LatticeGen: A Cooperative Framework which Hides Generated Text in a Lattice for Privacy-Aware Generation on Cloud

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zhang, Mengke, He, Tianxing, Wang, Tianle, Mi, Lu, Mireshghallah, Fatemehsadat, Chen, Binyi, Wang, Hao, Tsvetkov, Yulia
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914741633417216
author Zhang, Mengke
He, Tianxing
Wang, Tianle
Mi, Lu
Mireshghallah, Fatemehsadat
Chen, Binyi
Wang, Hao
Tsvetkov, Yulia
author_facet Zhang, Mengke
He, Tianxing
Wang, Tianle
Mi, Lu
Mireshghallah, Fatemehsadat
Chen, Binyi
Wang, Hao
Tsvetkov, Yulia
contents In the current user-server interaction paradigm of prompted generation with large language models (LLM) on cloud, the server fully controls the generation process, which leaves zero options for users who want to keep the generated text to themselves. We propose LatticeGen, a cooperative framework in which the server still handles most of the computation while the user controls the sampling operation. The key idea is that the true generated sequence is mixed with noise tokens by the user and hidden in a noised lattice. Considering potential attacks from a hypothetically malicious server and how the user can defend against it, we propose the repeated beam-search attack and the mixing noise scheme. In our experiments we apply LatticeGen to protect both prompt and generation. It is shown that while the noised lattice degrades generation quality, LatticeGen successfully protects the true generation to a remarkable degree under strong attacks (more than 50% of the semantic remains hidden as measured by BERTScore).
format Preprint
id arxiv_https___arxiv_org_abs_2309_17157
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle LatticeGen: A Cooperative Framework which Hides Generated Text in a Lattice for Privacy-Aware Generation on Cloud
Zhang, Mengke
He, Tianxing
Wang, Tianle
Mi, Lu
Mireshghallah, Fatemehsadat
Chen, Binyi
Wang, Hao
Tsvetkov, Yulia
Computation and Language
In the current user-server interaction paradigm of prompted generation with large language models (LLM) on cloud, the server fully controls the generation process, which leaves zero options for users who want to keep the generated text to themselves. We propose LatticeGen, a cooperative framework in which the server still handles most of the computation while the user controls the sampling operation. The key idea is that the true generated sequence is mixed with noise tokens by the user and hidden in a noised lattice. Considering potential attacks from a hypothetically malicious server and how the user can defend against it, we propose the repeated beam-search attack and the mixing noise scheme. In our experiments we apply LatticeGen to protect both prompt and generation. It is shown that while the noised lattice degrades generation quality, LatticeGen successfully protects the true generation to a remarkable degree under strong attacks (more than 50% of the semantic remains hidden as measured by BERTScore).
title LatticeGen: A Cooperative Framework which Hides Generated Text in a Lattice for Privacy-Aware Generation on Cloud
topic Computation and Language
url https://arxiv.org/abs/2309.17157