---
格式版本: 2
标题: "Model Card for OpenAI Privacy Filter"
原文链接: "https://arxiv.org/abs/2608.18274"
发布日期: "2026-08-18"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Tue, 18 Aug 2026 19:48:48 UTC (73 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:09:16+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:03:44+08:00"
入库时间: "2026-08-20T07:09:16.694Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=OpenAI&searchtype=all"
匹配关键词:
  - "deployment"
相关厂家:
  - "OpenAI"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 10
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为OpenAI隐私过滤模型的学术论文，与超节点/AI Rack/机柜级AI基础设施完全无关，无有效技术或商业信号。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:10:26+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 5
AI摘要: "OpenAI Privacy Filter 是一个紧凑的双向 token 分类模型，用于检测和编辑非结构化文本中的个人身份信息（PII）与秘密，由自回归预训练 checkpoint 改造而来。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:22:41.664Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.18274"
---

## Computer Science > Cryptography and Security

## Title:Model Card for OpenAI Privacy Filter

Authors:[Charles de Bourcy](https://arxiv.org/search/cs?searchtype=author&query=de+Bourcy,+C), [Sahra Ghalebikesabi](https://arxiv.org/search/cs?searchtype=author&query=Ghalebikesabi,+S), [Avi Schwarzschild](https://arxiv.org/search/cs?searchtype=author&query=Schwarzschild,+A), [Alex Gorbachev](https://arxiv.org/search/cs?searchtype=author&query=Gorbachev,+A), [Mihai Maruseac](https://arxiv.org/search/cs?searchtype=author&query=Maruseac,+M), [Annie Chu](https://arxiv.org/search/cs?searchtype=author&query=Chu,+A), [Vol Kyrylov](https://arxiv.org/search/cs?searchtype=author&query=Kyrylov,+V), [Tong Mu](https://arxiv.org/search/cs?searchtype=author&query=Mu,+T), [Ally Bennett](https://arxiv.org/search/cs?searchtype=author&query=Bennett,+A), [Andy Nguyen](https://arxiv.org/search/cs?searchtype=author&query=Nguyen,+A), [Casey Meehan](https://arxiv.org/search/cs?searchtype=author&query=Meehan,+C), [Jessica Gan Lee](https://arxiv.org/search/cs?searchtype=author&query=Lee,+J+G), [Shane Bauer](https://arxiv.org/search/cs?searchtype=author&query=Bauer,+S), [Harold Nguyen](https://arxiv.org/search/cs?searchtype=author&query=Nguyen,+H), [Rodolpho Eckhardt](https://arxiv.org/search/cs?searchtype=author&query=Eckhardt,+R), [Yuqi Liu](https://arxiv.org/search/cs?searchtype=author&query=Liu,+Y), [Charlie Oxborough](https://arxiv.org/search/cs?searchtype=author&query=Oxborough,+C), [Marco Rougeth](https://arxiv.org/search/cs?searchtype=author&query=Rougeth,+M), [Omar Chedid](https://arxiv.org/search/cs?searchtype=author&query=Chedid,+O), [Caio Costa](https://arxiv.org/search/cs?searchtype=author&query=Costa,+C), [Yash Parikh](https://arxiv.org/search/cs?searchtype=author&query=Parikh,+Y), [Yao Li](https://arxiv.org/search/cs?searchtype=author&query=Li,+Y), [Congzheng Song](https://arxiv.org/search/cs?searchtype=author&query=Song,+C), [Om Thakkar](https://arxiv.org/search/cs?searchtype=author&query=Thakkar,+O), [Vinnie Monaco](https://arxiv.org/search/cs?searchtype=author&query=Monaco,+V)

[View PDF](https://arxiv.org/pdf/2608.18274) [HTML (experimental)](https://arxiv.org/html/2608.18274v1)

> Abstract:OpenAI Privacy Filter is a compact, bidirectional token-classification model for detecting and redacting personally identifiable information (PII) and secrets in unstructured text. The model is derived from an autoregressively pretrained checkpoint and converted into a bidirectional, banded-attention classifier that labels an input sequence in a single forward pass. A constrained Viterbi decoder produces coherent spans across eight privacy categories and exposes configurable operating points for precision-recall tradeoffs. Privacy Filter has 1.5 billion total parameters, 50 million active parameters per token, and a 128,000-token context window. It is designed for efficient local deployment and domain-specific fine-tuning. Privacy Filter is intended as a configurable data-minimization component within layered privacy workflows, not as an anonymization or compliance guarantee.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR); Machine Learning (cs.LG) |
| Cite as: | [arXiv:2608.18274](https://arxiv.org/abs/2608.18274) \[cs.CR\] |
|  | (or [arXiv:2608.18274v1](https://arxiv.org/abs/2608.18274v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.18274](https://doi.org/10.48550/arXiv.2608.18274) |

## Submission history

From: Sahra Ghalebikesabi \[[view email](https://arxiv.org/show-email/545aa0d0/2608.18274)\]  
**\[v1\]** Tue, 18 Aug 2026 19:48:48 UTC (73 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.18274) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
