Understanding Privacy Risks of Embeddings Induced by Large Language Models

Zhihao Zhu,Ninglu Shao,Defu Lian,Chenwang Wu,Zheng Liu,Yi Yang,Enhong Chen
2024-04-25
Abstract:Large language models (LLMs) show early signs of artificial general intelligence but struggle with hallucinations. One promising solution to mitigate these hallucinations is to store external knowledge as embeddings, aiding LLMs in retrieval-augmented generation. However, such a solution risks compromising privacy, as recent studies experimentally showed that the original text can be partially reconstructed from text embeddings by pre-trained language models. The significant advantage of LLMs over traditional pre-trained models may exacerbate these concerns. To this end, we investigate the effectiveness of reconstructing original knowledge and predicting entity attributes from these embeddings when LLMs are employed. Empirical findings indicate that LLMs significantly improve the accuracy of two evaluated tasks over those from pre-trained models, regardless of whether the texts are in-distribution or out-of-distribution. This underscores a heightened potential for LLMs to jeopardize user privacy, highlighting the negative consequences of their widespread use. We further discuss preliminary strategies to mitigate this risk.
Computation and Language,Artificial Intelligence
What problem does this paper attempt to address?
The problem that this paper attempts to solve is the potential privacy risks that large language models (LLMs) may bring when using text embeddings to enhance their generation capabilities. Specifically, researchers are concerned with how to partially reconstruct the original text or predict entity attributes through these text embeddings generated by large language models, which may lead to the leakage of user privacy. Although embeddings are generally considered to be safe and private because they are just real - valued vectors, recent research has shown that part of the original text and author information can be recovered from these embeddings through pre - trained language models. This has drawn attention to the potential risks of large language models in this regard, especially considering that LLMs are more powerful than traditional pre - trained models and may exacerbate these privacy issues. Therefore, this paper aims to explore and evaluate this risk and discuss preliminary risk mitigation strategies.