Re-identification of De-identified Documents with Autoregressive Infilling
Lucas Georges Gabriel Charpentier, Pierre Lison
Abstract
Documents revealing sensitive information about human individuals must often be deidentified prior to being released. This deidentification is typically done by masking all mentions of personal identifiers, thereby making it more difficult to uncover the identity of the person(s) in question. To investigate the robustness of de-identification methods, we present a novel, RAG-inspired approach that attempts the reverse process of re-identification based on a database of documents representing background knowledge. Given a de-identified text in which personal identifiers have been masked, the re-identification proceeds in two steps. A retriever first selects from the background knowledge passages deemed relevant for the re-identification. Those passages are then provided to an infilling model which seeks to infer the original content of each text span. This process is repeated until all masked spans are replaced. We evaluate the re-identification on two datasets based on Wikipedia biographies and court cases. Results show that (1) as many as 80% of de-identified text spans can be successfully recovered and (2) the reidentification accuracy increases along with the level of background knowledge. whether the de-identification has adequately con-044 cealed the identity of the person(s) mentioned in 045 the original document. Many evaluation techniques 046 assess the performance of de-identification meth-047 ods by comparing their outputs with those of hu-048 man experts (Lison et al., 2021; Pilán et al., 2022). 049 However, those evaluation techniques depend on 050 the availability of human annotations and may be 051 prone to human errors and inconsistencies. 052 An alternative approach to evaluating the de-053 identification performance is through an automated 054 adversary that attempts to infer the original context 055 of each text span that had been masked (Mozes and
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni et al.NeurIPS 2020 · 19,162 citations
- ColBERT: Efficient and Effective Passage Search via Contextualized Late Interaction over BERTOmar Khattab, Matei ZahariaSIGIR 2020 · 1,246 citations
- Anonymisation Models for Text Data: State of the art, Challenges and Future DirectionsPierre Lison, Ildikó Pilán, David Sánchez, Montserrat Batet et al.ACL 2021
- GLM: General Language Model Pretraining with Autoregressive Blank InfillingZhengxiao Du, Yujie Qian, Xiao Liu, Ming Ding et al.ACL 2022
Related papers
- On the Vulnerability of Applying Retrieval-Augmented Generation within Knowledge-Intensive Application DomainsXun Xian, Ganghua Wang, Xuan Bi, Rui Zhang et al.ICML 2025
- From Weak Cues to Real Identities: Evaluating Inference-Driven De-Anonymization in LLM AgentsMyeongseob Ko, Jihyun Jeong, Sumiran Thakur, Gyuhak Kim et al.ICML 2026 · 3 citations
- Text Embeddings Reveal (Almost) As Much As TextJohn X. Morris, Volodymyr Kuleshov, Vitaly Shmatikov, Alexander M. RushEMNLP 2023 · 60 citations
- Large-scale online deanonymization with LLMsSimon Lermen, Daniel Paleka, Joshua Swanson, Michael Aerni et al.USENIX Security 2026 · 20 citations
- Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented GenerationAli Naseh, Yuefeng Peng, Anshuman Suri, Harsh Chaudhari et al.CCS 2025
