Agentic re-identification on 27 transcripts GPT-5.1 attacker
15Re-ID Success CountOne-shot w/ detailed prompt
Evaluation Results
| Method | Links | ||
|---|---|---|---|
| One-shot w/ detailed promptPrompting Strategy=detailed prompt2026.05 | 15 | 55.6 | |
| Presidio2026.05 | 13 | 48.1 | |
| One-shot w/ minimal promptPrompting Strategy=minimal prompt2026.05 | 10 | 37 | |
| AURA (8-attribute, GPT-4.1)Privacy Strategy=8-attribute, Base Model=GPT-4.12026.05 | 6 | 22.2 | |
| Anonymizer2026.05 | 6 | 22.2 | |
| AURA (8-attribute, Qwen3.5-27B)Privacy Strategy=8-attribute, Base Model=Qwen3.5-27B2026.05 | 4 | 14.8 | |
| DP-MLMDifferential Privacy Epsilon (ε)=502026.05 | 4 | 14.8 | |
| DP-MLMDifferential Privacy Epsilon (ε)=1002026.05 | 4 | 14.8 | |
| DP-MLMDifferential Privacy Epsilon (ε)=1202026.05 | 4 | 14.8 | |
| DP-MLMDifferential Privacy Epsilon (ε)=1402026.05 | 4 | 14.8 | |
| DP-MLMDifferential Privacy Epsilon (ε)=702026.05 | 3 | 11.1 | |
| AURA (adapt. privacy, Qwen3.5-27B)Privacy Strategy=adapt. privacy, Base Model=Qwen3.5-27B2026.05 | 2 | 7.4 | |
| AURA (adapt. privacy, Qwen3.5-35B-A3B)Privacy Strategy=adapt. privacy, Base Model=Qwen3.5-35B-A3B2026.05 | 2 | 7.4 | |
| AURA (adapt. privacy, GPT-4.1)Privacy Strategy=adapt. privacy, Base Model=GPT-4.12026.05 | 2 | 7.4 | |
| AURA (pure adaptive, GPT-4.1)Privacy Strategy=pure adaptive, Base Model=GPT-4.12026.05 | 2 | 7.4 | |
| AURA (8-attribute, Qwen3.5-35B-A3B)Privacy Strategy=8-attribute, Base Model=Qwen3.5-35B-A3B2026.05 | 2 | 7.4 | |
| DP-MLMDifferential Privacy Epsilon (ε)=102026.05 | 0 | 0 | |
| DP-MLMDifferential Privacy Epsilon (ε)=302026.05 | 0 | 0 |