arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

学习引用:面向隐私感知语言模型的客户端解析生成

Learning to Refer: Client-Resolved Generation for Privacy-Aware Language Models

Jeongho Yoon, Chanhee Park, Yongchan Chun, Duong Tuan Thanh, Sungbin Han, Chanjun Park, Hyeonseok Moon, Heuiseok Lim

arXiv 2609.32706首次发表:更新:

发表机构

Korea University; Konkuk University; Soongsil University; Sookmyung Women’s University(高丽大学; 建国大学; 崇实大学; 淑明女子大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对云LLM的隐私风险,提出客户端解析生成(CRG)接口,分离生成与词汇实现,保护输入输出内容,在SealTools上完整调用精确匹配从57.3%提升至79.9%,兼顾效用与模型机密性。

AI 中文摘要

基于云的大语言模型(LLM)要求用户向服务提供商披露明文数据,这在敏感领域造成了隐私风险。现有的隐私保护方法往往以牺牲效用换取保护,产生大量的计算或通信开销,仍然容易受到中间表示重建攻击,或者仅保护训练和推理流程中的一部分。我们引入了客户端解析生成(CRG),这是一种生成接口,将服务器端生成与输入派生内容的词汇实现分离。客户端仅传输池化和噪声扰动的表示,而输入派生的输出内容则使用请求本地的位置引用表示,并仅在客户端解析为原始字符串。该接口在训练和推理期间保护私有输入和输入派生的输出内容,同时允许服务提供商对客户端隐藏其专有模型参数。同时,精确的词汇复用仍然可行,而无需在提供商可见的生成路径上直接暴露复用的内容。我们在医学和文档基础的问答、敏感标识符转移和工具调用上评估了CRG,并进行了重建和原始日志泄露分析。在SealTools上,与输入隐私框架PPFT相比,CRG将完整调用精确匹配从57.3%提高到79.9%,随着更多所需输出内容可通过引用解析,增益更大。总之,这些结果表明,CRG通过减少输入和输出路径上的明文暴露,同时保持任务效用和服务器端模型机密性,为隐私敏感的云LLM提供了一种实用接口。

英文摘要

Cloud-based large language models (LLMs) require users to disclose plaintext data to service providers, creating privacy risks in sensitive domains. Existing privacy-preserving approaches often trade utility for protection, incur substantial computational or communication overhead, remain vulnerable to reconstruction from intermediate representations, or protect only a subset of the training and inference pipeline. We introduce Client-Resolved Generation (CRG), a genera- tion interface that separates server-side generation from the lexical realization of input-derived content. The client transmits only pooled and noise-perturbed rep- resentations, while input-derived output content is represented using request-local positional references and resolved to its original strings only on the client. This interface protects private input and input-derived output content during both train- ing and inference while allowing the service provider to keep its proprietary model parameters hidden from the client. At the same time, exact lexical reuse remains possible without directly exposing the reused content on the provider-visible gen- eration path. We evaluate CRG on medical and document-grounded QA, sensi- tive identifier transfer, and tool calling, together with reconstruction and raw-logit leakage analyses. On SealTools, CRG improves complete-call exact match from 57.3% to 79.9% over the input-privacy framework PPFT, with larger gains as more required output content can be resolved through references. Together, these results show that CRG provides a practical interface for privacy-sensitive cloud LLMs by reducing plaintext exposure across both input and output pathways while preserv- ing task utility and server-side model confidentiality.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑