Learnable Privacy Neurons Localization in Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Ruizhe, Hu, Tianxiang, Feng, Yang, Liu, Zuozhu
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909206756458496
author Chen, Ruizhe
Hu, Tianxiang
Feng, Yang
Liu, Zuozhu
author_facet Chen, Ruizhe
Hu, Tianxiang
Feng, Yang
Liu, Zuozhu
contents Concerns regarding Large Language Models (LLMs) to memorize and disclose private information, particularly Personally Identifiable Information (PII), become prominent within the community. Many efforts have been made to mitigate the privacy risks. However, the mechanism through which LLMs memorize PII remains poorly understood. To bridge this gap, we introduce a pioneering method for pinpointing PII-sensitive neurons (privacy neurons) within LLMs. Our method employs learnable binary weight masks to localize specific neurons that account for the memorization of PII in LLMs through adversarial training. Our investigations discover that PII is memorized by a small subset of neurons across all layers, which shows the property of PII specificity. Furthermore, we propose to validate the potential in PII risk mitigation by deactivating the localized privacy neurons. Both quantitative and qualitative experiments demonstrate the effectiveness of our neuron localization algorithm.
format Preprint
id arxiv_https___arxiv_org_abs_2405_10989
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Learnable Privacy Neurons Localization in Language Models
Chen, Ruizhe
Hu, Tianxiang
Feng, Yang
Liu, Zuozhu
Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
Concerns regarding Large Language Models (LLMs) to memorize and disclose private information, particularly Personally Identifiable Information (PII), become prominent within the community. Many efforts have been made to mitigate the privacy risks. However, the mechanism through which LLMs memorize PII remains poorly understood. To bridge this gap, we introduce a pioneering method for pinpointing PII-sensitive neurons (privacy neurons) within LLMs. Our method employs learnable binary weight masks to localize specific neurons that account for the memorization of PII in LLMs through adversarial training. Our investigations discover that PII is memorized by a small subset of neurons across all layers, which shows the property of PII specificity. Furthermore, we propose to validate the potential in PII risk mitigation by deactivating the localized privacy neurons. Both quantitative and qualitative experiments demonstrate the effectiveness of our neuron localization algorithm.
title Learnable Privacy Neurons Localization in Language Models
topic Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
url https://arxiv.org/abs/2405.10989