A Multi-Layer Architecture for Progressive Privacy Risk Mitigation in AI Applications
Resumo
AI applications process sensitive data and remain exposed to inference and reconstruction attacks. Privacy-Enhancing Technologies (PETs) are often deployed in isolation, allowing risks to accumulate across AI pipelines. This paper presents a Multi-Layer Architecture for Progressive Privacy Risk Mitigation that integrates semantic PII sanitization, structured anonymization, Differential Privacy, adversarial validation, and governance auditing. Experiments with Microsoft Presidio, ARX/PyCANON, and Opacus are combined with a reproducible pipeline that preserves layer interfaces and privacy metrics. Results show improved PT-BR PII detection, utility-aware anonymization, and lower inference and reconstruction exposure.Referências
Abadi, M. et al. (2016). Deep learning with differential privacy. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, pages 308–318.
Aggarwal, C. C. (2005). On k-anonymity and the curse of dimensionality. Proceedings of the VLDB Conference, pages 901–909.
Bommasani, R., Hudson, D. A., Adeli, E., Altman, R., Arora, S., von Arx, S., Bernstein, M. S., Bohg, J., Bosselut, A., Brunskill, E., et al. (2021). On the opportunities and risks of foundation models. Technical report, Stanford Center for Research on Foundation Models (CRFM).
Brazil (2018). Lei no 13.709, de 14 de agosto de 2018: Lei geral de proteção de dados pessoais (lgpd).
Carlini, N., Tramer, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, U., Oprea, A., and Raffel, C. (2021). Extracting training data from large language models. In Proceedings of the 30th USENIX Security Symposium (USENIX Security ’21), pages 2633–2650. USENIX Association.
Cavoukian, A. (2011). Privacy by design: The 7 foundational principles. Information and Privacy Commissioner of Ontario.
Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography Conference, pages 265–284.
Dwork, C. and Roth, A. (2014). The Algorithmic Foundations of Differential Privacy. Foundations and Trends in Theoretical Computer Science.
Explosion AI (2026). spacy: Industrial-strength natural language processing in python.
Fredrikson, M., Jha, S., and Ristenpart, T. (2015). Model inversion attacks that exploit confidence information and basic countermeasures. In ACM SIGSAC Conference on Computer and Communications Security, pages 1322–1333.
Kaissis, G. A., Makowski, M. R., Rückert, D., and Braren, R. F. (2020). Secure, privacy-preserving and federated machine learning in medical imaging. Nature Machine Intelligence, 2(6):305–311.
Lefevre, K., DeWitt, D., and Ramakrishnan, R. (2006). Mondrian multidimensional k-anonymity. In International Conference on Data Engineering.
Li, N., Li, T., and Venkatasubramanian, S. (2007). t-closeness: Privacy beyond k-anonymity and l-diversity. In International Conference on Data Engineering.
Machanavajjhala, A. et al. (2007). l-diversity: Privacy beyond k-anonymity. ACM Transactions on Knowledge Discovery from Data, 1(1).
Microsoft (2023). Presidio: Pii data protection and anonymization sdk.
National Institute of Standards and Technology (2023). Artificial intelligence risk management framework (ai rmf 1.0).
Paixão, A. C. P., Camargo, G. F. L., and Braga, A. M. (2025a). Testing open-source libraries for private counts and averages on energy metering time series. In 20th European Dependable Computing Conference, pages 100–104.
Paixão, A. C. P. et al. (2025b). Understanding how to use open-source libraries for differentially private statistics on energy metering time series. In Proceedings of the 10th International Conference on Internet of Things, Big Data and Security (IoTBDS), pages 289–296. SCITEPRESS.
Ratinov, L. and Roth, D. (2009). Design challenges and misconceptions in named entity recognition. In Conference on Computational Natural Language Learning.
Shokri, R. et al. (2017). Membership inference attacks against machine learning models. In IEEE Symposium on Security and Privacy.
Sweeney, L. (2002). k-anonymity: A model for protecting privacy. International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems, 10(5):557–570.
Yousefpour, A. et al. (2021). Opacus: User-friendly differential privacy library in pytorch.
Zhu, L., Liu, Z., and Han, S. (2019). Deep leakage from gradients. In Advances in Neural Information Processing Systems.
Aggarwal, C. C. (2005). On k-anonymity and the curse of dimensionality. Proceedings of the VLDB Conference, pages 901–909.
Bommasani, R., Hudson, D. A., Adeli, E., Altman, R., Arora, S., von Arx, S., Bernstein, M. S., Bohg, J., Bosselut, A., Brunskill, E., et al. (2021). On the opportunities and risks of foundation models. Technical report, Stanford Center for Research on Foundation Models (CRFM).
Brazil (2018). Lei no 13.709, de 14 de agosto de 2018: Lei geral de proteção de dados pessoais (lgpd).
Carlini, N., Tramer, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, U., Oprea, A., and Raffel, C. (2021). Extracting training data from large language models. In Proceedings of the 30th USENIX Security Symposium (USENIX Security ’21), pages 2633–2650. USENIX Association.
Cavoukian, A. (2011). Privacy by design: The 7 foundational principles. Information and Privacy Commissioner of Ontario.
Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography Conference, pages 265–284.
Dwork, C. and Roth, A. (2014). The Algorithmic Foundations of Differential Privacy. Foundations and Trends in Theoretical Computer Science.
Explosion AI (2026). spacy: Industrial-strength natural language processing in python.
Fredrikson, M., Jha, S., and Ristenpart, T. (2015). Model inversion attacks that exploit confidence information and basic countermeasures. In ACM SIGSAC Conference on Computer and Communications Security, pages 1322–1333.
Kaissis, G. A., Makowski, M. R., Rückert, D., and Braren, R. F. (2020). Secure, privacy-preserving and federated machine learning in medical imaging. Nature Machine Intelligence, 2(6):305–311.
Lefevre, K., DeWitt, D., and Ramakrishnan, R. (2006). Mondrian multidimensional k-anonymity. In International Conference on Data Engineering.
Li, N., Li, T., and Venkatasubramanian, S. (2007). t-closeness: Privacy beyond k-anonymity and l-diversity. In International Conference on Data Engineering.
Machanavajjhala, A. et al. (2007). l-diversity: Privacy beyond k-anonymity. ACM Transactions on Knowledge Discovery from Data, 1(1).
Microsoft (2023). Presidio: Pii data protection and anonymization sdk.
National Institute of Standards and Technology (2023). Artificial intelligence risk management framework (ai rmf 1.0).
Paixão, A. C. P., Camargo, G. F. L., and Braga, A. M. (2025a). Testing open-source libraries for private counts and averages on energy metering time series. In 20th European Dependable Computing Conference, pages 100–104.
Paixão, A. C. P. et al. (2025b). Understanding how to use open-source libraries for differentially private statistics on energy metering time series. In Proceedings of the 10th International Conference on Internet of Things, Big Data and Security (IoTBDS), pages 289–296. SCITEPRESS.
Ratinov, L. and Roth, D. (2009). Design challenges and misconceptions in named entity recognition. In Conference on Computational Natural Language Learning.
Shokri, R. et al. (2017). Membership inference attacks against machine learning models. In IEEE Symposium on Security and Privacy.
Sweeney, L. (2002). k-anonymity: A model for protecting privacy. International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems, 10(5):557–570.
Yousefpour, A. et al. (2021). Opacus: User-friendly differential privacy library in pytorch.
Zhu, L., Liu, Z., and Han, S. (2019). Deep leakage from gradients. In Advances in Neural Information Processing Systems.
Publicado
01/09/2026
Como Citar
LIMA, Leonardo Bruscagini de; ROCHA, Luca Misi; SILVA, Javier Martinez; BRAGA, Alexandre Melo.
A Multi-Layer Architecture for Progressive Privacy Risk Mitigation in AI Applications. In: TRILHA DE INTERAÇÃO COM A INDÚSTRIA E DE INOVAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 864-871.
DOI: https://doi.org/10.5753/sbseg_estendido.2026.28883.
