In plain words: A lightweight fine-tuning step teaches a big language model to say "I don't know" when asked about specific private facts it memorized from web data. In questions answered without looking anything up, it hid those facts while keeping the model's overall ability nearly unchanged.
Abstract
We explore a knowledge sanitization approach to mitigate the privacy concerns associated with large language models (LLMs). LLMs trained on a large corpus of Web data can memorize and potentially reveal sensitive or confidential information, raising critical security concerns. Our technique efficiently fine-tunes these models using the Low-Rank Adaptation (LoRA) method, prompting them to generate harmless responses such as ``I don't know'' when queried about specific information. Experimental results in a closed-book question-answering task show that our straightforward method not only minimizes particular knowledge leakage but also preserves the overall performance of LLMs. These two advantages strengthen the defense against extraction attacks and reduces the emission of harmful content such as hallucinations.
Yoichi Ishibashi, Hidetoshi Shimodaira
arXiv:2309.11852 · cs.CL · submitted Sep 21, 2023 · updated Mar 2, 2024
abstract · pdf · html