Special Characters Attack: Toward Scalable Training Data Extraction From Large Language Models
Bai, Yang, Pei, Ge, Gu, Jindong, Yang, Yong, Ma, Xingjun
–arXiv.org Artificial Intelligence
Large language models (LLMs) have achieved remarkable performance on a wide range of tasks. However, recent studies have shown that LLMs can memorize training data and simple repeated tokens can trick the model to leak the data. In this paper, we take a step further and show that certain special characters or their combinations with English letters are stronger memory triggers, leading to more severe data leakage. The intuition is that, since LLMs are trained with massive data that contains a substantial amount of special characters (e.g. structural symbols {, } of JSON files, and @, # in emails and online posts), the model may memorize the co-occurrence between these special characters and the raw texts. This motivates us to propose a simple but effective Special Characters Attack (SCA) to induce training data leakage. Our experiments verify the high effectiveness of SCA against state-of-the-art LLMs: they can leak diverse training data, such as code corpus, web pages, and personally identifiable information, and sometimes generate non-stop outputs as a byproduct. We further show that the composition of the training data corpus can be revealed by inspecting the leaked data -- one crucial piece of information for pre-training high-performance LLMs. Our work can help understand the sensitivity of LLMs to special characters and identify potential areas for improvement.
arXiv.org Artificial Intelligence
May-20-2024
- Country:
- Africa > Middle East
- Egypt > Cairo Governorate > Cairo (0.04)
- Asia
- Japan > Honshū
- Kansai > Osaka Prefecture
- Osaka (0.04)
- Kantō > Tokyo Metropolis Prefecture
- Tokyo (0.04)
- Kansai > Osaka Prefecture
- Middle East
- Israel > Tel Aviv District
- Tel Aviv (0.04)
- Republic of Türkiye > Istanbul Province
- Istanbul (0.04)
- Israel > Tel Aviv District
- China
- Beijing > Beijing (0.04)
- Guangdong Province > Shenzhen (0.04)
- Shanghai > Shanghai (0.04)
- Tianjin Province > Tianjin (0.04)
- South Korea > Seoul
- Seoul (0.04)
- Pakistan > Punjab
- Lahore Division > Lahore (0.04)
- Vietnam > Hồ Chí Minh City
- Hồ Chí Minh City (0.04)
- Thailand > Bangkok
- Bangkok (0.04)
- India
- Andhra Pradesh > Visakhapatnam (0.04)
- Karnataka > Bengaluru (0.04)
- Maharashtra > Mumbai (0.04)
- Tamil Nadu > Chennai (0.04)
- Bangladesh > Dhaka Division
- Dhaka District > Dhaka (0.04)
- Indonesia > Java
- Philippines > Luzon
- National Capital Region > City of Manila (0.04)
- Japan > Honshū
- Europe
- France (0.04)
- Italy > Marche
- Ancona Province > Ancona (0.04)
- Middle East > Republic of Türkiye
- Istanbul Province > Istanbul (0.04)
- Portugal (0.04)
- Romania > București - Ilfov Development Region
- Municipality of Bucharest > Bucharest (0.04)
- Russia > Central Federal District
- Moscow Oblast > Moscow (0.04)
- United Kingdom > England
- Oxfordshire > Oxford (0.14)
- North America
- Canada > Ontario
- Toronto (0.04)
- Mexico > Mexico City
- Mexico City (0.04)
- United States
- Illinois > Cook County
- Chicago (0.04)
- Minnesota > Hennepin County
- Minneapolis (0.14)
- New York (0.04)
- Illinois > Cook County
- Canada > Ontario
- Oceania > Australia (0.04)
- Pacific Ocean > North Pacific Ocean
- South China Sea (0.04)
- South America
- Argentina > Pampas
- Buenos Aires F.D. > Buenos Aires (0.04)
- Brazil
- Rio de Janeiro > Rio de Janeiro (0.04)
- São Paulo (0.04)
- Argentina > Pampas
- Africa > Middle East
- Genre:
- Research Report (1.00)
- Industry:
- Government
- Military (0.67)
- Regional Government > North America Government
- United States Government (1.00)
- Voting & Elections (1.00)
- Health & Medicine (1.00)
- Information Technology > Security & Privacy (1.00)
- Law > Statutes (0.67)
- Leisure & Entertainment (0.67)
- Government
- Technology: