Secure AI: De-identifying data with SDP
By Google Cloud Tech
Share:
Key Concepts:
- Sensitive Data Protection (SDP): A Google Cloud service for finding and anonymizing sensitive data.
- InfoTypes: Built-in or custom classifiers used by SDP to identify sensitive data patterns.
- Discovery: SDP's capability to scan large datasets for sensitive data.
- Inspection: SDP's capability to analyze real-time data for sensitive data.
- Deidentification: The process of removing or masking sensitive data.
- Redaction: Removing sensitive data entirely.
- Tokenization: Replacing sensitive data with non-reversible tokens.
- Bucketing: Generalizing numerical data into ranges.
- Model Armor: A Google Cloud product that bundles SDP's data detection with other security features for AI applications.
- Inspect Template: A configuration that defines which InfoTypes to detect.
- Deidentification Template: A configuration that defines how to transform sensitive data.
1. Introduction: The Challenge of Realistic Data for Testing
- Developers face the challenge of using realistic data for testing without introducing security risks, especially in generative AI applications.
- Generative AI applications often interact with user data, making data protection crucial.
2. Sensitive Data Protection (SDP) Overview
- SDP is a Google Cloud service designed to find and anonymize sensitive data.
- It operates in two main steps: detection and transformation.
3. Detection Phase
- SDP uses over 200 built-in classifiers called "InfoTypes" to identify data like credit card numbers, names, and addresses.
- Users can create custom InfoTypes for specific data patterns.
- Detection can be used in two ways:
- Discovery: Scans large datasets (e.g., Cloud Storage buckets, BigQuery tables) to map where sensitive data resides.
- Inspection: Analyzes real-time data (e.g., incoming API requests, uploaded files).
4. Transformation Phase
- Once SDP finds sensitive data, it can transform it using various methods:
- Redaction: Removing the data entirely.
- Replacement: Replacing the data with a placeholder.
- Masking: Partially hiding the data.
- Tokenization: Replacing the data with a consistent, non-reversible token. This maintains data relationships without exposing the original information.
- Bucketing: Generalizing numbers into ranges.
- Shifting Dates: Altering dates by a consistent amount.
5. Practical Example: Deidentifying Data in Cloud Storage
- The process of creating a deidentified copy of data in a Cloud Storage bucket involves three steps:
- Creating an Inspect Template: Defines which InfoTypes to detect (e.g., email addresses, phone numbers).
- Creating a Deidentification Template: Specifies how to transform the detected sensitive data (e.g., redact email addresses).
- Running a Job: SDP scans the input bucket, applies the rules from the deidentification template, and saves a sanitized version in the output bucket.
6. Application to Generative AI
- AI applications often use user input or internal data that may contain sensitive information.
- SDP can be used to clean this data at key points:
- Scanning User Prompts: Before sending prompts to the model to prevent sensitive data from being processed or logged.
- Filtering Application Logs: Before writing logs, filter both the user's query and the model's response to maintain useful logs without storing personal data.
- Scanning Model Output: Before displaying output to the user to ensure the model doesn't reveal sensitive information learned from training data.
7. Model Armor
- Model Armor is a Google Cloud product that bundles SDP's data detection capabilities with other security features for AI applications.
- It includes features like blocking prompt injection attacks and filtering for harmful content.
- Model Armor can use the same deidentification templates configured in SDP.
8. Model Armor Demo
- A chat application integrated with Model Armor demonstrates how it intercepts and redacts a credit card number entered by a user.
- The configured SDP template is used to redact the sensitive data in real-time.
9. Conclusion
- SDP can be used to deidentify data for test environments.
- Model Armor can be used to secure real-time interactions in generative AI applications.
- Both services help build applications that handle sensitive data correctly.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Why Does This Guy Appear In Kids Videos?
sphynx

TIC en las Organizaciones - Electiva Complementaria II Unisimon
Julieth Güell S

How to Tame Your Advice Monster | Michael Bungay Stanier | TED
TED

Margaret Heffernan: Why it's time to forget the pecking order at work
TED

The importance of psychological safety: Amy Edmondson
The King's Fund

What Is Psychological Safety?
Harvard Business Review

13-Conflict Management: Listening in Conflict
Deliberate Development