Locally Differentially Private Document Generation Using Zero Shot Prompting
Saiteja Utpala, Sara Hooker, Pin‐Yu Chen · 2023
Numerous studies have highlighted the privacy risks associated with pretrained large language models.In contrast, our research offers a unique perspective by demonstrating that pretrained large language models can effectively contribute to privacy preservation.We propose a locally differentially private mechanism called DP-Prompt, which leverages the power of pretrained large language models and zero-shot prompting to counter author de-anonymization attacks while minimizing the impact on downstream utility.When DP-Prompt is used with a powerful language model like ChatGPT (gpt-3.5),we observe a notable reduction in the success rate of deanonymization attacks, showing that it surpasses existing approaches by a considerable margin despite its simpler design.For instance, in the case of the IMDB dataset, DP-Prompt (with ChatGPT) perfectly recovers the clean sentiment F1 score while achieving a 46% reduction in author identification F1 score against static attackers and a 26% reduction against adaptive attackers.We conduct extensive experiments across six open-source large language models, ranging up to 7 billion parameters, to analyze various effects of the privacyutility tradeoff.Code is avaliable at https: //github.com/SaitejaUtpala/dp_promptSentiment(Utility) Author Identification(Privacy) 0.0 0.2 0.4 0.6 0.8 1.0 F1-Score 0.8 0.93 0.8 0.69 0.79 0.49 Privacy vs Utility of DP-Prompt (with ChatGPT) w/o DP-Prompt DP-Prompt(Adaptive) DP-Prompt(Static) Mechanism Privacy Level Requires fine-tuning Generates sanitized doc Madlib (Feyisetan et al., 2020) Word level Metric-DP No Yes Mahanolbis (Xu et al., 2020) Word level Metric-DP No Yes TEM (Carvalho et al., 2021) Word level Metric-DP No Yes Truncated Laplace (Meehan et al., 2022) Sentence level Pure-DP No No Deep Candidate (Meehan et al., 2022) Sentence level Pure-DP Yes No Paraphraser (Mattern et al., 2022b) Document level Pure-LDP Yes Yes DP Prompt (Ours) Document level Pure-LDP No Yes