TensorX
返回文献探索

Paper · arXiv 2305.11759

Controlling the Extraction of Memorized Data from Large Language Models via Prompt-Tuning

Mustafa Safa Ozdayi, Charith Peris, Jack FitzGerald, Christophe Dupuy, Jimit Majmudar, Haidar Khan, Rahil Parikh, Rahul Gupta

2 upvotesMay 19, 2023arXiv 预印本
AI 摘要

Prompt-tuning can control the extraction rates of memorized content in large language models, offering both attack and defense mechanisms to manage privacy risks.

prompt-tuningextraction ratesmemorized contentLLMsGPT-Neoperplexityprivacy-utility trade-offs

Abstract

Large Language Models (LLMs) are known to memorize significant portions of their training data. Parts of this memorized content have been shown to be extractable by simply querying the model, which poses a privacy risk. We present a novel approach which uses prompt-tuning to control the extraction rates of memorized content in LLMs. We present two prompt training strategies to increase and decrease extraction rates, which correspond to an attack and a defense, respectively. We demonstrate the effectiveness of our techniques by using models from the GPT-Neo family on a public benchmark. For the 1.3B parameter GPT-Neo model, our attack yields a 9.3 percentage point increase in extraction rate compared to our baseline. Our defense can be tuned to achieve different privacy-utility trade-offs by a user-specified hyperparameter. We achieve an extraction rate reduction of up to 97.7% relative to our baseline, with a perplexity increase of 16.9%.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号