English

SoK: Semantic Privacy in Large Language Models

Cryptography and Security 2025-07-17 v2 Artificial Intelligence

Abstract

As Large Language Models (LLMs) are increasingly deployed in sensitive domains, traditional data privacy measures prove inadequate for protecting information that is implicit, contextual, or inferable - what we define as semantic privacy. This Systematization of Knowledge (SoK) introduces a lifecycle-centric framework to analyze how semantic privacy risks emerge across input processing, pretraining, fine-tuning, and alignment stages of LLMs. We categorize key attack vectors and assess how current defenses, such as differential privacy, embedding encryption, edge computing, and unlearning, address these threats. Our analysis reveals critical gaps in semantic-level protection, especially against contextual inference and latent representation leakage. We conclude by outlining open challenges, including quantifying semantic leakage, protecting multimodal inputs, balancing de-identification with generation quality, and ensuring transparency in privacy enforcement. This work aims to inform future research on designing robust, semantically aware privacy-preserving techniques for LLMs.

Keywords

Cite

@article{arxiv.2506.23603,
  title  = {SoK: Semantic Privacy in Large Language Models},
  author = {Baihe Ma and Yanna Jiang and Xu Wang and Guangsheng Yu and Qin Wang and Caijun Sun and Chen Li and Xuelei Qi and Ying He and Wei Ni and Ren Ping Liu},
  journal= {arXiv preprint arXiv:2506.23603},
  year   = {2025}
}
R2 v1 2026-07-01T03:39:06.263Z