跳到正文
arXiv:cs.CL· Teng-Ruei Chen·· 3 小时前AI 评分53

arXiv 论文测量 LLM 路由元数据泄露敏感话题隐私并测试缓解方法

Sensitive-Topic Leakage Through LLM Routing Metadata: Measurement and Mitigation

AI 导读

arXiv 论文(arXiv:2610.09981)测量 LLM 路由器的模型选择元数据如何泄露敏感话题隐私,基于 WildChat-1M 和 LMSYS-Chat-1M 共 170 万条真实请求,覆盖两种成本/质量路由器和一个领域路由器。

正文

View PDF HTML (experimental)

Abstract:LLM routers pick a cheap or expensive model per request by its content, and many gateways and some cloud platforms can log that choice with content logging off. We measure this privacy channel beyond token counts, accounting for noisy labels and repeated prompts. We run pre-registered studies on 1.7 million real requests (WildChat-1M, LMSYS-Chat-1M) with two cost/quality routers and a domain router, survey eleven systems' logging, and test post-processing defenses. At matched length, the shift's direction depends on category and router. For RouteLLM at the 50% operating point, harassment and self-harm requests reach the strong model 19 points less often than comparable ones on prompts unseen in exploration, medical requests (exploratory: LLM labels failed their gate) 31 points less often on distinct prompts (both post hoc), and sexual requests 10 points more often (secondary); the other router's four are negative. Twenty RouteLLM decisions separate frequent medical askers with AUC 0.71, exploratory and below the pre-registered primary endpoint's 0.75 (domain router: 0.92, an upper estimate). Per-category length-matched parity with accurate labels removes the gap on real traffic, costing at most 0.2 accuracy points on RouterBench (post hoc), where routers' gaps on sensitive subjects (13-42 points, pre-registered) exceed those of an oracle routing by realized accuracy gain (1-11, post hoc). Per-conversation stickiness, per-user budget bands, and pooled parity fail, the last as categories' shifts differ in size or sign. A post hoc exact per-user rate hides only even-prefix strong counts and forfeits most self-assessed routing value; it preserves odd-position decisions, from which a post hoc log attack reaches AUC 0.73 after 20 RouteLLM requests (exploratory).
Comments: 20 pages, 5 figures, 9 tables
Subjects: Cryptography and Security (cs.CR); Computation and Language (cs.CL)
Cite as: arXiv:2610.09981 [cs.CR]
  (or arXiv:2610.09981v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.09981

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Teng-Ruei Chen [view email]
[v1] Wed, 7 Oct 2026 12:47:37 UTC (406 KB)

来源:arXiv:cs.CL · arxiv.org