Does Vec2Text Pose a New Corpus Poisoning Threat?

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zhuang, Shengyao, Koopman, Bevan, Zuccon, Guido
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909343060852736
author Zhuang, Shengyao
Koopman, Bevan
Zuccon, Guido
author_facet Zhuang, Shengyao
Koopman, Bevan
Zuccon, Guido
contents The emergence of Vec2Text -- a method for text embedding inversion -- has raised serious privacy concerns for dense retrieval systems which use text embeddings. This threat comes from the ability for an attacker with access to embeddings to reconstruct the original text. In this paper, we take a new look at Vec2Text and investigate how much of a threat it poses to the different attacks of corpus poisoning, whereby an attacker injects adversarial passages into a retrieval corpus with the intention of misleading dense retrievers. Theoretically, Vec2Text is far more dangerous than previous attack methods because it does not need access to the embedding model's weights and it can efficiently generate many adversarial passages. We show that under certain conditions, corpus poisoning with Vec2Text can pose a serious threat to dense retriever system integrity and user experience by injecting adversarial passaged into top ranked positions. Code and data are made available at https://github.com/ielab/vec2text-corpus-poisoning
format Preprint
id arxiv_https___arxiv_org_abs_2410_06628
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Does Vec2Text Pose a New Corpus Poisoning Threat?
Zhuang, Shengyao
Koopman, Bevan
Zuccon, Guido
Information Retrieval
The emergence of Vec2Text -- a method for text embedding inversion -- has raised serious privacy concerns for dense retrieval systems which use text embeddings. This threat comes from the ability for an attacker with access to embeddings to reconstruct the original text. In this paper, we take a new look at Vec2Text and investigate how much of a threat it poses to the different attacks of corpus poisoning, whereby an attacker injects adversarial passages into a retrieval corpus with the intention of misleading dense retrievers. Theoretically, Vec2Text is far more dangerous than previous attack methods because it does not need access to the embedding model's weights and it can efficiently generate many adversarial passages. We show that under certain conditions, corpus poisoning with Vec2Text can pose a serious threat to dense retriever system integrity and user experience by injecting adversarial passaged into top ranked positions. Code and data are made available at https://github.com/ielab/vec2text-corpus-poisoning
title Does Vec2Text Pose a New Corpus Poisoning Threat?
topic Information Retrieval
url https://arxiv.org/abs/2410.06628