acceptodds
Under review as a conference paper at ICLR 2027

Leak Less, Solve More: Reinforced Anonymization for Privacy-Preserving Local-Cloud LLM Collaboration

Abstract

Privacy concerns have driven users to deploy trusted small language models (SLMs) locally. However, such SLMs may struggle with complex queries and therefore consult a cloud LLM before composing the final answer locally, forming a local–cloud–local collaboration. Although the forwarded query can be anonymized, a cloud LLM may still infer private attributes such as age, location, or occupation from semantic cues. Yet aggressively removing such cues can also eliminate information essential for solving the task. This creates a fundamental challenge: anonymization needs to suppress privacy leakage while preserving task-critical information. Existing anonymization methods either fail the inference attack or optimize anonymized text in isolation without verifying whether the downstream task remains solvable. Moreover, no existing benchmark jointly evaluates privacy leakage and task utility on the same query. To address these gaps, we first construct a benchmark of 2200 privacy-bearing queries drawn from four QA datasets. Each query is paired with four-option privacy probes that measure an LLM attacker's attribute inference accuracy (AIA), as well as a verifiable answer for measuring the end-to-end utility of the collaborative pipeline. We then introduce ReAnon, a reinforced anonymization framework that trains a local SLM to rewrite queries into task-equivalent representations against inference attacks while preserving downstream utility. The SLM is trained with supervised fine-tuning (SFT) and multi-objective GRPO using joint utility and entropy-based privacy reward. With Qwen3.5-4B as the local SLM and Qwen3.5-27B as the cloud LLM, the resulting SLM reduces average AIA by 14.9 points (from 79.76 to 64.82) while improving utility by 1.7 points (from 61.76 to 63.50) over its zero-shot counterpart, achieving the lowest AIA, the highest utility, and the best average rank among all evaluated protection methods.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.