PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
June 24, 20240 citationsOpen Access

Noisy Neighbors: Efficient membership inference attacks against LLMs

View Full Paper
FGFilippo GalliLMLuca MelisTCTommaso Cucinotta

Key Points

  • The new methodology effectively utilizes stochastic noise for membership inference attacks, enhancing privacy risk assessment.
  • Using this approach, the performance closely aligns with traditional shadow models while simplifying the process.
  • Employing inference mode only, the method generates noisy neighbors, streamlining privacy auditing efforts with minimal computation required for additional model training or resources involved in shadow models' development and training. This efficiency opens doors for broader applications of privacy auditing tools across various datasets and formats, allowing regulators to evaluate LLMs against existing privacy standards more effectively, especially in light of new privacy regulations.

Abstract

The potential of transformer-based LLMs risks being hindered by privacy concerns due to their reliance on extensive datasets, possibly including sensitive information. Regulatory measures like GDPR and CCPA call for using robust auditing tools to address potential privacy issues, with Membership Inference Attacks (MIA) being the primary method for assessing LLMs' privacy risks. Differently from traditional MIA approaches, often requiring computationally intensive training of additional models, this paper introduces an efficient methodology that generates noisy neighbors for a target sample by adding stochastic noise in the embedding space, requiring operating the target model in inference mode only. Our findings demonstrate that this approach closely matches the effectiveness of employing shadow models, showing its usability in practical privacy auditing scenarios.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Galli et al. (2024) studied this question.

synapsesocial.com/papers/68e63919b6db6435875cb4e6https://doi.org/10.48550/arxiv.2406.16565
Ask AI
Helpful
Bookmark
Share
View Full Paper