<italic>Large language models</italic> (LLMs), represented by ChatGPT, have greatly simplified text generation tasks. However, they have also raised concerns about privacy risks such as data leakage and unauthorized information collection. Existing solutions for privacy-preserving inference face practical challenges related to computational time and communication costs. In this article, we propose <monospace>InferDPT</monospace>, the first practical framework for privacy-preserving <underline><monospace>Infer</monospace></underline>ence of closed-box LLMs, implementing <underline><monospace>D</monospace></underline>ifferential <underline><monospace>P</monospace></underline>rivacy in <underline><monospace>T</monospace></underline>ext generation. <monospace>InferDPT</monospace> comprises two key modules: the “perturbation module” utilizes the differentially private mechanism to generate a perturbed prompt, facilitating privacy-preserving inference with closed-box LLMs; the “extraction module”, inspired by knowledge distillation and phenomenon we observed, extracts coherent and consistent text from the perturbed generation result, ensuring successful text generation completion. To achieve a better balance between utility and privacy protection, we introduce RANTEXT, a novel differentially private mechanism integrated into the perturbation module of <monospace>InferDPT</monospace>, which introduces the concept of “<underline>RAN</underline>dom adjacency list” for <underline>TEXT</underline> perturbation within the prompt. Experimental results across three datasets demonstrate that the text generation quality of <monospace>InferDPT</monospace> is comparable to that of non-private GPT-4, and RANTEXT surpasses existing state-of-the-art mechanisms, namely, SANTEXT+ and CUSTEXT+ in the trade-off between privacy and utility. Even with a privacy parameter <inline-formula><tex-math notation="LaTeX">$\varepsilon$</tex-math><alternatives><mml:math><mml:mi>ɛ</mml:mi></mml:math><inline-graphic xlink:href="chen-ieq1-3550389.gif"/></alternatives></inline-formula> value of 6.0, RANTEXT achieves an average privacy protection level of exceeding 0.90 against the embedding inversion attacks, which is 0.58× higher than that of SANTEXT+ and 3.35× higher than that of CUSTEXT+.
Paper
References (62)
Scroll for more · 38 remaining