Papers
Topics
Authors
Recent
Search
2000 character limit reached

You Don't Know My Favorite Color: Preventing Dialogue Representations from Revealing Speakers' Private Personas

Published 26 Apr 2022 in cs.CL, cs.CR, and cs.LG | (2205.10228v1)

Abstract: Social chatbots, also known as chit-chat chatbots, evolve rapidly with large pretrained LLMs. Despite the huge progress, privacy concerns have arisen recently: training data of LLMs can be extracted via model inversion attacks. On the other hand, the datasets used for training chatbots contain many private conversations between two individuals. In this work, we further investigate the privacy leakage of the hidden states of chatbots trained by language modeling which has not been well studied yet. We show that speakers' personas can be inferred through a simple neural network with high accuracy. To this end, we propose effective defense objectives to protect persona leakage from hidden states. We conduct extensive experiments to demonstrate that our proposed defense objectives can greatly reduce the attack accuracy from 37.6% to 0.5%. Meanwhile, the proposed objectives preserve LLMs' powerful generation ability.

Citations (16)

Summary

Paper to Video (Beta)

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.

Authors (3)

Collections

Sign up for free to add this paper to one or more collections.