Measuring Impacts of Poisoning on Model Parameters and Embeddings for Large Language Models of Code

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Hussain, Aftab, Rabin, Md Rafiqul Islam, Alipour, Mohammad Amin
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909207036428288
author Hussain, Aftab
Rabin, Md Rafiqul Islam
Alipour, Mohammad Amin
author_facet Hussain, Aftab
Rabin, Md Rafiqul Islam
Alipour, Mohammad Amin
contents Large language models (LLMs) have revolutionized software development practices, yet concerns about their safety have arisen, particularly regarding hidden backdoors, aka trojans. Backdoor attacks involve the insertion of triggers into training data, allowing attackers to manipulate the behavior of the model maliciously. In this paper, we focus on analyzing the model parameters to detect potential backdoor signals in code models. Specifically, we examine attention weights and biases, and context embeddings of the clean and poisoned CodeBERT and CodeT5 models. Our results suggest noticeable patterns in context embeddings of poisoned samples for both the poisoned models; however, attention weights and biases do not show any significant differences. This work contributes to ongoing efforts in white-box detection of backdoor signals in LLMs of code through the analysis of parameters and embeddings.
format Preprint
id arxiv_https___arxiv_org_abs_2405_11466
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Measuring Impacts of Poisoning on Model Parameters and Embeddings for Large Language Models of Code
Hussain, Aftab
Rabin, Md Rafiqul Islam
Alipour, Mohammad Amin
Software Engineering
Large language models (LLMs) have revolutionized software development practices, yet concerns about their safety have arisen, particularly regarding hidden backdoors, aka trojans. Backdoor attacks involve the insertion of triggers into training data, allowing attackers to manipulate the behavior of the model maliciously. In this paper, we focus on analyzing the model parameters to detect potential backdoor signals in code models. Specifically, we examine attention weights and biases, and context embeddings of the clean and poisoned CodeBERT and CodeT5 models. Our results suggest noticeable patterns in context embeddings of poisoned samples for both the poisoned models; however, attention weights and biases do not show any significant differences. This work contributes to ongoing efforts in white-box detection of backdoor signals in LLMs of code through the analysis of parameters and embeddings.
title Measuring Impacts of Poisoning on Model Parameters and Embeddings for Large Language Models of Code
topic Software Engineering
url https://arxiv.org/abs/2405.11466