Stealing User Prompts from Mixture of Experts

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yona, Itay, Shumailov, Ilia, Hayes, Jamie, Carlini, Nicholas
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913567985369088
author Yona, Itay
Shumailov, Ilia
Hayes, Jamie
Carlini, Nicholas
author_facet Yona, Itay
Shumailov, Ilia
Hayes, Jamie
Carlini, Nicholas
contents Mixture-of-Experts (MoE) models improve the efficiency and scalability of dense language models by routing each token to a small number of experts in each layer. In this paper, we show how an adversary that can arrange for their queries to appear in the same batch of examples as a victim's queries can exploit Expert-Choice-Routing to fully disclose a victim's prompt. We successfully demonstrate the effectiveness of this attack on a two-layer Mixtral model, exploiting the tie-handling behavior of the torch.topk CUDA implementation. Our results show that we can extract the entire prompt using $O({VM}^2)$ queries (with vocabulary size $V$ and prompt length $M$) or 100 queries on average per token in the setting we consider. This is the first attack to exploit architectural flaws for the purpose of extracting user prompts, introducing a new class of LLM vulnerabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2410_22884
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Stealing User Prompts from Mixture of Experts
Yona, Itay
Shumailov, Ilia
Hayes, Jamie
Carlini, Nicholas
Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
Mixture-of-Experts (MoE) models improve the efficiency and scalability of dense language models by routing each token to a small number of experts in each layer. In this paper, we show how an adversary that can arrange for their queries to appear in the same batch of examples as a victim's queries can exploit Expert-Choice-Routing to fully disclose a victim's prompt. We successfully demonstrate the effectiveness of this attack on a two-layer Mixtral model, exploiting the tie-handling behavior of the torch.topk CUDA implementation. Our results show that we can extract the entire prompt using $O({VM}^2)$ queries (with vocabulary size $V$ and prompt length $M$) or 100 queries on average per token in the setting we consider. This is the first attack to exploit architectural flaws for the purpose of extracting user prompts, introducing a new class of LLM vulnerabilities.
title Stealing User Prompts from Mixture of Experts
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
url https://arxiv.org/abs/2410.22884