Aug 2026· Scientific Journal of Intelligent Systems Research· Vol 8, pp. 44-56· 0 citations· 24 references
TL;DR
This paper introduces the development path of sensitive data detection technology, including rule-based methods, older machine-learning techniques, and currently popular pre-trained language models, and introduces the research content of LLM-driven zero-shot named entity recognition, open information extraction and privacy detection.
Abstract
With the rapid growth of digital information, the risk of sensitive information leakage in textual data, including personally identifiable information, medical privacy, financial data, and corporate confidential information, has become increasingly prominent. Traditional sensitive information detection methods, which mainly rely on rule matching, supervised learning, and manual annotation, struggle to meet the requirements of identifying diverse, open-domain, and dynamically evolving sensitive information. In recent years, Large Language Models (LLMs) have provided a new technical paradigm for zero-shot sensitive information detection without annotated data, owing to their powerful semantic understanding, contextual reasoning, and knowledge transfer capabilities. Through prompt learning, in-context learning, and instruction-driven information extraction approaches, LLMs can achieve flexible sensitive information identification in scenarios involving unknown sensitive categories and cross-domain applications. However, LLMs themselves introduce new security risks, including training data leakage, privacy memorization, and prompt injection attacks, posing significant challenges to sensitive information detection technologies. This paper presents a systematic survey of the development of LLM-based zero-shot sensitive information detection techniques. First, it introduces the development path of sensitive data detection technology, including rule-based methods, older machine-learning techniques, and currently popular pre-trained language models. Then it introduces the research content of LLM-driven zero-shot named entity recognition, open information extraction and privacy detection. List the privacy-leakage risks and corresponding defence measures for current applications of LLMs. Finally, this paper presents some future research directions for the above work and provides a path for the development of efficient, secure and trustworthy intelligent sensitive information detection systems.
A systematic evaluation of several proprietary and open-source Large Language Models for sensitive entity extraction from documents and a form-filling pipeline that uses vision-capable LLMs to label form fields, generate realistic synthetic personas, and fill real blank forms, enabling reproducible evaluation across diverse layouts.
Errita Xu, Stefan Larson, Kevin Leach· Proceedings of the 2026 ACM...· 0 citations
Phishing attacks via desktops, smartphones and internet of things devices are becoming increasingly sophisticated, posing critical security challenges for digital infrastructures. Defending against these attacks requires AI-based detection models that maintain high accuracy, since false positives or negatives can lead to severe breaches, while remaining lightweight enough to run on resource-constrained client devices. Split Learning (SL) meets these requirements by having clients compute only initial model layers locally and transmit intermediate activations (“smashed data”) to a server for the remaining inference, avoiding direct sharing of raw inputs. However, prior work in the image domain has shown that smashed data can leak original content, suggesting that SL may not be safe for user privacy. Therefore, it is essential to investigate whether these privacy risks also extend to language-model–based SL systems, which have fundamentally different neural network architectures, including attention mechanism. This paper introduces the Semantic Information Reconstruction Attack (SIRA), a novel framework designed to infer sensitive semantic elements directly from smashed data by leveraging the generative capabilities of large language models. In experiments on real-world phishing datasets, SIRA outperforms conventional reconstruction attacks in accurately inferring private webpage information. These findings reveal a potential privacy vulnerability in SL-based language models for security applications and motivate the development of targeted defense strategies.
Yushin Kim, Jungin Kim, Yongseok Kwon et al.· International Journal of Inf...· 0 citations
DeBERTa-Sentinel is introduced, a responsible AI-generated text detection framework leveraging DeBERTa-v3's disentangled attention to capture subtle structural irregularities in synthetic content and promotes trustworthy, ethical, and human-centric AI systems.
While the privacy risks of multimodal large language models (MLLMs) have drawn significant attention, the unique vulnerabilities of domain-specific MLLMs remain largely underexplored. Focusing on document understanding MLLMs for identity document processing, this paper investigates the privacy issues inherent in Key Information Extraction (KIE) tasks. We reveal that when input images lack sufficient visual evidence, these models often rely on memorized field relations from training data to infer missing content, thereby leaking multiple correlated fields containing sensitive personal information. To mitigate this risk, we make three key contributions.First, we propose the Dynamic Relational Unlearning Framework (DRUF) which comprises a Relational Decoupling Unlearning (RDU) module and a dynamic set update mechanism. It suppresses the leakage of high-risk field pairs while preserving KIE performance.Second, we introduce DocPrivacyBench, a novel benchmark to systematically evaluate a model's susceptibility to privacy leakage under conditions of absent or minimal visual evidence.Third, we evaluate three MLLMs and six unlearning methods using this benchmark, assessing both post-unlearning leakage suppression and utility preservation.Our results demonstrate that existing MLLMs consistently exhibit privacy leakage when visual evidence is scarce, particularly on noisier datasets. In contrast, DRUF outperforms the strongest baseline by improving leakage suppression by 4.8 percentage points, effectively mitigating privacy risks while maintaining robust document information extraction performance.
Beining Xu, Hairui Wang, Jiaxin Wang et al.· 0 citations
In the domain of confidentiality management, secret point recognition stands as a precise and efficient technical solution. However, it faces significant hurdles in machine learning-based implementations: stringent confidentiality constraints on confidential data and restricted data accessibility often lead to insufficient labeled samples, which severely compromise recognition performance. To address this challenge, this paper proposes a secret point recognition algorithm that leverages test-time augmentation (TTA) based on a large language model (LLM) and entropy increase judgment. The algorithm operates in two key phases. During the training phase, a pre-trained language model is fine-tuned using a small volume of labeled confidential data to establish a foundational classification capability. During inference, an LLM is employed to paraphrase the input text, generating multiple variants that retain the core semantics while adopting diverse linguistic styles. To ensure increased diversity of the paraphrased text, an entropy increase judgment is introduced. These paraphrased texts serve as augmented data and are then fed into the fine-tuned classification model to produce preliminary predictions. Finally, a dedicated aggregation strategy consolidates these preliminary results to yield the final prediction for the original input text. The results of experiments using simulated confidential data indicate that the proposed algorithm can effectively improve recognition accuracy, demonstrating its superiority in low-sample scenarios.
Zhendong Wu, Hu Li, Liang Zhang et al.· International Conference on...· 0 citations
This survey provides the first comprehensive and systematic review of text anonymization methods published between 2020 and 2025, covering 48 primary studies identified through a structured search and rigorous screening procedure and reveals a growing shift from identifier‐centric de‐identification toward context‐aware anonymization.
Marina Litvak, A. Jorge· WIREs Data Mining and Knowle...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.