{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,17]],"date-time":"2026-04-17T08:41:34Z","timestamp":1776415294437,"version":"3.51.2"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T00:00:00Z","timestamp":1745280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,4,28]]},"DOI":"10.1145\/3696410.3714531","type":"proceedings-article","created":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T22:57:28Z","timestamp":1745362648000},"page":"5224-5233","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Effectiveness of Privacy-preserving Algorithms in LLMs: A Benchmark and Empirical Analysis"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-5803-1880","authenticated-orcid":false,"given":"Jinglin","family":"Sun","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, The University of New South Wales, Sydney, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2674-0253","authenticated-orcid":false,"given":"Basem","family":"Suleiman","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, The University of New South Wales, Sydney, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8188-2601","authenticated-orcid":false,"given":"Imdad","family":"Ullah","sequence":"additional","affiliation":[{"name":"School of Computer Science, The University of Sydney, Sydney, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3930-6600","authenticated-orcid":false,"given":"Imran","family":"Razzak","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, The University of New South Wales, Sydney, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,4,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Lintang Sutawika, Hailey Schoelkopf, Quentin Anthony, Shivanshu Purohit, and Edward Raff.","author":"Biderman Stella","year":"2023","unstructured":"Stella Biderman, USVSN Sai Prashanth, Lintang Sutawika, Hailey Schoelkopf, Quentin Anthony, Shivanshu Purohit, and Edward Raff. 2023. Emergent and Predictable Memorization in Large Language Models. arxiv: 2304.11158 [cs.CL]"},{"key":"e_1_3_2_1_2_1","volume-title":"Quantifying Memorization Across Neural Language Models. In The Eleventh International Conference on Learning Representations.","author":"Carlini Nicholas","year":"2023","unstructured":"Nicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Florian Tramer, and Chiyuan Zhang. 2023. Quantifying Memorization Across Neural Language Models. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Chang Liu, \u00dalfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The secret sharer: evaluating and testing unintended memorization in neural networks. In Proceedings of the 28th USENIX Conference on Security Symposium (Santa Clara, CA, USA) (SEC'19). USENIX Association, USA, 267--284."},{"key":"e_1_3_2_1_4_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al. 2021. Extracting training data from large language models. In 30th USENIX Security Symposium (USENIX Security 21). 2633--2650."},{"key":"e_1_3_2_1_5_1","volume-title":"TEM: High Utility Metric Differential Privacy on Text. arxiv: 2107.07928 [cs.CR]","author":"Carvalho Ricardo Silva","year":"2021","unstructured":"Ricardo Silva Carvalho, Theodore Vasiloudis, and Oluwaseyi Feyisetan. 2021. TEM: High Utility Metric Differential Privacy on Text. arxiv: 2107.07928 [cs.CR]"},{"key":"e_1_3_2_1_6_1","unstructured":"Patrick Chao Alexander Robey Edgar Dobriban Hamed Hassani George J. Pappas and Eric Wong. 2023. Jailbreaking Black Box Large Language Models in Twenty Queries. arxiv: 2310.08419 [cs.LG]"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39077-7_5"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1"},{"key":"e_1_3_2_1_9_1","unstructured":"Yu Chen Tingxin Li Huiming Liu and Yang Yu. 2023a. Hide and Seek (HaS): A Lightweight Framework for Prompt Privacy Protection. arxiv: 2309.03057 [cs.CR]"},{"key":"e_1_3_2_1_10_1","unstructured":"Ajinkya Deshmukh Saumya Banthia and Anantha Sharma. 2023. Life of PII -- A PII Obfuscation Transformer. arxiv: 2305.09550 [cs.CL]"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583512"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2013.53"},{"key":"e_1_3_2_1_13_1","volume-title":"International colloquium on automata, languages, and programming","author":"Dwork Cynthia","unstructured":"Cynthia Dwork. 2006. Differential privacy. In International colloquium on automata, languages, and programming. Springer, 1--12."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371856"},{"key":"e_1_3_2_1_15_1","unstructured":"Valentin Hartmann Anshuman Suri Vincent Bindschaedler David Evans Shruti Tople and Robert West. 2023. SoK: Memorization in General-Purpose Large Language Models. arxiv: 2310.18362 [cs.CL] https:\/\/arxiv.org\/abs\/2310.18362"},{"key":"e_1_3_2_1_16_1","unstructured":"Edward J. Hu Yelong Shen Phillip Wallis Zeyuan Allen-Zhu Yuanzhi Li Shean Wang Lu Wang and Weizhu Chen. 2021. LoRA: Low-Rank Adaptation of Large Language Models. arxiv: 2106.09685 [cs.CL]"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10639-023-11834-1"},{"key":"e_1_3_2_1_18_1","unstructured":"Zhigang Kan Linbo Qiao Hao Yu Liwen Peng Yifu Gao and Dongsheng Li. 2023. Protecting User Privacy in Remote Conversational Systems: A Privacy-Preserving framework based on text sanitization. arxiv: 2306.08223 [cs.CR]"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Daniel Kang Xuechen Li Ion Stoica Carlos Guestrin Matei Zaharia and Tatsunori Hashimoto. 2023. Exploiting Programmatic Behavior of LLMs: Dual-Use Through Standard Security Attacks. arxiv: 2302.05733 [cs.CR]","DOI":"10.1109\/SPW63631.2024.00018"},{"key":"e_1_3_2_1_20_1","unstructured":"Haoran Li Dadi Guo Wei Fan Mingshi Xu Jie Huang Fanpu Meng and Yangqiu Song. 2023a. Multi-step Jailbreaking Privacy Attacks on ChatGPT. arxiv: 2304.05197 [cs.CL]"},{"key":"e_1_3_2_1_21_1","unstructured":"Yansong Li Zhixing Tan and Yang Liu. 2023b. Privacy-Preserving Prompt Tuning for Large Language Model Services. arxiv: 2305.06212 [cs.CL]"},{"key":"e_1_3_2_1_22_1","unstructured":"Anay Mehrotra Manolis Zampetakis Paul Kassianik Blaine Nelson Hyrum Anderson Yaron Singer and Amin Karbasi. 2024. Tree of Attacks: Jailbreaking Black-Box LLMs Automatically. arxiv: 2312.02119 [cs.LG]"},{"key":"e_1_3_2_1_23_1","unstructured":"Stephen Meisenbacher Nihildev Nandakumar Alexandra Klymenko and Florian Matthes. 2024. A Comparative Analysis of Word-Level Metric Differential Privacy: Benchmarking The Privacy-Utility Trade-off. arxiv: 2404.03324 [cs.CL]"},{"key":"e_1_3_2_1_24_1","unstructured":"Milad Nasr Nicholas Carlini Jonathan Hayase Matthew Jagielski A. Feder Cooper Daphne Ippolito Christopher A. Choquette-Choo Eric Wallace Florian Tram\u00e8r and Katherine Lee. 2023. Scalable Extraction of Training Data from (Production) Language Models. arxiv: 2311.17035 [cs.LG]"},{"key":"e_1_3_2_1_25_1","unstructured":"Keivalya Pandya and Mehfuza Holia. 2023. Automating Customer Service using LangChain: Building custom open-source GPT Chatbot for organizations. arxiv: 2310.05421 [cs.CL]"},{"key":"e_1_3_2_1_26_1","unstructured":"Anselm Paulus Arman Zharmagambetov Chuan Guo Brandon Amos and Yuandong Tian. 2024. AdvPrompter: Fast Adaptive Adversarial Prompting for LLMs. arxiv: 2404.16873 [cs.CR]"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Richard Plant Valerio Giuffrida and Dimitra Gkatzia. 2022. You Are What You Write: Preserving Privacy in the Era of Large Language Models. arxiv: 2204.09391 [cs.CL]","DOI":"10.2139\/ssrn.4417900"},{"key":"e_1_3_2_1_28_1","volume-title":"Undesirable Memorization in Large Language Models: A Survey. arXiv preprint arXiv:2410.02650","author":"Satvaty Ali","year":"2024","unstructured":"Ali Satvaty, Suzan Verberne, and Fatih Turkmen. 2024. Undesirable Memorization in Large Language Models: A Survey. arXiv preprint arXiv:2410.02650 (2024)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"e_1_3_2_1_30_1","volume-title":"Beyond Memorization: Violating Privacy Via Inference with Large Language Models. arxiv: 2310.07298 [cs.AI]","author":"Staab Robin","year":"2023","unstructured":"Robin Staab, Mark Vero, Mislav Balunovi?, and Martin Vechev. 2023. Beyond Memorization: Violating Privacy Via Inference with Large Language Models. arxiv: 2310.07298 [cs.AI]"},{"key":"e_1_3_2_1_31_1","volume-title":"Kabilan Elangovan, Laura Gutierrez, Ting Fang Tan, and Daniel Shu Wei Ting.","author":"Thirunavukarasu Arun James","year":"2023","unstructured":"Arun James Thirunavukarasu, Darren Shu Jeng Ting, Kabilan Elangovan, Laura Gutierrez, Ting Fang Tan, and Daniel Shu Wei Ting. 2023. Large language models in medicine. Nature medicine, Vol. 29, 8 (2023), 1930--1940."},{"key":"e_1_3_2_1_32_1","unstructured":"Kushal Tirumala Aram H. Markosyan Luke Zettlemoyer and Armen Aghajanyan. 2022. Memorization Without Overfitting: Analyzing the Training Dynamics of Large Language Models. arxiv: 2205.10770 [cs.CL]"},{"key":"e_1_3_2_1_33_1","volume-title":"Basem Suleiman, Tariq Ahamed Ahanger, Zawar Shah, Junaid Qadir, and Salil S. Kanhere.","author":"Ullah Imdad","year":"2023","unstructured":"Imdad Ullah, Najm Hassan, Sukhpal Singh Gill, Basem Suleiman, Tariq Ahamed Ahanger, Zawar Shah, Junaid Qadir, and Salil S. Kanhere. 2023. Privacy Preserving Large Language Models: ChatGPT Case Study Based Vision and Framework. arxiv: 2310.12523 [cs.CR]"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.26190\/669X-A286"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3491101.3519665"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP48485.2024.10448234"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-5446"},{"key":"e_1_3_2_1_38_1","volume-title":"Jailbroken: How Does LLM Safety Training Fail?arxiv: 2307.02483 [cs.LG]","author":"Wei Alexander","year":"2023","unstructured":"Alexander Wei, Nika Haghtalab, and Jacob Steinhardt. 2023. Jailbroken: How Does LLM Safety Training Fail?arxiv: 2307.02483 [cs.LG]"},{"key":"e_1_3_2_1_39_1","article-title":"Loose-lipped large language models spill your secrets: The privacy implications of large language models","volume":"36","author":"Winograd Amy","year":"2023","unstructured":"Amy Winograd. 2023. Loose-lipped large language models spill your secrets: The privacy implications of large language models. Harvard Journal of Law & Technology, Vol. 36, 2 (2023).","journal-title":"Harvard Journal of Law & Technology"},{"key":"e_1_3_2_1_40_1","unstructured":"Shijie Wu Ozan Irsoy Steven Lu Vadim Dabravolski Mark Dredze Sebastian Gehrmann Prabhanjan Kambadur David Rosenberg and Gideon Mann. 2023. BloombergGPT: A Large Language Model for Finance. arxiv: 2303.17564 [cs.LG]"},{"key":"e_1_3_2_1_41_1","volume-title":"Density-Aware Differentially Private Textual Perturbations Using Truncated Gumbel Noise. The International FLAIRS Conference Proceedings (2021","author":"Xu Nan","year":"2021","unstructured":"Nan Xu, Oluwaseyi Feyisetan, Abhinav Aggarwal, Zekun Xu, and Nathanael Teissier. 2021. Density-Aware Differentially Private Textual Perturbations Using Truncated Gumbel Noise. The International FLAIRS Conference Proceedings (2021). https:\/\/api.semanticscholar.org\/CorpusID:236618950"},{"key":"e_1_3_2_1_42_1","volume-title":"A Differentially Private Text Perturbation Method Using a Regularized Mahalanobis Metric. arxiv","author":"Xu Zekun","year":"2010","unstructured":"Zekun Xu, Abhinav Aggarwal, Oluwaseyi Feyisetan, and Nathanael Teissier. 2020. A Differentially Private Text Perturbation Method Using a Regularized Mahalanobis Metric. arxiv: 2010.11947 [cs.CL]"},{"key":"e_1_3_2_1_43_1","volume-title":"Chow","author":"Yue Xiang","year":"2021","unstructured":"Xiang Yue, Minxin Du, Tianhao Wang, Yaliang Li, Huan Sun, and Sherman S. M. Chow. 2021. Differential Privacy for Text Analytics via Natural Text Sanitization. arxiv: 2106.01221 [cs.CL]"},{"key":"e_1_3_2_1_44_1","unstructured":"Shenglai Zeng Yaxin Li Jie Ren Yiding Liu Han Xu Pengfei He Yue Xing Shuaiqiang Wang Jiliang Tang and Dawei Yin. 2024. Exploring Memorization in Fine-tuned Language Models. arxiv: 2310.06714 [cs.AI]"}],"event":{"name":"WWW '25: The ACM Web Conference 2025","location":"Sydney NSW Australia","acronym":"WWW '25","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM on Web Conference 2025"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714531","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3696410.3714531","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:33Z","timestamp":1750295913000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714531"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,22]]},"references-count":44,"alternative-id":["10.1145\/3696410.3714531","10.1145\/3696410"],"URL":"https:\/\/doi.org\/10.1145\/3696410.3714531","relation":{},"subject":[],"published":{"date-parts":[[2025,4,22]]},"assertion":[{"value":"2025-04-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}