English

Inside the Black Box: Detecting Data Leakage in Pre-trained Language Encoders

Computation and Language 2024-08-21 v1

Abstract

Despite being prevalent in the general field of Natural Language Processing (NLP), pre-trained language models inherently carry privacy and copyright concerns due to their nature of training on large-scale web-scraped data. In this paper, we pioneer a systematic exploration of such risks associated with pre-trained language encoders, specifically focusing on the membership leakage of pre-training data exposed through downstream models adapted from pre-trained language encoders-an aspect largely overlooked in existing literature. Our study encompasses comprehensive experiments across four types of pre-trained encoder architectures, three representative downstream tasks, and five benchmark datasets. Intriguingly, our evaluations reveal, for the first time, the existence of membership leakage even when only the black-box output of the downstream model is exposed, highlighting a privacy risk far greater than previously assumed. Alongside, we present in-depth analysis and insights toward guiding future researchers and practitioners in addressing the privacy considerations in developing pre-trained language models.

Keywords

Cite

@article{arxiv.2408.11046,
  title  = {Inside the Black Box: Detecting Data Leakage in Pre-trained Language Encoders},
  author = {Yuan Xin and Zheng Li and Ning Yu and Dingfan Chen and Mario Fritz and Michael Backes and Yang Zhang},
  journal= {arXiv preprint arXiv:2408.11046},
  year   = {2024}
}

Comments

ECAI24

R2 v1 2026-06-28T18:18:30.221Z