arXiv:2502.03692cs.LGcs.CL2025-02ICLR被引 1

针对文档问答模型提出两种新隐私攻击,可判断文档是否被训练过。

DocMIA: Document-Level Membership Inference Attacks against DocVQA Models

  • 设计白盒与黑盒两种攻击,无需辅助数据集
  • 在多个文档问答模型上超越现有最优攻击效果
  • 揭示文档级模型的隐私泄露风险,适合关注数据安全的研究者

文档视觉问答(DocVQA)已成为多模态大模型的标准评估基准,推动了文档自动化处理的发展。然而,文档常包含敏感信息,训练此类模型存在隐私风险。本文提出两种专为DocVQA模型设计的新型成员推理攻击,分别适用于白盒(完全访问模型参数)和黑盒(仅能获取输出)场景。攻击假设攻击者无辅助数据集,更贴近实际但更具挑战性。所提无监督方法在多种DocVQA模型和数据集上均优于现有最先进攻击,证明其有效性并凸显该领域的隐私风险。

原文摘要 · Abstract (English)

Document Visual Question Answering (DocVQA) has introduced a new paradigm for end-to-end document understanding, and quickly became one of the standard benchmarks for multimodal LLMs. Automating document processing workflows, driven by DocVQA models, presents significant potential for many business sectors. However, documents tend to contain highly sensitive information, raising concerns about privacy risks associated with training such DocVQA models. One significant privacy vulnerability, exploited by the membership inference attack, is the possibility for an adversary to determine if a particular record was part of the model's training data. In this paper, we introduce two novel membership inference attacks tailored specifically to DocVQA models. These attacks are designed for two different adversarial scenarios: a white-box setting, where the attacker has full access to the model architecture and parameters, and a black-box setting, where only the model's outputs are available. Notably, our attacks assume the adversary lacks access to auxiliary datasets, which is more realistic in practice but also more challenging. Our unsupervised methods outperform existing state-of-the-art membership inference attacks across a variety of DocVQA models and datasets, demonstrating their effectiveness and highlighting the privacy risks in this domain.

隐私攻击文档理解成员推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。