电子学报2026,Vol.54Issue(1):50-67,18.DOI:10.12263/DZXB.20250793
面向在线生成式人工智能服务的隐私保护方法
Building Privacy Shield in Online Generative AI Services
摘要
Abstract
In recent years,state-of-the-art online artificial intelligence systems demonstrate remarkable capabilities in various fields,exerting broad social impacts.In order to access these model services,users are typically required to upload their personal data to the cloud platform.However,these queries may contain sensitive or confidential information,and di-rectly sharing them with cloud platforms introduces potential privacy leakage risks.Moreover,platforms may exploit user data for further model training,causing private information to be memorized by the model and later regenerated in public services,thereby aggravating the risk of privacy breaches.Existing privacy-preserving mechanisms in generative AI applica-tions predominantly rely on prompt sanitization techniques,whose security critically depends on the accuracy of sensitive information identification.These approaches usually require large amounts of annotated data for model training,which not only raises implementation costs but may also introduce new privacy vulnerabilities in specific scenarios.To address this is-sue,this paper proposes a novel privacy-preserving collaborative learning framework named PrivateAI.The core idea of this framework is to fully exploit sensitive data distributed across different devices to train local privacy identification mod-els,while strictly ensuring data privacy.Meanwhile,PrivateAI extracts the implicit knowledge embedded in the large foun-dation models and compresses it into a lightweight distilled dataset,thereby achieving effective privacy detection perfor-mance enhancement of local models.In addition,to tackle the heterogeneity challenge between the knowledge extracted from labeled data and foundation models,the framework introduces a heterogeneous knowledge fusion mechanism that aligns and integrates multi-source knowledge from both the foundational models and distributed labeled datasets.We evalu-ate PrivateAI on two datasets,and the results demonstrate that models learned by PrivateAI can maximally improve the pri-vacy protection success rate by 53.7 percentage points.PrivateAI holds significant potential in mitigating privacy breaches,acting as a sentinel against severe privacy leakage incidents within online AI applications.关键词
隐私保护/协同学习/在线人工智能服务/差分隐私/联邦学习Key words
privacy protection/collaborative learning/online artificial intelligence services/differential privacy/fed-erated learning分类
信息技术与安全科学引用本文复制引用
齐涛,王慧丽,杨珮茹,王文丹,谭支鹏,黄永峰,王尚广,徐红艳,罗传文..面向在线生成式人工智能服务的隐私保护方法[J].电子学报,2026,54(1):50-67,18.基金项目
国家自然科学基金(No.62425203,No.62502044) National Natural Science Foundation of China(No.62425203,No.62502044) (No.62425203,No.62502044)