privfill is a Python package providing LLM-based local Differential Privacy (DP) mechanisms for text privatization via sentece infilling. It offers easy-to-use wrappers for fine-tuned Hugging Face models.
This software was originally presented in the NAACL 2025 findings paper: On the Impact of Noise in Differentially Private Text Rewriting
Installation
Install the package locally in editable mode from your project's root directory:
pip install privfill
Core Prerequisites:
- Python $\geq$ 3.9
- PyTorch (CUDA recommended for faster inference)
- Transformers & NLTK
Basic Usage & Model Selection
Instead of typing Hugging Face repository paths, you can choose from the three built-in models using the SupportedModels enum.
import privfill
# Choose between FLAN_T5_BASE, FLAN_T5_LARGE, and BART_LARGE
engine = privfill.load_pipeline(privfill.SupportedModels.FLAN_T5_BASE, DP=True)
text = "This is a long private document ... which contains sensitive information and should be privatized,"
private_text = engine.privatize(text, epsilon=10)
print(private_text)
As described in the paper, we also create an analagous, non-DP variant of PrivFill. The usage is very similar:
engine = privfill.load_pipeline(privfill.SupportedModels.FLAN_T5_BASE, DP=False)
private_text = engine.privatize(text)
Available Models
| Enum | Hugging Face Repository | Base Mechanism |
|---|---|---|
| SupportedModels.FLAN_T5_BASE | sjmeis/flan-t5-base-infill-combined | DP-Prompt |
| SupportedModels.FLAN_T5_LARGE | sjmeis/flan-t5-large-infill-combined | DP-Prompt |
| SupportedModels.BART_LARGE | sjmeis/bart-large-infill-combined | DP-BART |
Models
We make our three sentence infilling models public. They can be found at this link.
Comparison Code
We also include the LLMDP class code for DP-BART and DP-Prompt, as used in the paper.
X = LLMDP.DPPrompt()
# or
X = LLMDP.DPBart()
# then
X.privatize(text, epsilon)
Metadata
Release files for privfill 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| privfill-0.1.0.tar.gz | 6.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| privfill-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.9 kB
Release files / privfill-0.1.0.tar.gz
| Download URL | privfill-0.1.0.tar.gz |
|---|---|
| Size | 6.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
51a25519056eebeef431c19c2b40e10a0e235580cc817ea96ec485de9e33c9c5
|
|
BLAKE2b-256 checksum How to use checksums |
c70ea848b51649d056c80d40b2cf6684b5eed2973040683761e1c7a8a0d064f6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.10.20
|
Release files / privfill-0.1.0-py3-none-any.whl
| Download URL | privfill-0.1.0-py3-none-any.whl |
|---|---|
| Size | 7.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5ec3f1252f63e82196da97b537deabc076a2e3657f036188b4126494f88986f8
|
|
BLAKE2b-256 checksum How to use checksums |
c98e16c94b87cda6476f600ed41b2363bbd659f539a0dfa5a5dd143a131d205b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.10.20
|