{"id":"https://openalex.org/W7125664883","doi":"https://doi.org/10.56553/popets-2026-0009","title":"Sanitization or Deception? Rethinking Privacy Protection in Large Language Models","display_name":"Sanitization or Deception? Rethinking Privacy Protection in Large Language Models","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7125664883","doi":"https://doi.org/10.56553/popets-2026-0009"},"language":null,"primary_location":{"id":"doi:10.56553/popets-2026-0009","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2026-0009","pdf_url":"https://petsymposium.org/popets/2026/popets-2026-0009.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://petsymposium.org/popets/2026/popets-2026-0009.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5039150756","display_name":"Bipin Paudel","orcid":"https://orcid.org/0009-0006-6693-6743"},"institutions":[{"id":"https://openalex.org/I189590672","display_name":"Kansas State University","ror":"https://ror.org/05p1j8758","country_code":"US","type":"education","lineage":["https://openalex.org/I189590672"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Bipin Paudel","raw_affiliation_strings":["Kansas State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kansas State University","institution_ids":["https://openalex.org/I189590672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032853619","display_name":"Bishwas Mandal","orcid":"https://orcid.org/0000-0002-6686-2223"},"institutions":[{"id":"https://openalex.org/I189590672","display_name":"Kansas State University","ror":"https://ror.org/05p1j8758","country_code":"US","type":"education","lineage":["https://openalex.org/I189590672"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Bishwas Mandal","raw_affiliation_strings":["Kansas State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kansas State University","institution_ids":["https://openalex.org/I189590672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018956193","display_name":"George T. Amariucai","orcid":"https://orcid.org/0000-0003-4471-6425"},"institutions":[{"id":"https://openalex.org/I189590672","display_name":"Kansas State University","ror":"https://ror.org/05p1j8758","country_code":"US","type":"education","lineage":["https://openalex.org/I189590672"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"George Amariucai","raw_affiliation_strings":["Kansas State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kansas State University","institution_ids":["https://openalex.org/I189590672"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012143414","display_name":"Shuangqing Wei","orcid":"https://orcid.org/0000-0001-5913-1441"},"institutions":[{"id":"https://openalex.org/I121820613","display_name":"Louisiana State University","ror":"https://ror.org/05ect4e57","country_code":"US","type":"education","lineage":["https://openalex.org/I121820613"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shuangqing Wei","raw_affiliation_strings":["Louisiana State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Louisiana State University","institution_ids":["https://openalex.org/I121820613"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5039150756"],"corresponding_institution_ids":["https://openalex.org/I189590672"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.1233113,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"2026","issue":"1","first_page":"154","last_page":"174"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.1421000063419342,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.1421000063419342,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.13050000369548798,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.10040000081062317,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8123999834060669},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.6743999719619751},{"id":"https://openalex.org/keywords/deception","display_name":"Deception","score":0.526199996471405},{"id":"https://openalex.org/keywords/empirical-measure","display_name":"Empirical measure","score":0.4593000113964081},{"id":"https://openalex.org/keywords/empirical-research","display_name":"Empirical research","score":0.4113999903202057},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.40799999237060547},{"id":"https://openalex.org/keywords/information-leakage","display_name":"Information leakage","score":0.4065999984741211},{"id":"https://openalex.org/keywords/private-information-retrieval","display_name":"Private information retrieval","score":0.4059000015258789},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.3709999918937683}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8123999834060669},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7432000041007996},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.6743999719619751},{"id":"https://openalex.org/C2779267917","wikidata":"https://www.wikidata.org/wiki/Q170028","display_name":"Deception","level":2,"score":0.526199996471405},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.491100013256073},{"id":"https://openalex.org/C206654554","wikidata":"https://www.wikidata.org/wiki/Q5374247","display_name":"Empirical measure","level":2,"score":0.4593000113964081},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.43529999256134033},{"id":"https://openalex.org/C120936955","wikidata":"https://www.wikidata.org/wiki/Q2155640","display_name":"Empirical research","level":2,"score":0.4113999903202057},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.40799999237060547},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.4065999984741211},{"id":"https://openalex.org/C99221444","wikidata":"https://www.wikidata.org/wiki/Q1532069","display_name":"Private information retrieval","level":2,"score":0.4059000015258789},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.3709999918937683},{"id":"https://openalex.org/C2777530160","wikidata":"https://www.wikidata.org/wiki/Q41796","display_name":"Sentence","level":2,"score":0.36890000104904175},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.3668000102043152},{"id":"https://openalex.org/C3017597292","wikidata":"https://www.wikidata.org/wiki/Q25052250","display_name":"Privacy protection","level":2,"score":0.3598000109195709},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.35589998960494995},{"id":"https://openalex.org/C2780148112","wikidata":"https://www.wikidata.org/wiki/Q1432581","display_name":"Proxy (statistics)","level":2,"score":0.3476000130176544},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.3246000111103058},{"id":"https://openalex.org/C166052673","wikidata":"https://www.wikidata.org/wiki/Q83021","display_name":"Empirical evidence","level":2,"score":0.3077000081539154},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.2928999960422516},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.29280000925064087},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.27959999442100525},{"id":"https://openalex.org/C23130292","wikidata":"https://www.wikidata.org/wiki/Q5275358","display_name":"Differential privacy","level":2,"score":0.2689000070095062},{"id":"https://openalex.org/C2777042071","wikidata":"https://www.wikidata.org/wiki/Q6509304","display_name":"Leakage (economics)","level":2,"score":0.26409998536109924},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2615000009536743},{"id":"https://openalex.org/C130318100","wikidata":"https://www.wikidata.org/wiki/Q2268914","display_name":"Semantic similarity","level":2,"score":0.25859999656677246},{"id":"https://openalex.org/C44291984","wikidata":"https://www.wikidata.org/wiki/Q1074173","display_name":"Question answering","level":2,"score":0.2581000030040741},{"id":"https://openalex.org/C137822555","wikidata":"https://www.wikidata.org/wiki/Q2587068","display_name":"Information sensitivity","level":2,"score":0.2542000114917755},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.2502000033855438}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.56553/popets-2026-0009","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2026-0009","pdf_url":"https://petsymposium.org/popets/2026/popets-2026-0009.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.56553/popets-2026-0009","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2026-0009","pdf_url":"https://petsymposium.org/popets/2026/popets-2026-0009.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.8093559145927429,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G1549141601","display_name":"Collaborative Research: SaTC 2.0: RES: A Privacy-Preserving Framework for Sharing and Learning from Scarce Medical Data","funder_award_id":"2523438","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7125664883.pdf","grobid_xml":"https://content.openalex.org/works/W7125664883.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Large":[0],"language":[1],"models":[2],"have":[3,27],"shown":[4],"considerable":[5],"abilities":[6],"across":[7],"many":[8],"tasks,":[9],"but":[10,104],"their":[11,148],"capacity":[12],"to":[13,31,95],"detect":[14],"sensitive":[15],"user":[16],"information":[17],"from":[18,43],"text":[19,30],"raises":[20],"significant":[21],"privacy":[22,41,184],"concerns.":[23],"While":[24],"recent":[25],"approaches":[26],"explored":[28],"sanitizing":[29],"hide":[32,145],"private":[33,55,146],"features,":[34,147],"a":[35,192],"deeper":[36],"challenge":[37],"remains:":[38],"distinguishing":[39,182],"true":[40,136],"preservation":[42],"deceptive":[44],"transformations.":[45],"In":[46],"this":[47,196],"paper,":[48],"we":[49,74,154],"investigate":[50],"whether":[51],"LLM-based":[52,165,188],"sanitization":[53,189],"reduces":[54],"feature":[56],"leakage":[57,76],"without":[58],"misleading":[59],"an":[60],"adversary":[61],"into":[62],"confidently":[63],"predicting":[64],"incorrect":[65,124],"labels.":[66],"Using":[67],"LLM":[68],"as":[69,135],"both":[70],"sanitizer":[71],"and":[72,86,126,168,173,185,190],"adversary,":[73],"measure":[75],"using":[77,162],"two":[78],"entropy-based":[79],"metrics:":[80],"Empirical":[81,87],"Average":[82,88],"Objective":[83],"Leakage":[84],"(E-AOL)":[85],"Confidence":[89],"Boost":[90],"(E-ACB).":[91],"These":[92],"allow":[93],"us":[94],"quantify":[96],"not":[97,132],"only":[98],"how":[99,106],"accurate":[100],"adversarial":[101,117,200],"predictions":[102],"are,":[103],"also":[105,120],"confident":[107],"they":[108],"remain":[109],"post-sanitization.":[110],"We":[111,138],"posit":[112],"that":[113,140],"deception,":[114],"while":[115,141],"reducing":[116],"accuracy,":[118],"will":[119],"increase":[121],"confidence":[122],"in":[123,187],"inferences,":[125],"hence":[127],"reduced":[128],"accuracy":[129],"alone":[130],"should":[131],"be":[133],"interpreted":[134],"privacy.":[137],"show":[139],"current":[142],"LLMs":[143],"can":[144],"transformations":[149],"sometimes":[150],"cause":[151],"deception.":[152],"Finally,":[153],"evaluate":[155],"the":[156,178],"semantic":[157],"utility":[158],"of":[159,180],"sanitized":[160],"outputs":[161],"sentence":[163],"embeddings,":[164],"similarity":[166],"judgments,":[167],"standard":[169],"metrics":[170],"like":[171],"BLEU":[172],"ROUGE.":[174],"Our":[175],"findings":[176],"emphasize":[177],"importance":[179],"explicitly":[181],"between":[183],"deception":[186],"provide":[191],"framework":[193],"for":[194],"evaluating":[195],"distinction":[197],"under":[198],"realistic":[199],"conditions.":[201]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-01-26T00:00:00"}
