cd /news/artificial-intelligence/grasp-reinforcing-language-model-ano… · home topics artificial-intelligence article
[ARTICLE · art-89830] src=arxiv.org ↗ pub= topic=artificial-intelligence verified=true sentiment=↑ positive

GRASP: Reinforcing Language Model Anonymizers with Group Relative Policy Optimization

Researchers introduced GRASP (Group-Relative Anonymization via Self-refinement Policy-optimization), a method that uses Group Relative Policy Optimization to train a small on-device language model for adversarial anonymization, improving the privacy-utility trade-off over DPO-distilled baselines. Trained on Llama-3.1-8B, GRASP matches or outperforms frontier-model-driven anonymization from Gemini 2.5 Flash and Claude while removing more private information, and runs at roughly 1% of the GPT-4o teacher's cost.

read1 min views1 publishedAug 10, 2026

arXiv:2608.06526v1 Announce Type: new Abstract: Large language models can infer sensitive personal attributes, such as age, location, and occupation, from ordinary text, turning everyday writing into a privacy risk. Adversarial anonymization defends against this by rewriting a text with a capable language model that also plays the attacker, but it needs a powerful model at inference time and thus sends private text to a third party, the very exposure anonymization should prevent. Recent work distills this behavior into a small on-device model using supervised fine-tuning and direct preference optimization (DPO), but DPO only imitates the teacher's offline choices and never directly optimizes the privacy--utility objective we care about. We introduce \textbf{GRASP} (\textbf{G}roup-\textbf{R}elative \textbf{A}nonymization via \textbf{S}elf-refinement \textbf{P}olicy-optimization), which reinforces the local anonymizer online with Group Relative Policy Optimization. A single small model acts as anonymizer, adversary, and utility judge, trained against a self-generated reward that hides attributes while preserving meaning, with a design that guards against reward hacking. Trained on Llama-3.1-8B, \ours{} improves the privacy--utility trade-off over the DPO-distilled baseline, consistently across three independent LLM judges. Against adversarial anonymization driven by frontier models such as Gemini~2.5~Flash and Claude, it achieves a comparable or better overall trade-off while removing substantially more private information, and it runs entirely on-device at roughly $1%$ of the GPT-4o teacher's cost.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @grasp 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/grasp-reinforcing-la…] indexed:0 read:1min 2026-08-10 ·