Privacy vulnerabilities in LLMs, such as leakage from memorization, have been constantly identified, and various mitigation proposals have been proposed. LoRA is usually used in fine-tuning LLMs and a good entry point to insert privacy-enhancing modules. In this ongoing research, we introduce \(\textsf{PSY}\) , a Posterior Sampling based PrivacY enhancer that can be used in LoRA. We propose a simple yet effective realization of \(\textsf{PSY}\) using posterior sampling, which effectively prevents privacy leakage from intermediate information and, in turn, preserves the privacy of data owners. We evaluate LoRA extended with \(\textsf{PSY}\) against state-of-the-art membership inference and data extraction attacks. The experiments are executed on three different LLM architectures fine-tuned on three datasets with LoRA. In contrast to the commonly used differential privacy method, we find that our proposed modification consistently reduces the attack success rate. Meanwhile, our method has almost no negative impact on model fine-tuning or final performance. Most importantly, \(\textsf{PSY}\) reveals a promising path towards privacy enhancement with latent space extensions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Short Paper: PSY: Posterior Sampling Based Privacy Enhancer in Large Language Models

  • Yulian Sun,
  • Li Duan,
  • Yong Li

摘要

Privacy vulnerabilities in LLMs, such as leakage from memorization, have been constantly identified, and various mitigation proposals have been proposed. LoRA is usually used in fine-tuning LLMs and a good entry point to insert privacy-enhancing modules. In this ongoing research, we introduce \(\textsf{PSY}\) , a Posterior Sampling based PrivacY enhancer that can be used in LoRA. We propose a simple yet effective realization of \(\textsf{PSY}\) using posterior sampling, which effectively prevents privacy leakage from intermediate information and, in turn, preserves the privacy of data owners. We evaluate LoRA extended with \(\textsf{PSY}\) against state-of-the-art membership inference and data extraction attacks. The experiments are executed on three different LLM architectures fine-tuned on three datasets with LoRA. In contrast to the commonly used differential privacy method, we find that our proposed modification consistently reduces the attack success rate. Meanwhile, our method has almost no negative impact on model fine-tuning or final performance. Most importantly, \(\textsf{PSY}\) reveals a promising path towards privacy enhancement with latent space extensions.