Secure AI: De-identifying data with SDP

By Google Cloud Tech

Share:

Key Concepts:

  • Sensitive Data Protection (SDP): A Google Cloud service for finding and anonymizing sensitive data.
  • InfoTypes: Built-in or custom classifiers used by SDP to identify sensitive data patterns.
  • Discovery: SDP's capability to scan large datasets for sensitive data.
  • Inspection: SDP's capability to analyze real-time data for sensitive data.
  • Deidentification: The process of removing or masking sensitive data.
  • Redaction: Removing sensitive data entirely.
  • Tokenization: Replacing sensitive data with non-reversible tokens.
  • Bucketing: Generalizing numerical data into ranges.
  • Model Armor: A Google Cloud product that bundles SDP's data detection with other security features for AI applications.
  • Inspect Template: A configuration that defines which InfoTypes to detect.
  • Deidentification Template: A configuration that defines how to transform sensitive data.

1. Introduction: The Challenge of Realistic Data for Testing

  • Developers face the challenge of using realistic data for testing without introducing security risks, especially in generative AI applications.
  • Generative AI applications often interact with user data, making data protection crucial.

2. Sensitive Data Protection (SDP) Overview

  • SDP is a Google Cloud service designed to find and anonymize sensitive data.
  • It operates in two main steps: detection and transformation.

3. Detection Phase

  • SDP uses over 200 built-in classifiers called "InfoTypes" to identify data like credit card numbers, names, and addresses.
  • Users can create custom InfoTypes for specific data patterns.
  • Detection can be used in two ways:
    • Discovery: Scans large datasets (e.g., Cloud Storage buckets, BigQuery tables) to map where sensitive data resides.
    • Inspection: Analyzes real-time data (e.g., incoming API requests, uploaded files).

4. Transformation Phase

  • Once SDP finds sensitive data, it can transform it using various methods:
    • Redaction: Removing the data entirely.
    • Replacement: Replacing the data with a placeholder.
    • Masking: Partially hiding the data.
    • Tokenization: Replacing the data with a consistent, non-reversible token. This maintains data relationships without exposing the original information.
    • Bucketing: Generalizing numbers into ranges.
    • Shifting Dates: Altering dates by a consistent amount.

5. Practical Example: Deidentifying Data in Cloud Storage

  • The process of creating a deidentified copy of data in a Cloud Storage bucket involves three steps:
    1. Creating an Inspect Template: Defines which InfoTypes to detect (e.g., email addresses, phone numbers).
    2. Creating a Deidentification Template: Specifies how to transform the detected sensitive data (e.g., redact email addresses).
    3. Running a Job: SDP scans the input bucket, applies the rules from the deidentification template, and saves a sanitized version in the output bucket.

6. Application to Generative AI

  • AI applications often use user input or internal data that may contain sensitive information.
  • SDP can be used to clean this data at key points:
    1. Scanning User Prompts: Before sending prompts to the model to prevent sensitive data from being processed or logged.
    2. Filtering Application Logs: Before writing logs, filter both the user's query and the model's response to maintain useful logs without storing personal data.
    3. Scanning Model Output: Before displaying output to the user to ensure the model doesn't reveal sensitive information learned from training data.

7. Model Armor

  • Model Armor is a Google Cloud product that bundles SDP's data detection capabilities with other security features for AI applications.
  • It includes features like blocking prompt injection attacks and filtering for harmful content.
  • Model Armor can use the same deidentification templates configured in SDP.

8. Model Armor Demo

  • A chat application integrated with Model Armor demonstrates how it intercepts and redacts a credit card number entered by a user.
  • The configured SDP template is used to redact the sensitive data in real-time.

9. Conclusion

  • SDP can be used to deidentify data for test environments.
  • Model Armor can be used to secure real-time interactions in generative AI applications.
  • Both services help build applications that handle sensitive data correctly.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video