Numerous companies have started offering services based on large language models (LLM), such as ChatGPT, which inevitably raises privacy concerns as users' prompts are exposed to the model provider. Previous research on secure reasoning using multi-party computation (MPC) has proven to be impractical for LLM applications due to its time-consuming and communication-intensive nature. While lightweight anonymization techniques can protect private information in prompts through substitution or masking, they fail to recover sensitive data replaced in the LLM-generated results. In this paper, we expand the application scenarios of anonymization techniques by training a small local model to de-anonymize the LLM's returned results with minimal computational overhead. We introduce the HaS framework, where "H(ide)" and "S(eek)" represent its two core processes: hiding private entities for anonymization and seeking private entities for de-anonymization, respectively. To quantitatively assess HaS's privacy protection performance, we propose both black-box and white-box adversarial models. Furthermore, we conduct experiments to evaluate HaS's usability in translation and classification tasks. The experimental findings demonstrate that the HaS framework achieves an optimal balance between privacy protection and utility.
翻译:众多企业已开始基于大型语言模型(LLM)提供服务,例如ChatGPT,这不可避免地引发隐私担忧,因为用户的提示词会暴露给模型提供者。此前采用多方安全计算(MPC)的安全推理研究已被证明不适用于LLM应用,因其耗时且通信开销巨大。尽管轻量级匿名化技术能通过替换或遮蔽保护提示词中的隐私信息,但无法恢复被替换的LLM生成结果中的敏感数据。本文通过训练小型本地模型以最小计算开销对LLM返回结果进行去匿名化处理,拓展了匿名化技术的应用场景。我们提出HaS框架,其中"H(ide)"和"S(eek)"分别代表其两大核心流程:隐藏隐私实体以实现匿名化,以及寻找隐私实体以实现去匿名化。为量化评估HaS的隐私保护性能,我们提出了黑盒与白盒两种对抗模型。此外,我们通过翻译与分类任务实验评估了HaS的可用性。实验结果表明,HaS框架在隐私保护与实用性之间实现了最优平衡。