arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.23193cs.CRcs.AIcs.CL

LLMs作为语言变色龙:解耦语义与结构以实现隐私保护通信

LLMs as Linguistic Chameleons: Decoupling Semantics and Structure for Privacy-Preserving Communication

  • Emory University(埃默里大学)

机构由 AI 辅助整理,请以论文原文为准。

Yuzhu Mao, Liang Zhao

AI总结:

针对LLM API推理时隐私泄露问题,提出CROSS-MAP双向框架,通过语义解耦替换原始语义并保留结构,多目标优化训练本地模型,在降低重建成功率的同时保持任务效用。

AI中文摘要:

随着大型语言模型(LLM)API日益集成到隐私敏感的工作流程中,在不损害任务效用的前提下确保推理时隐私仍是一项重大挑战。现有方法保留了大部分原始语义内容以维持下游性能,但这同时也为重建原始文本留下了可利用的线索。本研究探讨了语义解耦,即在保留LLM推理所需结构的同时,用替代内容替换原始语义。基于这一思想,我们提出了CROSS-MAP,一个双向框架,在推理前将私有输入映射到不同的语义域,并在推理后恢复相应的输出。本地模型通过多目标优化进行训练,以在映射阶段最大化语义发散度,同时在恢复阶段最小化语义不一致性。实验表明,CROSS-MAP在多种攻击设置下降低了重建成功率,同时在效用方面优于现有基线。

英文摘要:

As Large Language Model (LLM) APIs become increasingly integrated into privacy-sensitive workflows, ensuring inference-time privacy without compromising task utility remains a major challenge. Existing approaches preserve most of the original semantic content to maintain downstream performance, but this also leaves exploitable cues for reconstructing the original text. This work investigates semantic decoupling, which replaces original semantics with alternative content while preserving the structure needed for LLM reasoning. Based on this idea, we propose CROSS-MAP, a bidirectional framework that maps private inputs into a different semantic domain before inference and recovers the corresponding outputs afterward. Local models are trained with multi-objective optimization to maximize semantic divergence in the mapping stage while minimizing semantic inconsistency in the recovery stage. Experiments show that CROSS-MAP reduces reconstruction success across multiple attack settings while outperforming existing baselines in utility.

↑