InvisibleInk: High-Utility and Low-Cost Text Generation with Differential Privacy

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Vinod, Vishnu, Pillutla, Krishna, Thakurta, Abhradeep Guha
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918483418152960
author Vinod, Vishnu
Pillutla, Krishna
Thakurta, Abhradeep Guha
author_facet Vinod, Vishnu
Pillutla, Krishna
Thakurta, Abhradeep Guha
contents As major progress in LLM-based long-form text generation enables paradigms such as retrieval-augmented generation (RAG) and inference-time scaling, safely incorporating private information into the generation remains a critical open question. We present InvisibleInk, a highly scalable long-form text generation framework satisfying rigorous differential privacy guarantees with respect to the sensitive reference texts. It interprets sampling from the LLM's next-token-distribution as the exponential mechanism over the LLM logits with two innovations. First, we reduce the privacy cost by isolating and clipping only the sensitive information in the model logits (relative to the public logits). Second, we improve text quality by sampling without any privacy cost from a small superset of the top-$k$ private tokens. Empirical evaluations demonstrate a consistent $8\times$ (or more) reduction in computation cost over state-of-the-art baselines to generate long-form private text of the same utility across privacy levels. InvisibleInk is able to generate, for the first time, high-quality private long-form text at less than $4$-$8\times$ times the computation cost of non-private generation, paving the way for its practical use. We open-source a pip-installable Python package (invink) for InvisibleInk at https://github.com/cerai-iitm/invisibleink.
format Preprint
id arxiv_https___arxiv_org_abs_2507_02974
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle InvisibleInk: High-Utility and Low-Cost Text Generation with Differential Privacy
Vinod, Vishnu
Pillutla, Krishna
Thakurta, Abhradeep Guha
Machine Learning
Computation and Language
Cryptography and Security
As major progress in LLM-based long-form text generation enables paradigms such as retrieval-augmented generation (RAG) and inference-time scaling, safely incorporating private information into the generation remains a critical open question. We present InvisibleInk, a highly scalable long-form text generation framework satisfying rigorous differential privacy guarantees with respect to the sensitive reference texts. It interprets sampling from the LLM's next-token-distribution as the exponential mechanism over the LLM logits with two innovations. First, we reduce the privacy cost by isolating and clipping only the sensitive information in the model logits (relative to the public logits). Second, we improve text quality by sampling without any privacy cost from a small superset of the top-$k$ private tokens. Empirical evaluations demonstrate a consistent $8\times$ (or more) reduction in computation cost over state-of-the-art baselines to generate long-form private text of the same utility across privacy levels. InvisibleInk is able to generate, for the first time, high-quality private long-form text at less than $4$-$8\times$ times the computation cost of non-private generation, paving the way for its practical use. We open-source a pip-installable Python package (invink) for InvisibleInk at https://github.com/cerai-iitm/invisibleink.
title InvisibleInk: High-Utility and Low-Cost Text Generation with Differential Privacy
topic Machine Learning
Computation and Language
Cryptography and Security
url https://arxiv.org/abs/2507.02974