Extracting memorized pieces of (copyrighted) books from open-weight language models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cooper, A. Feder, Lemley, Mark A., Casasola, Allison, Ahmed, Ahmed, Gokaslan, Aaron, Cyphert, Amy B., De Sa, Christopher, Ho, Daniel E., Liang, Percy
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910184105836544
author Cooper, A. Feder
Lemley, Mark A.
Casasola, Allison
Ahmed, Ahmed
Gokaslan, Aaron
Cyphert, Amy B.
De Sa, Christopher
Ho, Daniel E.
Liang, Percy
author_facet Cooper, A. Feder
Lemley, Mark A.
Casasola, Allison
Ahmed, Ahmed
Gokaslan, Aaron
Cyphert, Amy B.
De Sa, Christopher
Ho, Daniel E.
Liang, Percy
contents Plaintiffs and defendants in copyright lawsuits over generative AI often make sweeping, opposing claims about the extent to which large language models (LLMs) memorize protected expression from books in their training data. We show that these polarized positions dramatically oversimplify the relationship between memorization and copyright. To do so, we develop a technique to measure memorization of books, which we apply to 200 books and 14 open-weight LLMs. Through over 3000 experiments, we show that memorization varies both by model and book. With respect to our specific extraction methodology, we find that most LLMs do not memorize most books -- either in whole or in part; however, there are notable exceptions. For instance, Llama 3.1 70B entirely memorizes some books, like Harry Potter and the Sorcerer's Stone; memorization is so extensive that one can deterministically extract the whole book almost verbatim using the book's first few words as an initial prompt. We discuss why our results have significant implications for copyright cases, though not ones that unambiguously favor either side.
format Preprint
id arxiv_https___arxiv_org_abs_2505_12546
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Extracting memorized pieces of (copyrighted) books from open-weight language models
Cooper, A. Feder
Lemley, Mark A.
Casasola, Allison
Ahmed, Ahmed
Gokaslan, Aaron
Cyphert, Amy B.
De Sa, Christopher
Ho, Daniel E.
Liang, Percy
Computation and Language
Computers and Society
Machine Learning
Plaintiffs and defendants in copyright lawsuits over generative AI often make sweeping, opposing claims about the extent to which large language models (LLMs) memorize protected expression from books in their training data. We show that these polarized positions dramatically oversimplify the relationship between memorization and copyright. To do so, we develop a technique to measure memorization of books, which we apply to 200 books and 14 open-weight LLMs. Through over 3000 experiments, we show that memorization varies both by model and book. With respect to our specific extraction methodology, we find that most LLMs do not memorize most books -- either in whole or in part; however, there are notable exceptions. For instance, Llama 3.1 70B entirely memorizes some books, like Harry Potter and the Sorcerer's Stone; memorization is so extensive that one can deterministically extract the whole book almost verbatim using the book's first few words as an initial prompt. We discuss why our results have significant implications for copyright cases, though not ones that unambiguously favor either side.
title Extracting memorized pieces of (copyrighted) books from open-weight language models
topic Computation and Language
Computers and Society
Machine Learning
url https://arxiv.org/abs/2505.12546