Pith. sign in

REVIEW 2 cited by

Memorization in NLP Fine-tuning Methods

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2205.12506 v2 pith:WNGUH5JC submitted 2022-05-25 cs.CL cs.LG

classification cs.CLcs.LG
keywords fine-tuningattacksmemorizationmethodsmodeldifferentextractionhead
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Large language models are shown to present privacy risks through memorization of training data, and several recent works have studied such risks for the pre-training phase. Little attention, however, has been given to the fine-tuning phase and it is not well understood how different fine-tuning methods (such as fine-tuning the full model, the model head, and adapter) compare in terms of memorization risk. This presents increasing concern as the "pre-train and fine-tune" paradigm proliferates. In this paper, we empirically study memorization of fine-tuning methods using membership inference and extraction attacks, and show that their susceptibility to attacks is very different. We observe that fine-tuning the head of the model has the highest susceptibility to attacks, whereas fine-tuning smaller adapters appears to be less vulnerable to known extraction attacks.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Private Seeds, Public LLMs: Realistic and Privacy-Preserving Synthetic Data Generation

    cs.CR 2026-04 unverdicted novelty 6.0 of 10

    RPSG generates realistic synthetic replicas of private text by combining private seeds with public LLMs and a formal differential privacy mechanism in candidate selection.

  2. On the Performance of Differentially Private Optimization with Heavy-Tail Class Imbalance

    cs.LG 2025-07 conditional novelty 5.0 of 10

    Under heavy-tail class imbalance, subtracting the DP noise variance from Adam's second moment (DP-AdamBC) substantially improves learning of rare classes compared with DP gradient descent.

Pith tools