我是无名之辈:面向文本匿名化的风格感知改写
I Am No One: Style-Aware Paraphrasing for Text Anonymization
- RMIT University(皇家墨尔本理工大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
提出风格感知提示驱动的文本匿名化方法,利用大语言模型构建风格画像并改写文本,在博客和评论数据集上将作者归属F1降低60-70%,同时保持内容质量。
AI中文摘要:
作者归属模型能够利用稳定的风格指纹,从看似匿名的文本中重新识别用户身份,即使在显式标识符被移除后依然如此,这对文本发布和分析构成了日益增长的隐私风险。这一风险同样延伸到语音衍生文本,例如会议和呼叫中心对话的ASR转录,其中风格度量泄漏即使在声学匿名化后仍可能持续存在。基于差分隐私的匿名化方法往往严重降低文本质量和效用。我们提出了一种风格感知的、提示驱动的匿名化方法,利用预训练的大语言模型从最少样本中构建紧凑的风格画像,并重写文本以抑制可识别的风格标记,同时保留语义。在博客和评论数据集上,我们的方法将作者归属F1分数降低了60-70%,同时保持了内容质量和可读性,显著优于基于DP和非DP的基线方法。
英文摘要:
Authorship attribution models can re-identify users from seemingly anonymized text by exploiting stable stylistic fingerprints, even after explicit identifiers are removed, posing a growing privacy risk for text publishing and analytics. This risk extends to speech-derived text such as ASR transcripts of meetings and call-center conversations, where stylometric leakage can persist even after acoustic anonymization. Differential privacy-based anonymization often severely degrades text quality and utility. We propose a style-aware, prompt-driven anonymization approach that uses pretrained large language models to construct compact stylistic profiles from minimal samples and rewrite text to suppress identifiable style markers while preserving meaning. Across blog and review datasets, our approach reduces authorship attribution F1 by 60-70% while maintaining content quality and readability, substantially outperforming DP-based and non-DP baselines.