Score breakdown

Extracting Training Data from Large Language Models

paper-0135 · paper · 2021

Nicholas Carlini et al.

LLMs memorize and can regurgitate training data.

Abstract

It has become common to publish large (billion parameter) language models that have been trained on private datasets. This paper demonstrates that in such settings, an adversary can perform a training data extraction attack to recover individual training examples by querying the language model. We demonstrate our attack on GPT-2, a language model trained on scrapes of the public Internet, and are able to extract hundreds of verbatim text sequences from the model's training data. These extracted examples include (public) personally identifiable information (names, phone numbers, and email addresses), IRC conversations, code, and 128-bit UUIDs. Our attack is possible even though each of the above sequences are included in just one document in the training data. We comprehensively evaluate our extraction attack to understand the factors that contribute to its success. Worryingly, we find that larger models are more vulnerable than smaller models. We conclude by drawing lessons and discussing possible safeguards for training large language models. [OpenAlex]

Academic, score -0.2065

MetricStatusValueNorm.WeightContributionSourceConfidenceLicenseProvenance
citation_countpresent275.00.0012330.50.000617OpenAlexmediumOpenAlex, CC0 metadatalink
library_holdingsmissingrecorded as missing, penalized by rule, never imputed−0.1recorded as missing; penalized by rule, never imputed
readership_persistencepresent6.00.3571430.050.017857OpenAlexlowOpenAlex, CC0 metadatalink
syllabus_adoptionsmissingrecorded as missing, penalized by rule, never imputed−0.125recorded as missing; penalized by rule, never imputed

Broad Influence, score -0.0569

MetricStatusValueNorm.WeightContributionSourceConfidenceLicenseProvenance
citation_countpresent275.00.0012330.20.000247OpenAlexmediumOpenAlex, CC0 metadatalink
library_holdingsmissingrecorded as missing, penalized by rule, never imputed−0.125recorded as missing; penalized by rule, never imputed
readership_persistencepresent6.00.3571430.40.142857OpenAlexlowOpenAlex, CC0 metadatalink
syllabus_adoptionsmissingrecorded as missing, penalized by rule, never imputed−0.075recorded as missing; penalized by rule, never imputed

Governance Practitioner, score -0.2890

MetricStatusValueNorm.WeightContributionSourceConfidenceLicenseProvenance
citation_countpresent275.00.0012330.250.000308OpenAlexmediumOpenAlex, CC0 metadatalink
library_holdingsmissingrecorded as missing, penalized by rule, never imputed−0.15recorded as missing; penalized by rule, never imputed
readership_persistencepresent6.00.3571430.10.035714OpenAlexlowOpenAlex, CC0 metadatalink
syllabus_adoptionsmissingrecorded as missing, penalized by rule, never imputed−0.175recorded as missing; penalized by rule, never imputed

A rank is not a verdict on intrinsic worth. It is a transparent output of declared evidence, weights, and missing-data rules at a specific release date.

Disagree with this rank or a number? Challenge it with your evidence. Every challenge gets a public identifier and a published resolution.