SafeNLIDB: A Privacy-Preserving Safety Alignment Framework for LLM-based Natural Language Database Interfaces

Authors

  • Ruiheng Liu Xi’an Research Institute of High-Tech, Xi’an, China Harbin Institute of Technology, Harbin, China
  • Xiaobing Chen Harbin Institute of Technology, Harbin, China
  • Jinyu Zhang Harbin Institute of Technology, Harbin, China
  • Qiongwen Zhang Harbin Institute of Technology, Harbin, China
  • Yu Zhang Harbin Institute of Technology, Harbin, China
  • Bailong Yang Xi’an Research Institute of High-Tech, Xi’an, China

DOI:

https://doi.org/10.1609/aaai.v40i38.40484

Abstract

The rapid advancement of Large Language Models (LLMs) has driven significant progress in Natural Language Interface to Database (NLIDB). However, the widespread adoption of LLMs has raised critical privacy and security concerns. During interactions, LLMs may unintentionally expose confidential database contents or be manipulated by attackers to exfiltrate data through seemingly benign queries. While current efforts typically rely on rule-based heuristics or LLM agents to mitigate this leakage risk, these methods still struggle with complex inference-based attacks, suffer from high false positive rates, and often compromise the reliability of SQL queries. To address these challenges, we propose SafeNLIDB, a novel privacy-security alignment framework for LLM-based NLIDB. The framework features an automated pipeline that generates hybrid chain-of-thought interaction data from scratch, seamlessly combining explicit security reasoning with SQL generation. Additionally, we introduce reasoning warm-up and alternating preference optimization to overcome the multi-preference oscillations of Direct Preference Optimization (DPO), enabling LLMs to produce security-aware SQL through fine-grained reasoning without the need for human-annotated preference data. Extensive experiments demonstrate that our method outperforms both larger-scale LLMs and ideal-setting baselines, achieving significant security improvements while preserving high utility.

Downloads

Published

2026-03-14

How to Cite

Liu, R., Chen, X., Zhang, J., Zhang, Q., Zhang, Y., & Yang, B. (2026). SafeNLIDB: A Privacy-Preserving Safety Alignment Framework for LLM-based Natural Language Database Interfaces. Proceedings of the AAAI Conference on Artificial Intelligence, 40(38), 32123–32131. https://doi.org/10.1609/aaai.v40i38.40484

Issue

Section

AAAI Technical Track on Natural Language Processing III