GraphProfiler:通过个人知识图谱进行源关联的敏感属性推断
GraphProfiler: Source-Linked Sensitive Attribute Inference via Personal Knowledge Graphs
- RMIT University(皇家墨尔本理工大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
GraphProfiler提出基于LLM的可审计画像器,将用户帖子构建为源关联个人知识图谱,将属性预测解析为可引用的图谱记录和源文本,在SynthPAI和PANDORA基准上分别达到86.7%和84.6%的攻击成功率,并支持针对性的隐私缓解。
AI中文摘要:
年龄、收入和职业等敏感属性可以通过聚合许多普通帖子中的间接线索,从用户生成的内容中推断出来。基于LLM的画像器可以自动且高精度地执行这种聚合,这使得大规模个人属性推断成为一个重大的隐私威胁。然而,现有的基于LLM的画像器对哪些具体的帖子、概念和关系使得推断成为可能提供的洞察有限,而这对于有针对性的隐私缓解至关重要,即仅编辑或重写少数实际泄露属性的帖子,而不是扰动整个历史记录。我们引入了GraphProfiler,一个可审计的基于LLM的画像器,它将每个用户的帖子历史表示为源关联的个人知识图谱,其中节点和边可追溯到原始帖子,并将属性预测解析为引用的图谱记录和源文本。GraphProfiler在八属性SynthPAI基准上达到了86.7%的攻击成功率,与强文本基线相差两个百分点以内,在PANDORA上达到了84.6%,同时为超过98%的预测引用了支持证据。我们受控的消融实验提供了证据,表明被引用的帖子有助于攻击成功,因为移除它们比移除等量的随机帖子更能显著降低攻击成功率。
英文摘要:
Sensitive attributes such as age, income, and occupation can be inferred from user-generated content by aggregating indirect cues across many ordinary posts. LLM-based profilers can perform this aggregation automatically and with high accuracy, which makes large-scale personal attribute inference a major privacy threat. Existing LLM-based profilers, however, offer limited insight into which specific posts, concepts, and relationships made an inference possible, which is key to targeted privacy mitigation, i.e., redacting or rewriting only the few posts that actually leak an attribute, rather than perturbing entire histories. We introduce GraphProfiler, an auditable LLM-based profiler that represents each user's post history as a source-linked personal knowledge graph where nodes and edges trace back to the originating post and resolves attribute predictions to cited graph records and source texts. GraphProfiler reaches 86.7% attack success rate on the eight-attribute SynthPAI benchmark, within two points of strong text-only baselines, and 84.6% on PANDORA, while citing supporting evidence for over 98% of predictions. Our controlled ablation experiments provide evidence that the cited posts contribute to attack success, as removing them reduces the attack success rate substantially more than removing an equal number of random posts.