arXiv · 2609.21340
Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees
Abstract
Empirical identity leakage from released text is increasingly driven by attackers that combine large language models (LLMs) with auxiliary knowledge to link documents to individuals. Existing audits typically report success rates for specific attack pipelines but lack finite-sample statistical guarantees, while training-time protections such as differential privacy are difficult to translate into release-time decisions for individual natural-language documents. We introduce Conformal Privacy Auditing(CPA), a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries. CPA outputs a conformal ambiguity set of candidate identities that is guaranteed to contain the true identity with user-chosen confidence under exchangeability, together with an interpretable leakage proxy derived from set size. CPA supports both logit-access and sampling-only attackers, enabling audits of open-source models and proprietary API models in a unified framework. Across multiple release benchmarks and attacker configurations, CPA achieves calibrated coverage and reveals sharp shifts in certified identifiability as auxiliary knowledge, LLM augmentation, and release mechanisms vary, providing a statistically grounded basis for reporting and comparing release-time linkage risk across attacker configurations, datasets, and release mechanisms alike.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Shuo Huang, Gholamreza Haffari, Xingliang Yuan, Ting Yu, Lizhen Qu. 2026-09-18. Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees. https://arxiv.org/abs/2609.21340
Cite the original work for its findings. Save a collection to share your selection of sources.