An Empirical Analysis of Memorization in Fine-tuned Autoregressive Language Models

An Empirical Analysis of Memorization in Fine-tuned Autoregressive Language Models
复制标题

DOI:
10.18653/v1/2022.emnlp-main.119
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Fatemehsadat Mireshghallah;Archit Uniyal;Tianhao Wang;David Evans;Taylor Berg-Kirkpatrick
Fatemehsadat Mireshghallah;Archit Uniyal;Tianhao Wang;David Evans;Taylor Berg-Kirkpatrick
中科院分区:
其他
文献类型:
--
作者:
Fatemehsadat Mireshghallah;Archit Uniyal;Tianhao Wang;David Evans;Taylor Berg-Kirkpatrick

文献摘要

被引文献

相似文献

大型语言模型通过记忆训练数据显示出隐私风险,最近的几项工作已经研究了预训练阶段的这种风险。然而,很少有人关注微调阶段,也不清楚不同的微调方法(如微调完整模型,模型头和适配器)在记忆风险方面的比较。随着“预先培训和微调”模式的扩散,这引起了越来越多的关注。在本文中,我们实证研究记忆的微调方法,使用成员推理和提取攻击,并表明它们的敏感性是非常不同的。我们观察到,微调模型的头部对攻击的敏感性最高,而微调较小的适配器似乎不太容易受到已知的提取攻击。
Large language models are shown to present privacy risks through memorization of training data, andseveral recent works have studied such risks for the pre-training phase. Little attention, however, has been given to the fine-tuning phase and it is not well understood how different fine-tuning methods (such as fine-tuning the full model, the model head, and adapter) compare in terms of memorization risk. This presents increasing concern as the “pre-train and fine-tune” paradigm proliferates. In this paper, we empirically study memorization of fine-tuning methods using membership inference and extraction attacks, and show that their susceptibility to attacks is very different. We observe that fine-tuning the head of the model has the highest susceptibility to attacks, whereas fine-tuning smaller adapters appears to be less vulnerable to known extraction attacks.