{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:VJ4EUO5ZGGGF2JUJRUJKWEJTIA","short_pith_number":"pith:VJ4EUO5Z","schema_version":"1.0","canonical_sha256":"aa784a3bb9318c5d26898d12ab1133403d07e8c46e39575b639278368e76e289","source":{"kind":"arxiv","id":"2405.05990","version":2},"attestation_state":"computed","paper":{"title":"Special Characters Attack: Toward Scalable Training Data Extraction From Large Language Models","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Ge Pei, Jindong Gu, Xingjun Ma, Yang Bai, Yong Yang","submitted_at":"2024-05-09T02:35:32Z","abstract_excerpt":"Large language models (LLMs) have achieved remarkable performance on a wide range of tasks. However, recent studies have shown that LLMs can memorize training data and simple repeated tokens can trick the model to leak the data. In this paper, we take a step further and show that certain special characters or their combinations with English letters are stronger memory triggers, leading to more severe data leakage. The intuition is that, since LLMs are trained with massive data that contains a substantial amount of special characters (e.g. structural symbols {, } of JSON files, and @, # in emai"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.05990","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2024-05-09T02:35:32Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG"],"title_canon_sha256":"26e5a50810a2fa7137d8301aba83021b3f923173fac44a66597830df23495b0f","abstract_canon_sha256":"784493f68ce295b848b5df8d38b30228ddcb9bf49a84da5a204d5fc5c2ca984f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:20:54.527161Z","signature_b64":"hZykvsB/H6yHbg2dXRSX8geyg7nYil9pK7OC3h3Hn3Zup7KipcCAptnNgRo56ZeA2Mx5iU7qp97yqOn8EgPhBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"aa784a3bb9318c5d26898d12ab1133403d07e8c46e39575b639278368e76e289","last_reissued_at":"2026-07-05T08:20:54.526695Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:20:54.526695Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Special Characters Attack: Toward Scalable Training Data Extraction From Large Language Models","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Ge Pei, Jindong Gu, Xingjun Ma, Yang Bai, Yong Yang","submitted_at":"2024-05-09T02:35:32Z","abstract_excerpt":"Large language models (LLMs) have achieved remarkable performance on a wide range of tasks. However, recent studies have shown that LLMs can memorize training data and simple repeated tokens can trick the model to leak the data. In this paper, we take a step further and show that certain special characters or their combinations with English letters are stronger memory triggers, leading to more severe data leakage. The intuition is that, since LLMs are trained with massive data that contains a substantial amount of special characters (e.g. structural symbols {, } of JSON files, and @, # in emai"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.05990","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.05990/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.05990","created_at":"2026-07-05T08:20:54.526747+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.05990v2","created_at":"2026-07-05T08:20:54.526747+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.05990","created_at":"2026-07-05T08:20:54.526747+00:00"},{"alias_kind":"pith_short_12","alias_value":"VJ4EUO5ZGGGF","created_at":"2026-07-05T08:20:54.526747+00:00"},{"alias_kind":"pith_short_16","alias_value":"VJ4EUO5ZGGGF2JUJ","created_at":"2026-07-05T08:20:54.526747+00:00"},{"alias_kind":"pith_short_8","alias_value":"VJ4EUO5Z","created_at":"2026-07-05T08:20:54.526747+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2502.05206","citing_title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","ref_index":211,"is_internal_anchor":false},{"citing_arxiv_id":"2406.08464","citing_title":"Magpie: Alignment Data Synthesis from Scratch by Prompting Aligned LLMs with Nothing","ref_index":89,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA","json":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA.json","graph_json":"https://pith.science/api/pith-number/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/graph.json","events_json":"https://pith.science/api/pith-number/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/events.json","paper":"https://pith.science/paper/VJ4EUO5Z"},"agent_actions":{"view_html":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA","download_json":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA.json","view_paper":"https://pith.science/paper/VJ4EUO5Z","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.05990&json=true","fetch_graph":"https://pith.science/api/pith-number/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/graph.json","fetch_events":"https://pith.science/api/pith-number/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/action/storage_attestation","attest_author":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/action/author_attestation","sign_citation":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/action/citation_signature","submit_replication":"https://pith.science/pith/VJ4EUO5ZGGGF2JUJRUJKWEJTIA/action/replication_record"}},"created_at":"2026-07-05T08:20:54.526747+00:00","updated_at":"2026-07-05T08:20:54.526747+00:00"}