DP-VAE: Human-Readable Text Anonymization for Online Reviews with Differentially Private Variational Autoencoders
Benjamin Weggenmann, Valentin Rublack, Michael Andrejczuk, Justus Mattern, Florian Kerschbaum
Abstract
While vast amounts of personal data are shared daily on public online platforms and used by companies and analysts to gain valuable insights, privacy concerns are also on the rise: Modern authorship attribution techniques have proven effective at identifying individuals from their data, such as their writing style or behavior of picking and judging movies. It is hence crucial to develop data sanitization methods that allow sharing of users’ data while protecting their privacy and preserving quality and content of the original data. In this paper, we tackle anonymization of textual data and propose an end-to-end differentially private variational autoencoder architecture. Unlike previous approaches that achieve differential privacy on a per-word level through individual perturbations, our solution works at an abstract level by perturbing the latent vectors that provide a global summary of the input texts. Decoding an obfuscated latent vector thus not only allows our model to produce coherent, high-quality output text that is human-readable, but also results in strong anonymization due to the diversity of the produced data. We evaluate our approach on IMDb movie and Yelp business reviews, confirming its anonymization capabilities and preservation of the semantics and utility of the original sentences.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3163f9a4-4378-446c-a9e5-bbe079d219c5Cited by top-tier papers5
- Synthetic Text Generation with Differential Privacy: A Simple and Practical RecipeXiang Yue, Huseyin A. Inan, Xuechen Li, Girish Kumar et al.ACL 2023 · 24 citations
- Differentially Private Language Models for Secure Data SharingJustus Mattern, Zhijing Jin, Benjamin Weggenmann, Bernhard Schölkopf et al.EMNLP 2022 · 16 citations
- FLAIM: AIM-based Synthetic Data Generation in the Federated SettingSamuel Maddock, Graham Cormode, Carsten MapleKDD 2024 · 5 citations
- StyleRemix: Interpretable Authorship Obfuscation via Distillation and Perturbation of Style ElementsJillian Fisher, Skyler Hallinan, Ximing Lu, Mitchell L. Gordon et al.EMNLP 2024 · 4 citations
- CLOAK: Contrastive Guidance for Latent Diffusion-Based Data ObfuscationXin Yang, Omid ArdakanianUbiComp 2026
Builds on3
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- The Curious Case of Neural Text DegenerationAri Holtzman, Jan Buys, Li Du, Maxwell Forbes et al.ICLR 2020 · 4,112 citations
- A4NT: Author Attribute Anonymity by Adversarial Training of Neural Machine TranslationRakshith Shetty, Bernt Schiele, Mario FritzUSENIX Security 2018 · 104 citations
Related papers
- Style Pooling: Automatic Text Style Obfuscation for Improved Classification FairnessFatemehsadat Mireshghallah, Taylor Berg-KirkpatrickEMNLP 2021 · 6 citations
- Explainable Disentangled Representation Learning for Generalizable Authorship Attribution in the Era of Generative AIHieu Man, Van-Cuong Pham, Nghia Trung Ngo, Franck Dernoncourt et al.ACL 2026
- A Neural Approach to Spatio-Temporal Data Release with User-Level Differential PrivacyRitesh Ahuja, Sepanta Zeighami, Gabriel Ghinita, Cyrus ShahabiSIGMOD 2023 · 14 citations
- De-Anonymization at Scale via Tournament-Style AttributionLirui Zhang, Huishuai ZhangACL 2026
- Unsupervised Opinion Summarization as Copycat-Review GenerationArthur Brazinskas, Mirella Lapata, Ivan TitovACL 2020 · 14 citations
