HeadlinesBriefing HeadlinesBriefing.com

Rampart: On-Device PII Redaction for Browsers

Hacker News •
×

When you type into a chatbot, you might reveal more about yourself than intended. A request to clean up an email carries your name and a coworker’s; a medical bill question carries your address and account number. Whatever you type travels to a remote server you can’t inspect. Rampart’s core design principle: the only personal information you can be sure is private is the information that never leaves your device.

Today, Rampart is open-sourced as a first-generation on-device personal information filtering system. It combines a deterministic layer using regular expressions to catch SSNs and ID numbers, and Mini LM to catch names and street addresses. Doing PII removal often means trusting a remote server or downloading large binaries, which present key challenges: AI privacy guarantees are almost impossible to verify, and most models are gigantic, narrowing the group of users who can benefit.

Everything happens in the browser, between typing a message and sending it; there is no server in the loop. Model size is 14.7MB, runtime latency is 3.9ms on Web GPU, and private-term recall across seven languages is 98.4%. Before a message goes anywhere, two readers look at it on your device: a deterministic rules layer for structured data like SSNs and credit cards, and a small language model, Mini LM, that reads sentences for context-aware redaction of names and addresses.

Rampart was trained on AI4Privacy’s Open PII 1.5M dataset and a synthetic generator. On a 30,000-row held-out test set, Rampart scored 98.42% recall, outperforming GLi NER small v2.1 (94.2%), Community BERT-small PII (81.5%), Microsoft Presidio (65%), and AWS Bedrock Guardrails (63.8%). It is an alpha product intended as a first line of defense.

Source: Hacker News · Summarized by HeadlinesBriefing