acceptodds
Under review as a conference paper at ICLR 2027

SeqBench: Benchmarking Cumlulative Privacy Leakage In Longitudinal Text

Abstract

Language models infer a writer’s attributes from evidence accumulated across posts and linked accounts. We call a target cumulative when the history recovers it and no post alone does. We prove that a per-post anonymiser that detects no more than an evidence-based reader and edits only what it detects leaves every cumulative target recoverable, and that, for a reader of the current archive, only revising released posts repairs a released leak. An anonymiser that edits only what it detects must therefore be sequential: it reads the history and revises what it has released. SeqBench is built to measure this separation. Its eleven synthetic corpora of up to 1,000 personas spread designed targets over several posts, most across platforms, and a blind leave-one-post-out certifier admits a target as cumulative only if a reader recovers it from its support and from no labelled post alone. On six further corpora from the same generator, labelled one post at a time, which mark no conjunctive route, the only kind per-post anonymisation provably cannot see, our sequential anonymiser edits 406 posts that per-post leaves unedited (86 the other way) and reaches back to 282 of its edited posts after release. Under a same-family attacker both cut strict value recall from 0.347 to 0.049 (per-post) and 0.056 (sequential), with no significant difference (p = 0.30); the 90% interval of their type-F1 difference lies within ±0.031. In a four-seat loop run by one minimal-edit script, the sequential scope edits fewer posts and keeps more utility in every seat (+0.058, p = 0.002), while round-4 type recall does not differ significantly.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.