Cape: Context-Aware Prompt Perturbation Mechanism with Differential Privacy

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Wu, Haoqi, Dai, Wei, Wang, Li, Yan, Qiang
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866913838009417728
author Wu, Haoqi
Dai, Wei
Wang, Li
Yan, Qiang
author_facet Wu, Haoqi
Dai, Wei
Wang, Li
Yan, Qiang
contents Large Language Models (LLMs) have gained significant popularity due to their remarkable capabilities in text understanding and generation. However, despite their widespread deployment in inference services such as ChatGPT, concerns about the potential leakage of sensitive user data have arisen. Existing solutions primarily rely on privacy-enhancing technologies to mitigate such risks, facing the trade-off among efficiency, privacy, and utility. To narrow this gap, we propose Cape, a context-aware prompt perturbation mechanism based on differential privacy, to enable efficient inference with an improved privacy-utility trade-off. Concretely, we introduce a hybrid utility function that better captures the token similarity. Additionally, we propose a bucketized sampling mechanism to handle large sampling space, which might lead to long-tail phenomenons. Extensive experiments across multiple datasets, along with ablation studies, demonstrate that Cape achieves a better privacy-utility trade-off compared to prior state-of-the-art works.
format Preprint
id arxiv_https___arxiv_org_abs_2505_05922
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Cape: Context-Aware Prompt Perturbation Mechanism with Differential Privacy
Wu, Haoqi
Dai, Wei
Wang, Li
Yan, Qiang
Cryptography and Security
Machine Learning
Large Language Models (LLMs) have gained significant popularity due to their remarkable capabilities in text understanding and generation. However, despite their widespread deployment in inference services such as ChatGPT, concerns about the potential leakage of sensitive user data have arisen. Existing solutions primarily rely on privacy-enhancing technologies to mitigate such risks, facing the trade-off among efficiency, privacy, and utility. To narrow this gap, we propose Cape, a context-aware prompt perturbation mechanism based on differential privacy, to enable efficient inference with an improved privacy-utility trade-off. Concretely, we introduce a hybrid utility function that better captures the token similarity. Additionally, we propose a bucketized sampling mechanism to handle large sampling space, which might lead to long-tail phenomenons. Extensive experiments across multiple datasets, along with ablation studies, demonstrate that Cape achieves a better privacy-utility trade-off compared to prior state-of-the-art works.
title Cape: Context-Aware Prompt Perturbation Mechanism with Differential Privacy
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2505.05922