Prompt-tuning has received attention as an efficient tuning method in the language domain, i.e., tuning a prompt that is a few tokens long, while keeping the large language model frozen, yet achieving comparable performance with conventional fine-tuning. Considering the emerging privacy concerns with language models, we initiate the study of privacy leakage in the setting of prompt-tuning. We first describe a real-world email service pipeline to provide customized output for various users via prompt-tuning. Then we propose a novel privacy attack framework to infer users' private information by exploiting the prompt module with user-specific signals. We conduct a comprehensive privacy evaluation on the target pipeline to demonstrate the potential leakage from prompt-tuning. The results also demonstrate the effectiveness of the proposed attack.
翻译:提示调优作为一种高效的语言领域微调方法受到关注,即仅调整由少量词元构成的提示,同时冻结大型语言模型,却能达到与传统微调相当的性能。鉴于语言模型引发的隐私问题日益凸显,我们率先开展了提示调优场景下隐私泄露的研究。首先,我们描述了一个真实的电子邮件服务流水线,通过提示调优为不同用户提供定制化输出。接着,我们提出了一种新颖的隐私攻击框架,通过利用包含用户特异性信号的提示模块来推断用户的隐私信息。我们对目标流水线进行了全面的隐私评估,以证明提示调优可能带来的隐私泄露。结果同时也证实了所提攻击方法的有效性。