M. J. Tang, D. Z. Hakkani-tür, and A. Gokhantur, Preserving privacy in spoken language databases, Proc. of the International Workshop on Privacy and Security Issues in Data Mining, ECML/PKDD, 2004.

C. Dwork and A. Roth, The Algorithmic Foundations of Differential Privacy, ser. Foundations and Trends in Theoretical Computer Science, 2014.

Y. Özlem-uzuner, P. Luo, and . Szolovits, Evaluating the stateof-the-art in automatic de-identification, Journal of the American Medical Informatics Association, vol.14, issue.5, pp.550-563, 2007.

S. M. Meystre, F. J. Friedlin, B. R. South, S. Shen, and M. H. Samore, Automatic de-identification of textual documents in the electronic health record: a review of recent research, BMC Medical Research Methodology, vol.10, issue.70, 2010.

F. Dernoncourt, J. Y. Lee, O. Uzuner, and P. Szolovits, Deidentification of patient notes with recurrent neural networks, Journal of the American Medical Informatics Association, vol.24, issue.3, pp.596-606, 2017.

K. Khin, P. Burckhardt, and R. Padman, A deep learning architecture for de-identification of patient notes: Implementation and evaluation, Proceedings of the Workshop on Information Technologies and Systems (WITS), 2018.

H. Chen, X. Liu, D. Yin, and T. Michigan, A survey on dialogue systems: Recent advances and new frontiers, ACM SIGKDD Explorations Newsletter, vol.19, issue.2, pp.25-35, 2017.

, Privacy-preserving Data Mining: Models and Algorithms, 2008.

J. Devlin, M. Chang, K. Lee, and K. Toutanova, BERT: pre-training of deep bidirectional transformers for language understanding, CoRR, 2018.

D. S. Carrell, D. J. Cronkite, M. R. Li, S. Nyemba, B. A. Malin et al., The machine giveth and the machine taketh away: a parrot attack on clinical text deidentified with hiding in plain sight, Journal of the American Medical Informatics Association, vol.26, issue.12, pp.1536-1544, 2019.

C. Dwork, F. Mcsherry, K. Nissim, and A. Smith, Calibrating noise to sensitivity in private data analysis, Theory of Cryptography, pp.265-284, 2006.

S. L. Warner, Randomized response: A survey technique for eliminating evasive answer bias, Journal of the American Statistical Association, vol.60, issue.309, pp.63-69, 1965.

Y. Wang, X. Wu, and D. Hu, Using randomized response for differential privacy preserving data collection, Proceeding of the workshop Privacy and Anonymity in the Information Society (PAIS) of the EDBT/ICDT 2016 Joint Conference, 2016.

J. P. Pestian, C. Brew, P. Matykiewicz, D. Hovermale, N. Johnson et al., A shared task involving multi-label classification of clinical free text, Biological, translational, and clinical language processing, pp.97-104, 2007.

K. Weilhammer, U. Reichel, and F. Schiel, Multi-Tier Annotations in the Verbmobil Corpus, Proceedings of the Third International Conference on Language Resources and Evaluation (LREC 2002), 2002.

C. T. Hemphill, J. J. Godfrey, and G. R. Doddington, The ATIS spoken language systems pilot corpus, Speech and Natural Language: Proceedings of a Workshop Held at Hidden Valley, 1990.

A. Coucke, A. Saade, A. Ball, T. Bluche, A. Caulier et al., Snips voice platform: an embedded spoken language understanding system for private-by-design voice interfaces, ArXiv, 2018.

S. Schuster, S. Gupta, R. Shah, and M. Lewis, Cross-lingual transfer learning for multilingual task oriented dialog, NAACL-HLT, 2019.

X. Li, S. Panda, J. Liu, and J. Gao, Microsoft dialogue challenge: Building end-to-end task-completion dialogue systems, 2018.

T. Wolf, L. Debut, V. Sanh, J. Chaumond, C. Delangue et al., Huggingface's transformers: State-of-the-art natural language processing, ArXiv, 2019.