TASK: Task‑Aware, Security‑Iterative Prompt Sanitization Framework
Abstract
Cloud-based large language models enable users to complete complex document-processing tasks without local deployment. However, prompts must leave the local environment during transmission to the cloud, creating substantial privacy risks. Existing prompt-sanitization methods commonly address this problem through substitution, obfuscation, or LLM-based rewriting. Such methods may excessively replace sensitive content or rely on rewriting criteria that do not align with the requirements of the current task, resulting in the loss of task-required information and substantially degrading model output quality. To address this problem, we make two key observations: spans of the same sensitive type can play different semantic roles across tasks, and residual risk after initial sanitization is typically concentrated in a small number of retained or weakly transformed spans and their associated evidence. Building on these observations, we propose TASK, a task-aware iterative prompt sanitization framework for cloud-based LLM inference. TASK jointly analyzes the semantic relevance of sensitive spans to the task and their local context to identify information that genuinely supports task completion. It then selects multi-level transformations, including retention, abstraction, generalization, and masking. To further reduce residual risk, TASK evaluates initially sanitized prompts using sensitive-value recovery and attribute-inference attacks, and iteratively adjusts high-risk decisions until the result satisfies the required privacy level. We evaluate TASK on document summarization, narrative question answering, and long-context question answering. The results show that TASK improves task quality and privacy scores by 23.72% and 8.64% on average, respectively.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.