AI 中文总结
PerceptFence提出屏幕共享AI助手的基于内容的调解架构,通过确定性覆盖评估,在OCR存活的秘密和PII上达到0.918的中和率,优于Presidio和gitleaks。
AI 中文摘要
实时屏幕共享AI助手会观察原始屏幕和语音流,但用户对助手可能观察、保留或披露的内容几乎没有运行时控制。基于提示级别的隐私设置是不够的,因为敏感内容通过捕获流进入。我们提出了PerceptFence,一种位于捕获、记忆和模型响应之间的基于内容的调解架构,并带有确定性合成夹具脚手架;该工件省略了实时捕获、类别推断、经过身份验证的重新同意、跨会话状态和外部模型适配器。在由单独实现的暴露预言机评分的9,600个协议记录的对抗性字符串上,PerceptFence在两个系统都运行的5个种子上中和了0.828的数字PII负载,而Microsoft Presidio为0.183;在该家族之外,Presidio以0.238对0.154领先,因此总体0.398对0.260的比较仅具有指示性。然后,我们评估了部署助手使用的路径:480个由Chrome渲染、降级并由OCR读取的合成开发者支持屏幕,规则在测试前冻结,并保留三种屏幕类型。PerceptFence中和了968个OCR存活的秘密和PII值中的889个(0.918;Wilson 95%置信区间0.899-0.934),而Presidio为0.581,gitleaks为0.179,在保留的屏幕类型上为0.974,在这些类型上测量的任务令牌保留成本为0.763。贡献是一个有文档记录的调解架构和具有明确覆盖边界的评估方法,而不是声称实时部署、形式隐私、新颖的编辑原语或通用模型鲁棒性。
英文摘要
Live screen-share AI assistants observe raw screen and speech streams, but users have little runtime control over what an assistant may observe, retain, or disclose. Prompt-level privacy settings are insufficient because sensitive content enters through the capture stream. We present PerceptFence, a content-layer mediation architecture between capture, memory, and model responses, with a deterministic synthetic-fixture scaffold; the artifact omits live capture, category inference, authenticated re-consent, cross-session state, and an external model adapter. On 9,600 protocol-documented adversarial strings scored by a separately implemented exposure oracle, PerceptFence neutralises 0.828 of digit-PII payloads on the 5 seeds both systems run, versus 0.183 for Microsoft Presidio; outside that family Presidio leads 0.238 to 0.154, so the overall 0.398 to 0.260 comparison is only indicative. We then evaluate the path a deployed assistant uses: 480 synthetic developer-support screens rendered by Chrome, degraded, and read by OCR, with rules frozen before testing and three screen types held out. PerceptFence neutralises 889 of 968 OCR-surviving secrets and PII values (0.918; Wilson 95% 0.899-0.934) against 0.581 for Presidio and 0.179 for gitleaks, and 0.974 on the held-out screen types, at a measured cost of 0.763 task-token retention on those types. The contribution is a documented mediation architecture and an evaluation method with explicit coverage boundaries, not a claim of live deployment, formal privacy, novel redaction primitives, or general model robustness.
Comments32 pages, 7 tables, 2 figures. Code, frozen protocol, and per-case results: https://github.com/asmitanegi/PerceptFence (release v0.4.0); archived software DOI 10.5281/zenodo.21289219