SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Zhang, Kaiyuan, Cheng, Siyuan, Guo, Hanxi, Chen, Yuetian, Su, Zian, An, Shengwei, Du, Yuntao, Fleming, Charles, Kundu, Ashish, Zhang, Xiangyu, Li, Ninghui
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912426724687872
author Zhang, Kaiyuan
Cheng, Siyuan
Guo, Hanxi
Chen, Yuetian
Su, Zian
An, Shengwei
Du, Yuntao
Fleming, Charles
Kundu, Ashish
Zhang, Xiangyu
Li, Ninghui
author_facet Zhang, Kaiyuan
Cheng, Siyuan
Guo, Hanxi
Chen, Yuetian
Su, Zian
An, Shengwei
Du, Yuntao
Fleming, Charles
Kundu, Ashish
Zhang, Xiangyu
Li, Ninghui
contents Large language models (LLMs) have achieved remarkable success and are widely adopted for diverse applications. However, fine-tuning these models often involves private or sensitive information, raising critical privacy concerns. In this work, we conduct the first comprehensive study evaluating the vulnerability of fine-tuned LLMs to membership inference attacks (MIAs). Our empirical analysis demonstrates that MIAs exploit the loss reduction during fine-tuning, making them highly effective in revealing membership information. These findings motivate the development of our defense. We propose SOFT (\textbf{S}elective data \textbf{O}bfuscation in LLM \textbf{F}ine-\textbf{T}uning), a novel defense technique that mitigates privacy leakage by leveraging influential data selection with an adjustable parameter to balance utility preservation and privacy protection. Our extensive experiments span six diverse domains and multiple LLM architectures and scales. Results show that SOFT effectively reduces privacy risks while maintaining competitive model performance, offering a practical and scalable solution to safeguard sensitive information in fine-tuned LLMs.
format Preprint
id arxiv_https___arxiv_org_abs_2506_10424
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks
Zhang, Kaiyuan
Cheng, Siyuan
Guo, Hanxi
Chen, Yuetian
Su, Zian
An, Shengwei
Du, Yuntao
Fleming, Charles
Kundu, Ashish
Zhang, Xiangyu
Li, Ninghui
Cryptography and Security
Artificial Intelligence
Large language models (LLMs) have achieved remarkable success and are widely adopted for diverse applications. However, fine-tuning these models often involves private or sensitive information, raising critical privacy concerns. In this work, we conduct the first comprehensive study evaluating the vulnerability of fine-tuned LLMs to membership inference attacks (MIAs). Our empirical analysis demonstrates that MIAs exploit the loss reduction during fine-tuning, making them highly effective in revealing membership information. These findings motivate the development of our defense. We propose SOFT (\textbf{S}elective data \textbf{O}bfuscation in LLM \textbf{F}ine-\textbf{T}uning), a novel defense technique that mitigates privacy leakage by leveraging influential data selection with an adjustable parameter to balance utility preservation and privacy protection. Our extensive experiments span six diverse domains and multiple LLM architectures and scales. Results show that SOFT effectively reduces privacy risks while maintaining competitive model performance, offering a practical and scalable solution to safeguard sensitive information in fine-tuned LLMs.
title SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2506.10424