Beyond Visual Evidence: Revealing and Mitigating Relational Privacy Leakage in Document MLLMs
This work addresses a critical privacy vulnerability in multimodal large language models for document understanding: when visual evidence is insufficient, these models often rely on memorized field correlations from training data to infer missing content, leading to relational leakage of sensitive personal information. To mitigate this risk, the paper introduces the first systematic analysis of such privacy leakage mechanisms and proposes a Dynamic Relation Unlearning Framework (DRUF), which integrates a relation decoupling unlearning module with a dynamic set updating mechanism to suppress high-risk field associations while preserving essential information extraction performance. Additionally, the authors construct DocPrivacyBench, the first privacy evaluation benchmark tailored to scenarios with missing visual evidence. Experiments demonstrate that DRUF significantly reduces privacy leakage risk—outperforming the strongest baseline by 4.8 percentage points—without compromising robustness in information extraction.