Pith. sign in

REVIEW 9 cited by

The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1802.08232 v3 pith:TQ367NI4 submitted 2018-02-22 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords memorizationtestingtraineddatamessagesmethodologymodelsneural
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

This paper describes a testing methodology for quantitatively assessing the risk that rare or unique training-data sequences are unintentionally memorized by generative sequence models---a common type of machine-learning model. Because such models are sometimes trained on sensitive data (e.g., the text of users' private messages), this methodology can benefit privacy by allowing deep-learning practitioners to select means of training that minimize such memorization. In experiments, we show that unintended memorization is a persistent, hard-to-avoid issue that can have serious consequences. Specifically, for models trained without consideration of memorization, we describe new, efficient procedures that can extract unique, secret sequences, such as credit card numbers. We show that our testing strategy is a practical and easy-to-use first line of defense, e.g., by describing its application to quantitatively limit data exposure in Google's Smart Compose, a commercial text-completion neural network trained on millions of users' email messages.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 9 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Adversarial Machine Learning Attacks on Financial Reporting via Maximum Violated Multi-Objective Attack

    cs.LG 2025-07 conditional novelty 6.0 of 10

    MVMO, a new weighted multi-objective attack, can inflate earnings and lower fraud scores in about 50 to 66 percent of firm-years, versus under 14 percent for standard attacks.

  2. How much do language models memorize?

    cs.CL 2025-05 conditional novelty 6.0 of 10

    A compression-based measurement puts GPT-style model memorization capacity at roughly 3.6 bits per parameter, with membership inference success following a sigmoid in the dataset-to-capacity ratio.

  3. lmgame-Bench: How Good are LLMs at Playing Games?

    cs.AI 2025-05 conditional novelty 6.0 of 10

    lmgame-Bench turns six classic games into a scaffolded LLM evaluation suite, ranks 13 models, detects contamination, and reports RL transfer from Sokoban or Tetris to unseen games and planning tasks.

  4. Preempting Text Sanitization Utility in Resource-Constrained Privacy-Preserving LLM Interactions

    cs.CR 2024-11 conditional novelty 6.0 of 10

    A local small language model can predict when a differentially private sanitized prompt will still yield useful LLM output, saving up to 20% of wasted API calls, and an exact-nearest-neighbor implementation of the dX-...

  5. Privacy Accounting and Quality Control in the Sage Differentially Private ML Platform

    stat.ML 2019-09 conditional novelty 6.0 of 10

    Sage enforces a global differential privacy guarantee over a growing data stream using block-level composition, and adds privacy-adaptive training with SLAed validation to maintain model quality.

  6. Context Reasoner: Incentivizing Reasoning Capability for Contextualized Privacy and Safety Compliance via Reinforcement Learning

    cs.CL 2025-05 conditional novelty 5.0 of 10

    A Context Reasoner pipeline that cold-starts LLMs on distilled legal reasoning and applies PPO with a rule-based compliance reward improves performance on CI-based legal compliance benchmarks and transfers to general ...

  7. Towards the Anonymization of the Language Modeling

    cs.CL 2025-01 unverdicted novelty 4.0 of 10

    Authors introduce MLM and CLM specialization methods that avoid memorizing identifiers in sensitive training data while aiming for a privacy-utility tradeoff on medical datasets.

  8. The FACTS of Technology-Assisted Sensitivity Review

    cs.CY 2019-07 unverdicted novelty 2.0 of 10

    The paper outlines the impact of FACTS issues on technology-assisted sensitivity review for government documents and identifies areas for future research.

  9. Synthetic Data Privacy Metrics

    cs.LG 2025-01 unverdicted

    This preprint reviews existing privacy metrics for synthetic data and privacy-enhancing techniques, and argues that the field lacks standardization.

Pith tools