This is the code and package repository for the ACL 2024 Findings paper: DP-MLM: Differentially Private Text Rewriting Using Masked Language Models
Setup
Installation
You can install the package directly using:
pip install dpmlm
Optionally, you can install from source. In this repository, you will find a requirements.txt file, which contains all necessary Python dependencies.
Resource Bootstrapping
Before running the mechanism, you need to download the necessary NLTK libraries:
from dpmlm.utils import setup_resources
setup_resources()
Usage of DP-MLM
The core logic resides in the DPMLM class. You can now initialize it with custom calibration bounds to ensure the DP privatization is tuned to your specific model (and bounding strategy).
from dpmlm import DPMLM
from dpmlm.utils import calculate_logit_bounds, cleanup
# 1. (Optional) Calibrate bounds for your specific model (e.g., RoBERTa)
bounds = calculate_logit_bounds("FacebookAI/roberta-base")
# 2. Instantiate the mechanism
M = DPMLM(MODEL="FacebookAI/roberta-base", calibration=bounds, bound_strategy=None)
# 3. Rewrite text
private_text = M.dpmlm_rewrite("Hello world, this is a private text.", epsilon=25)
# 4. Cleanup (optional, when finished)
cleanup(model_instances=[M])
If you want to set a bounding strategy for the clip bounds (beyond simple min/max selection), you can do so by passing a lambda function:
# strategy as used in the paper
strategy = lambda mean, std, low, high: (mean, mean + 4*std)
M = DPMLM(MODEL="FacebookAI/roberta-base", calibration=bounds, bound_strategy=strategy)
DP-MLM Batched Mode
For longer documents, the batched mode provides significant performance increases by parallelizing masked token predictions on the GPU.
To use batching, simply run:
M.dpmlm_rewrite_batch("Large document text...", epsilon=25, batch_size=16)
Depending on your setup, you may need to tweak the batch_size parameter for the most optimal performance gains.
Handling Direct and Indirect Identifiers
The DP-IPI extension of DP-MLM follows from research work (see below) that targets specifically the privatization of indirect personally identifiers in texts.
To activate this feature, you must instantiate DP-MLM accordingly:
M = DPMLM(MODEL="FacebookAI/roberta-base", calibration=bounds, bound_strategy=None, IPI=TRUE, PII=True)
PII mode uses Presidio to mask out personally identifiable information, thereby following strict redaction and bypassing DP-MLM.
In IPI mode, only tokens tagged as indirect personal identifiers are privatized. This is determined by a specified fine-tuned IPI detection model. We provide a default one, but you can also specify your own with IPI_model.
In both cases, you must also set flags when calling rewrite functions, e.g.:
private_text = M.dpmlm_rewrite("Hello world, this is a private text.", epsilon=25, IPI=True, PII=False)
Input Document Length
As of a release in 2025, DP-MLM no longer has the shortcoming of the 512 token context window (256 with concatentation), which was due to the limitations of MLM context windows.
Now, DP-MLM operates with a sliding window, where the maximum context is given, centered around the target word to be privatized. Thus, DP-MLM now works on arbitrarily long documents!
Usage of other evaluated models
There is one other included file for replication of the paper, which is easily importable and reusable:
LLMDP.py: implementations of bothDP-ParaphraseandDP-Prompt. Note that forDP-Prompt, you will need to download the corresponding LMs, i.e., from Hugging Face.
M = LLMDP.DPPrompt()
M.privatize("hello world", epsilon=100)
Important note
In order to use LLMDP.DPParaphrase, you must download the fine-tuned model directory.
This can be found at the following link: Model
Citation
Please consider citing the original work that introduced DP-MLM. Thank you!
@inproceedings{meisenbacher-etal-2024-dp,
title = "{DP}-{MLM}: Differentially Private Text Rewriting Using Masked Language Models",
author = "Meisenbacher, Stephen and
Chevli, Maulik and
Vladika, Juraj and
Matthes, Florian",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Findings of the Association for Computational Linguistics: ACL 2024",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.findings-acl.554/",
doi = "10.18653/v1/2024.findings-acl.554",
pages = "9314--9328"
}
If you use the DP-IPI variant, please cite:
Coming soon!
Metadata
Release files for dpmlm 1.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dpmlm-1.3.0.tar.gz | 266.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dpmlm-1.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 532.6 kB
Release files / dpmlm-1.3.0.tar.gz
| Download URL | dpmlm-1.3.0.tar.gz |
|---|---|
| Size | 266.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bd88cbd1d65749a122a3507461195160c51ebf6803a9254222b5bcece61386e3
|
|
BLAKE2b-256 checksum How to use checksums |
5a4b17977277da2d8fecf075a5160a2aa3909f0ec7ac251e6588571dfa75ac4c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.10.20
|
Release files / dpmlm-1.3.0-py3-none-any.whl
| Download URL | dpmlm-1.3.0-py3-none-any.whl |
|---|---|
| Size | 266.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7b5b8a77edf67386c1f66327c67d92abef3749edeceaae9cb81ae59bac21d3cb
|
|
BLAKE2b-256 checksum How to use checksums |
dd04e4e3ece4eea59ec2f81089c61f5aad18268b7b62d217357f7b278ee08f2a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.10.20
|