arXiv:2502.06560cs.CLcs.CY2025-02被引 2

低成本个性化文本生成可能被用于伪造他人笔迹,带来新型安全风险。

Position: It's Time to Act on the Risk of Efficient Personalized Text Generation

  • 用个人文本微调开源大模型,可低成本生成逼真模仿风格的假文本。
  • 只需少量公开文本即可伪造邮件或社交账号,甚至规避AI检测。
  • 该风险独立于图像/语音深伪,现有模型和研究未充分应对。

近年来,高质量开源生成式人工智能文本模型(通常称为LLMs)及高效微调技术的发展,使得基于个人数据训练出高度个性化的文本生成模型成为可能——这些模型能精准模仿特定个体的写作风格,生成符合其需求的高质量内容。该技术对个人用户而言易于获取,且可在消费级硬件上低成本完成训练与运行。尽管这对可用性与隐私保护是重大进步,本文指出,这种个性化文本生成的可行性也带来了新的安全风险:例如,仅需少量公开文本即可创建钓鱼邮件或虚假社交账号,或被本人用于规避AI检测。我们进一步认为,这类风险与图像、语音或视频深度伪造所引发的威胁互补且不同,但目前尚未被学术界或主流开闭源模型有效应对。

原文摘要 · Abstract (English)

The recent surge in high-quality open-source Generative AI text models (colloquially: LLMs), as well as efficient finetuning techniques, have opened the possibility of creating high-quality personalized models that generate text attuned to a specific individual's needs and are capable of credibly imitating their writing style by refining an open-source model with that person's own data. The technology to create such models is accessible to private individuals, and training and running such models can be done cheaply on consumer-grade hardware. While these advancements are a huge gain for usability and privacy, this position paper argues that the practical feasibility of impersonating specific individuals also introduces novel safety risks. For instance, this technology enables the creation of phishing emails or fraudulent social media accounts, based on small amounts of publicly available text, or by the individuals themselves to escape AI text detection. We further argue that these risks are complementary to - and distinct from - the much-discussed risks of other impersonation attacks such as image, voice, or video deepfakes, and are not adequately addressed by the larger research community, or the current generation of open- and closed-source models.

个性化生成文本伪造安全风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。