REVIEW 2 cited by
Text Embedding Inversion Security for Multilingual Language Models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and cross-lingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.
Forward citations
Cited by 2 Pith papers
-
inversedMixup: Data Augmentation via Inverting Mixed Embeddings
Mixing BERT embeddings and inverting them into text with LLaMA produces interpretable augmented sentences, improves few-shot classification on some datasets, and exposes 'manifold intrusion' in text Mixup.
-
Deep Learning Model Inversion Attacks and Defenses: A Comprehensive Survey
A structured literature review that taxonomizes model inversion attacks and defenses and provides a public resource repository.
Discussion (0). Continue with ORCID to comment.