arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

揭秘大语言模型交互中的隐私-效用权衡

Demystifying the Privacy-Utility Trade-off in LLM Interactions

Zhenhua Liu, Zhanxu Xie, Junjie Yu, Tong Zhu, Lijun Li, Wenliang Chen

arXiv 2609.10992首次发表:更新:

发表机构

Soochow University; Beihang University; Suzhou City University; Shanghai Key Lab of Intelligent Information Processing; Shanghai AI Lab(苏州大学; 北京航空航天大学; 苏州城市学院; 上海市智能信息处理重点实验室; 上海人工智能实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过系统分析揭示大语言模型交互中隐私-效用权衡的三种机制,并提出意图驱动的本地保护框架,利用轻量级模型Veilmind-4B实现低泄漏与高效用,推进帕累托前沿。

AI 中文摘要

大语言模型融入日常任务依赖于上下文丰富的指令,这不可避免地会暴露用户的敏感信息。当前的隐私保护方法通常采用与上下文无关的静态规则,导致严重的效用退化。然而,关于净化如何影响下游性能的具体机制在很大程度上仍未得到充分探索。为解决这一问题,我们进行了系统分析以解构隐私-效用权衡,揭示了三种底层机制:(1)上下文依赖效用,该机制首先通过揭示数据价值根据用户意图从关键约束转变为可丢弃噪声,确定了何时进行净化;(2)策略性适应,该机制随后通过规定移除与替换之间的选择取决于任务对事实完整性相对于结构连贯性的依赖,确定了如何进行净化;(3)组合交互,该机制最后通过证明属性构成一个具有协同依赖或拮抗冗余的语义网络,扩展了保护范围。在这些见解的指导下,我们引入了一个意图驱动的本地保护框架。通过蒸馏轻量级模型Veilmind-4B来驱动动态提取-净化-恢复流水线,我们的方法达到了低泄漏隐私点,同时相比现有面向隐私的基线保留了显著更高的响应效用,将隐私-效用权衡推向帕累托前沿。

英文摘要

The integration of Large Language Models into daily tasks relies on context-rich instructions, inevitably exposing sensitive user information. Current privacy-preserving methods typically employ context-agnostic static rules, causing severe utility degradation. However, the specific mechanisms governing how sanitization impacts downstream performance remain largely underexplored. To address this, we conduct a systematic analysis to deconstruct the privacy-utility trade-off, uncovering three underlying mechanisms: (1) Context-Dependent Utility, which first establishes when to sanitize by revealing that data value shifts from critical constraints to dispensable noise based on user intent; (2) Strategic Adaptation, which subsequently determines how to sanitize by dictating that the choice between removal and replacement depends on the task's reliance on factual integrity versus structural coherence; and (3) Combinatorial Interplay, which finally extends the protection scope by demonstrating that attributes form a semantic web of synergistic dependencies or antagonistic redundancies. Guided by these insights, we introduce an intent-driven local protection framework. By distilling a lightweight model Veilmind-4B to drive a dynamic extraction-sanitization-restoration pipeline, our approach reaches a low-leakage privacy point while preserving substantially higher response utility than existing privacy-oriented baselines, advancing the privacy-utility trade-off toward the Pareto frontier.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑