Skip to main content

DP-MLM

PyPI version GitHub stars License

This is the code and package repository for the ACL 2024 Findings paper: DP-MLM: Differentially Private Text Rewriting Using Masked Language Models

Setup

Installation

You can install the package directly using:

pip install dpmlm

Optionally, you can install from source. In this repository, you will find a requirements.txt file, which contains all necessary Python dependencies.

Resource Bootstrapping

Before running the mechanism, you need to download the necessary NLTK libraries:

from dpmlm.utils import setup_resources

setup_resources()

Usage of DP-MLM

The core logic resides in the DPMLM class. You can now initialize it with custom calibration bounds to ensure the DP privatization is tuned to your specific model (and bounding strategy).

from dpmlm import DPMLM
from dpmlm.utils import calculate_logit_bounds, cleanup

# 1. (Optional) Calibrate bounds for your specific model (e.g., RoBERTa)
bounds = calculate_logit_bounds("FacebookAI/roberta-base")

# 2. Instantiate the mechanism
M = DPMLM(MODEL="FacebookAI/roberta-base", calibration=bounds, bound_strategy=None)

# 3. Rewrite text
private_text = M.dpmlm_rewrite("Hello world, this is a private text.", epsilon=25)

# 4. Cleanup (optional, when finished)
cleanup(model_instances=[M])

If you want to set a bounding strategy for the clip bounds (beyond simple min/max selection), you can do so by passing a lambda function:

# strategy as used in the paper
strategy = lambda mean, std, low, high: (mean, mean + 4*std)
M = DPMLM(MODEL="FacebookAI/roberta-base", calibration=bounds, bound_strategy=strategy)

DP-MLM Batched Mode

For longer documents, the batched mode provides significant performance increases by parallelizing masked token predictions on the GPU.

To use batching, simply run:

M.dpmlm_rewrite_batch("Large document text...", epsilon=25, batch_size=16)

Depending on your setup, you may need to tweak the batch_size parameter for the most optimal performance gains.

Handling Direct and Indirect Identifiers

The DP-IPI extension of DP-MLM follows from research work (see below) that targets specifically the privatization of indirect personally identifiers in texts.

To activate this feature, you must instantiate DP-MLM accordingly:

M = DPMLM(MODEL="FacebookAI/roberta-base", calibration=bounds, bound_strategy=None, IPI=TRUE, PII=True)

PII mode uses Presidio to mask out personally identifiable information, thereby following strict redaction and bypassing DP-MLM.

In IPI mode, only tokens tagged as indirect personal identifiers are privatized. This is determined by a specified fine-tuned IPI detection model. We provide a default one, but you can also specify your own with IPI_model.

In both cases, you must also set flags when calling rewrite functions, e.g.:

private_text = M.dpmlm_rewrite("Hello world, this is a private text.", epsilon=25, IPI=True, PII=False)

Input Document Length

As of a release in 2025, DP-MLM no longer has the shortcoming of the 512 token context window (256 with concatentation), which was due to the limitations of MLM context windows.

Now, DP-MLM operates with a sliding window, where the maximum context is given, centered around the target word to be privatized. Thus, DP-MLM now works on arbitrarily long documents!

Usage of other evaluated models

There is one other included file for replication of the paper, which is easily importable and reusable:

  • LLMDP.py: implementations of both DP-Paraphrase and DP-Prompt. Note that for DP-Prompt, you will need to download the corresponding LMs, i.e., from Hugging Face.

M = LLMDP.DPPrompt()

M.privatize("hello world", epsilon=100)

Important note

In order to use LLMDP.DPParaphrase, you must download the fine-tuned model directory. This can be found at the following link: Model

Citation

Please consider citing the original work that introduced DP-MLM. Thank you!

@inproceedings{meisenbacher-etal-2024-dp,
    title = "{DP}-{MLM}: Differentially Private Text Rewriting Using Masked Language Models",
    author = "Meisenbacher, Stephen  and
      Chevli, Maulik  and
      Vladika, Juraj  and
      Matthes, Florian",
    editor = "Ku, Lun-Wei  and
      Martins, Andre  and
      Srikumar, Vivek",
    booktitle = "Findings of the Association for Computational Linguistics: ACL 2024",
    month = aug,
    year = "2024",
    address = "Bangkok, Thailand",
    publisher = "Association for Computational Linguistics",
    url = "https://aclanthology.org/2024.findings-acl.554/",
    doi = "10.18653/v1/2024.findings-acl.554",
    pages = "9314--9328"
}

If you use the DP-IPI variant, please cite:

Coming soon!

Metadata

Release files for dpmlm 1.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dpmlm 1.3.0
File Size Uploaded
dpmlm-1.3.0.tar.gz 266.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dpmlm 1.3.0
File Interpreter ABI Platform
dpmlm-1.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 532.6 kB

Release files / dpmlm-1.3.0.tar.gz

Download URL dpmlm-1.3.0.tar.gz
Size 266.4 kB
Tags Source
SHA-256 checksum
How to use checksums
bd88cbd1d65749a122a3507461195160c51ebf6803a9254222b5bcece61386e3
BLAKE2b-256 checksum
How to use checksums
5a4b17977277da2d8fecf075a5160a2aa3909f0ec7ac251e6588571dfa75ac4c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.20

Release files / dpmlm-1.3.0-py3-none-any.whl

Download URL dpmlm-1.3.0-py3-none-any.whl
Size 266.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7b5b8a77edf67386c1f66327c67d92abef3749edeceaae9cb81ae59bac21d3cb
BLAKE2b-256 checksum
How to use checksums
dd04e4e3ece4eea59ec2f81089c61f5aad18268b7b62d217357f7b278ee08f2a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.20

Release history Release notifications | RSS feed

This release

1.3.0 This release

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page