Canary Extraction in Natural Language Understanding Models

被引:0
|
作者
Parikh, Rahil [1 ]
Dupuy, Christophe [2 ]
Gupta, Rahul [2 ]
机构
[1] Univ Maryland, Inst Syst Res, Baltimore, MD 21201 USA
[2] Amazon Alexa AI, New York, NY USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Natural Language Understanding (NLU) models can be trained on sensitive information such as phone numbers, zip-codes etc. Recent literature has focused on Model Inversion Attacks (ModIvA) that can extract training data from model parameters. In this work, we present a version of such an attack by extracting canaries inserted in NLU training data. In the attack, an adversary with open-box access to the model reconstructs the canaries contained in the model's training set. We evaluate our approach by performing text completion on canaries and demonstrate that by using the prefix (non-sensitive) tokens of the canary, we can generate the full canary. As an example, our attack is able to reconstruct a four digit code in the training dataset of the NLU model with a probability of 0.5 in its best configuration. As countermeasures, we identify several defense mechanisms that, when combined, effectively eliminate the risk of ModIvA in our experiments.
引用
收藏
页码:552 / 560
页数:9
相关论文
共 50 条
  • [41] Stress Test Evaluation of Transformer-based Models in Natural Language Understanding Tasks
    Aspillaga, Carlos
    Carvallo, Andres
    Araujo, Vladimir
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON LANGUAGE RESOURCES AND EVALUATION (LREC 2020), 2020, : 1882 - 1894
  • [42] Optimizing Conversational Commerce Involving Multilingual Consumers Through Large Language Models' Natural Language Understanding Abilities
    Ilagan, Joseph Benjamin
    Ilagan, Jose Ramon
    Zulueta, Pia Ysabel
    Rodrigo, Maria Mercedes
    [J]. ARTIFICIAL INTELLIGENCE IN HCI, PT III, AI-HCI 2024, 2024, 14736 : 47 - 59
  • [43] UNDERSTANDING NATURAL LANGUAGE - WINOGRAD,T
    BROWN, JS
    [J]. BEHAVIORAL SCIENCE, 1973, 18 (06): : 448 - 449
  • [44] UNDERSTANDING NATURAL LANGUAGE - WINOGRAD,T
    JONES, KS
    [J]. INTERNATIONAL JOURNAL OF MAN-MACHINE STUDIES, 1974, 6 (02): : 279 - 281
  • [45] INFERENCE AND COMPUTER UNDERSTANDING OF NATURAL LANGUAGE
    SCHANK, RC
    RIEGER, CJ
    [J]. ARTIFICIAL INTELLIGENCE, 1974, 5 (04) : 373 - 412
  • [46] Consciousness - A requirement for understanding Natural Language
    Sabah, G
    [J]. TWO SCIENCES OF MIND: READING IN COGNITIVE SCIENCE AND CONSCIOUSNESS, 1997, 9 : 361 - 392
  • [47] UNDERSTANDING NATURAL LANGUAGE - WINOGRAD,T
    BODEN, MA
    [J]. BRITISH JOURNAL FOR THE PHILOSOPHY OF SCIENCE, 1974, 25 (01): : 85 - 88
  • [48] Natural language understanding - Allen,J
    Kemper, S
    [J]. JOURNAL OF LANGUAGE AND SOCIAL PSYCHOLOGY, 1996, 15 (02) : 207 - 208
  • [49] KNOWLEDGE REPRESENTATION FOR NATURAL LANGUAGE UNDERSTANDING
    Stanojevic, Mladen
    Vranes, Sanja
    [J]. FACTA UNIVERSITATIS-SERIES MATHEMATICS AND INFORMATICS, 2006, 21 : 93 - 104
  • [50] COMPUTER UNDERSTANDING OF NATURAL-LANGUAGE
    SCHANK, RC
    [J]. BEHAVIOR RESEARCH METHODS & INSTRUMENTATION, 1978, 10 (02): : 132 - 138