arXiv:2608. 02616v2 Announce Type: replace-cross Abstract: We present what is, to our knowledge, the first systematic evaluation of OpenAI's Privacy Filter (OPF), a 1.
By Rohith Uppala
arXiv:2608. 02616v1 Announce Type: cross Abstract: We present the first independent, systematic evaluation of OpenAI's Privacy Filter (OPF), a 1.
By Rohith Uppala
arXiv:2606. 24623v1 Announce Type: cross Abstract: Retrieval-Augmented Generation enhances large language models by incorporating external knowledge, but deploying it in sensitive scenarios risks privacy leakage via malicious prompts.
By Yuanhe Zhao, Tianyu Zhang, Huafei Xing, Derek F. Wong, Jianbin Li, Tao Fang
Redakto is a new tool designed to anonymize text before it is processed by large language models (LLMs). It offers state‑of‑the‑art redaction of personally identifiable information (PII) and pseudonymization, accessible via a web interface, REST APIs, and model context protocol hooks. The authors evaluate its performance on legal and medical datasets, showing that anonymized texts retain utility comparable to the originals, enabling LLM tasks without significant loss of effectiveness.
By Saurav Kumar Saha, Tom R\"ohr, Felix Bie{\ss}mann
arXiv:2606. 18782v1 Announce Type: cross Abstract: Large Language Models are increasingly applied to sensitive domains that require redaction of personally identifiable information (PII).
By Sean Brynj\'olfsson, Shashvat Jayakrishnan, Esha Sali, Diptanshu Purwar, Madhav Aggarwal
ASIRF (Agentic Sensitive Information Redaction Framework) is a system that retrieves domain‑specific definitions of sensitive information from a flexible knowledge base at inference time, eliminating the need for retraining when adapting to new domains. It offers two architectures—a three‑call multi‑agent pipeline and a single‑agent variant—and has been evaluated on ten small open‑weight models across eight datasets, including out‑of‑distribution fictional domains. In 68 of 80 model‑domain combinations (85 %), ASIRF’s recall surpasses that of the OpenAI Privacy Filter, with most shortfalls limited to the filter’s training‑distribution domains.
By Sudha Priyadarshini, Mohamed Chahine Ghanem
arXiv:2608. 05163v1 Announce Type: cross Abstract: A common assumption holds that switching to a non-English language makes a multilingual RAG system easier to attack for personal information.
By Yanhang Li, Zhichao Fan, Zexin Zhuang
The paper systematically studies how anonymizing input data affects large language models (LLMs). Five prominent LLMs were evaluated on eleven benchmarks, comparing performance on original versus pseudonymized inputs. Results show that anonymization generally degrades performance, with larger drops for more capable models and task-dependent effects; reversible anonymization preserves entity uniqueness better than irreversible redaction, and prompting about anonymization offers no benefit.
By Tobias Deu{\ss}er, Max Hahnb\"uck, Lorenz Sparrenberg, Tobias Uelwer, Christian Bauckhage, Rafet Sifa
arXiv:2608. 12675v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) is widely used to improve the performance of Large Language Models (LLMs) in answering user queries.
By Saleh Almohaimeed, Saad Almohaimeed, Mousa Jari, Fahad Alotaibi, Khalid A. Alobaid
arXiv:2609.38630v1 Announce Type: new
Abstract: Privacy redaction must remove personal information while preserving relationships expressed in text. We develop a multilingual named-entity tagger with...
By Jonathan Graehl
arXiv:2606. 24408v1 Announce Type: new Abstract: Assessing the privacy of large language models (LLMs) presents significant challenges.
By Lorenzo Rossi, Bart{\l}omiej Marek, Franziska Boenisch, Adam Dziedzic
The paper presents PersianAnonymizer, a method for anonymizing Persian customer chats by training a compact NER model using supervision from large language models (LLMs). Three instruction‑tuned LLMs—DeepSeek‑V3‑0324, GPT‑OSS‑120B, and Qwen3‑235B‑A22B‑Instruct‑2507—were used to generate span annotations, producing four corpora. A MatinaRoberta token‑classifier trained on each corpus achieved high macro‑F1 and Label Coverage Recall, with the OSS_ZeroShot‑derived NER labeling a 40K‑message test set in about two minutes on a single RTX 3090, demonstrating a practical, low‑cost approach to Persian data anonymization.
By Mohammad Hossein Shalchian, Mostafa Amiri, Amir Mahdi Sadeghzadeh