Skip to main content

PrivFill

PyPI version GitHub stars License

privfill is a Python package providing LLM-based local Differential Privacy (DP) mechanisms for text privatization via sentece infilling. It offers easy-to-use wrappers for fine-tuned Hugging Face models. This software was originally presented in the NAACL 2025 findings paper: On the Impact of Noise in Differentially Private Text Rewriting

Installation

Install the package locally in editable mode from your project's root directory:

pip install privfill

Core Prerequisites:

  • Python $\geq$ 3.9
  • PyTorch (CUDA recommended for faster inference)
  • Transformers & NLTK

Basic Usage & Model Selection

Instead of typing Hugging Face repository paths, you can choose from the three built-in models using the SupportedModels enum.

import privfill

# Choose between FLAN_T5_BASE, FLAN_T5_LARGE, and BART_LARGE
engine = privfill.load_pipeline(privfill.SupportedModels.FLAN_T5_BASE, DP=True)

text = "This is a long private document ... which contains sensitive information and should be privatized,"
private_text = engine.privatize(text, epsilon=10)

print(private_text)

As described in the paper, we also create an analagous, non-DP variant of PrivFill. The usage is very similar:

engine = privfill.load_pipeline(privfill.SupportedModels.FLAN_T5_BASE, DP=False)
private_text = engine.privatize(text)

Available Models

Enum Hugging Face Repository Base Mechanism
SupportedModels.FLAN_T5_BASE sjmeis/flan-t5-base-infill-combined DP-Prompt
SupportedModels.FLAN_T5_LARGE sjmeis/flan-t5-large-infill-combined DP-Prompt
SupportedModels.BART_LARGE sjmeis/bart-large-infill-combined DP-BART

Models

We make our three sentence infilling models public. They can be found at this link.

Comparison Code

We also include the LLMDP class code for DP-BART and DP-Prompt, as used in the paper.

X = LLMDP.DPPrompt()
# or
X = LLMDP.DPBart()

# then
X.privatize(text, epsilon)

Metadata

Release files for privfill 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for privfill 0.1.0
File Size Uploaded
privfill-0.1.0.tar.gz 6.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for privfill 0.1.0
File Interpreter ABI Platform
privfill-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 13.9 kB

Release files / privfill-0.1.0.tar.gz

Download URL privfill-0.1.0.tar.gz
Size 6.7 kB
Tags Source
SHA-256 checksum
How to use checksums
51a25519056eebeef431c19c2b40e10a0e235580cc817ea96ec485de9e33c9c5
BLAKE2b-256 checksum
How to use checksums
c70ea848b51649d056c80d40b2cf6684b5eed2973040683761e1c7a8a0d064f6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.20

Release files / privfill-0.1.0-py3-none-any.whl

Download URL privfill-0.1.0-py3-none-any.whl
Size 7.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5ec3f1252f63e82196da97b537deabc076a2e3657f036188b4126494f88986f8
BLAKE2b-256 checksum
How to use checksums
c98e16c94b87cda6476f600ed41b2363bbd659f539a0dfa5a5dd143a131d205b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.20

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page