Develop runtime identification of sensitive inputs

Develop and evaluate runtime extraction of sensitive inputs for trusted model environments, potentially by integrating and attesting an additional named-entity recognition model.

Background

The confidentiality mechanisms in TME require a predefined set of sensitive inputs that must not be disclosed. In the evaluation, these inputs are identified offline with Microsoft Presidio because the benchmark datasets lack sensitive-input annotations. The paper explicitly identifies runtime extraction as unresolved and suggests integrating an additional named-entity recognition model whose inference would also be attested.

References

Runtime extraction of sensitive inputs is future work, and can be supported by integrating an additional name-entity recognition model into TME, and attesting its inference.

— Trusted Model Environment for Private Semantic Computations  (2609.30032 - Duddu et al., 24 Sep 2026) in Section 4.1, Experiment Setup—Datasets

Reported ASR is a lower bound on the true leakage, and measures protection of sensitive inputs identified by the detector, not those it misses. Quantifying this gap requires human-labeled sensitive inputs, which is future work.

— Trusted Model Environment for Private Semantic Computations  (2609.30032 - Duddu et al., 24 Sep 2026) in Section 6, Discussion and Summary—Unidentified Sensitive Inputs