Pith. sign in

REVIEW 1 cited by

Auditing Data Provenance in Text-Generation Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1811.00513 v2 pith:633HIQDX submitted 2018-11-01 cs.CR cs.CLcs.LGstat.ML

classification cs.CRcs.CLcs.LGstat.ML
keywords auditingdatamodelsmodelusersdetectmethodpersonal
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

To help enforce data-protection regulations such as GDPR and detect unauthorized uses of personal data, we develop a new \emph{model auditing} technique that helps users check if their data was used to train a machine learning model. We focus on auditing deep-learning models that generate natural-language text, including word prediction and dialog generation. These models are at the core of popular online services and are often trained on personal data such as users' messages, searches, chats, and comments. We design and evaluate a black-box auditing method that can detect, with very few queries to a model, if a particular user's texts were used to train it (among thousands of other users). We empirically show that our method can successfully audit well-generalized models that are not overfitted to the training data. We also analyze how text-generation models memorize word sequences and explain why this memorization makes them amenable to auditing.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Efficient and Private: Memorisation under differentially private parameter-efficient fine-tuning in language models

    cs.LG 2024-11 conditional novelty 5.0 of 10

    PEFT methods (LoRA, Adapter) achieve lower membership-inference AUC than full fine-tuning, indicating reduced memorisation, but DP's protective effect is weaker for PEFT models.

Pith tools