动可防嵌入隐私泄露的假设。

AI 中文摘要

稠密文本嵌入因具有紧凑且语义丰富的表示,被广泛应用于数据挖掘、检索及下游机器学习系统,但近期的嵌入反演攻击表明,这类嵌入可暴露原始文本的大量信息,引发严重的隐私泄露风险。一种常见的防御手段是添加高斯噪声后发布扰动嵌入,该方法简单却能有效抵御标准反演攻击,且不会显著降低嵌入对下游任务的实用性。然而,目前尚不清楚这类受噪声保护的嵌入是否足以抵御明确考虑扰动过程的自适应攻击者。本文研究受噪声保护场景下的文本嵌入反演问题,其中攻击者仅能观测到带噪声的嵌入,无法获取干净的嵌入目标。我们首先分析现有生成式反演方法在该场景下失效的原因,确定了“双重噪声陷阱”,该陷阱从根本上阻碍了标准生成式反演模型实现高质量重构。为应对这一挑战,我们提出DAEI,一种感知去噪的嵌入反演流程,该流程将残差去噪自编码器与生成式文本反演相结合,其中去噪器通过 Stein 无偏风险估计以无监督方式训练,仅用带噪声的观测值即可实现去噪。大量实验表明,DAEI 相较于现有生成式反演基线在 BLEU 指标上实现了约 154% 的相对提升,同时将标记级 F1 和 ROUGE-L 指标提升了 32% 至 60%。DAEI promising 的反演性能对“简单高斯扰动足以防止嵌入表示中的敏感信息泄露”这一普遍假设提出了挑战。

英文摘要

Dense text embeddings are widely used in data mining, retrieval, and downstream machine learning systems due to their compact and semantically rich representations, but recent embedding inversion attacks have shown that they can expose substantial information about the original text, leading to serious privacy leakage risks. A common defense is to release perturbed embeddings by adding Gaussian noise, which is simple yet effective against standard inversion attacks and does not significantly degrade embedding utility for downstream tasks. However, it remains unclear whether such noise-protected embeddings are sufficiently safe against adaptive attackers that explicitly account for the perturbation process. In this paper, we study text embedding inversion in a noise-protected setting, where the attacker can observe only noisy embeddings and has no access to clean embedding targets. We first analyze why existing generative inversion methods fail under this setting and identify a "Double Noise Trap", which fundamentally prevents standard generative inversion models from achieving high-quality reconstruction. To address this challenge, we propose DAEI, a denoising-aware embedding inversion pipeline that combines a residual denoising autoencoder with generative text inversion where the denoiser is trained in an unsupervised manner using Stein's unbiased risk estimate to enable denoising from noisy observations alone. Extensive experiments show that DAEI achieves approximately 154\% relative improvement in BLEU over the existing generative inversion baseline, while also improving token-level F1 and ROUGE-L by 32--60\%. The promising inversion performance of DAEI challenges the prevailing assumption that simple Gaussian perturbation is sufficient to prevent sensitive information leakage from embedding representations.

Comments11 pages, 3 figures. Accepted by IEEE ICDM 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑