| 注册
首页|期刊导航|电子学报|面向在线生成式人工智能服务的隐私保护方法

面向在线生成式人工智能服务的隐私保护方法

齐涛 王慧丽 杨珮茹 王文丹 谭支鹏 黄永峰 王尚广 徐红艳 罗传文

电子学报2026,Vol.54Issue(1):50-67,18.
电子学报2026,Vol.54Issue(1):50-67,18.DOI:10.12263/DZXB.20250793

面向在线生成式人工智能服务的隐私保护方法

Building Privacy Shield in Online Generative AI Services

齐涛 1王慧丽 2杨珮茹 2王文丹 1谭支鹏 3黄永峰 2王尚广 1徐红艳 4罗传文4

作者信息

  • 1. 北京邮电大学计算机学院网络与交换技术全国重点实验室,北京 100876
  • 2. 清华大学电子工程系,北京 100084
  • 3. 华中科技大学武汉光电国家研究中心,湖北 武汉 430074
  • 4. 北京林业大学信息学院,北京 100083
  • 折叠

摘要

Abstract

In recent years,state-of-the-art online artificial intelligence systems demonstrate remarkable capabilities in various fields,exerting broad social impacts.In order to access these model services,users are typically required to upload their personal data to the cloud platform.However,these queries may contain sensitive or confidential information,and di-rectly sharing them with cloud platforms introduces potential privacy leakage risks.Moreover,platforms may exploit user data for further model training,causing private information to be memorized by the model and later regenerated in public services,thereby aggravating the risk of privacy breaches.Existing privacy-preserving mechanisms in generative AI applica-tions predominantly rely on prompt sanitization techniques,whose security critically depends on the accuracy of sensitive information identification.These approaches usually require large amounts of annotated data for model training,which not only raises implementation costs but may also introduce new privacy vulnerabilities in specific scenarios.To address this is-sue,this paper proposes a novel privacy-preserving collaborative learning framework named PrivateAI.The core idea of this framework is to fully exploit sensitive data distributed across different devices to train local privacy identification mod-els,while strictly ensuring data privacy.Meanwhile,PrivateAI extracts the implicit knowledge embedded in the large foun-dation models and compresses it into a lightweight distilled dataset,thereby achieving effective privacy detection perfor-mance enhancement of local models.In addition,to tackle the heterogeneity challenge between the knowledge extracted from labeled data and foundation models,the framework introduces a heterogeneous knowledge fusion mechanism that aligns and integrates multi-source knowledge from both the foundational models and distributed labeled datasets.We evalu-ate PrivateAI on two datasets,and the results demonstrate that models learned by PrivateAI can maximally improve the pri-vacy protection success rate by 53.7 percentage points.PrivateAI holds significant potential in mitigating privacy breaches,acting as a sentinel against severe privacy leakage incidents within online AI applications.

关键词

隐私保护/协同学习/在线人工智能服务/差分隐私/联邦学习

Key words

privacy protection/collaborative learning/online artificial intelligence services/differential privacy/fed-erated learning

分类

信息技术与安全科学

引用本文复制引用

齐涛,王慧丽,杨珮茹,王文丹,谭支鹏,黄永峰,王尚广,徐红艳,罗传文..面向在线生成式人工智能服务的隐私保护方法[J].电子学报,2026,54(1):50-67,18.

基金项目

国家自然科学基金(No.62425203,No.62502044) National Natural Science Foundation of China(No.62425203,No.62502044) (No.62425203,No.62502044)

电子学报

0372-2112

访问量0
|
下载量0
段落导航相关论文