实验证明大模型对部分书籍存在完整记忆,但非普遍现象。
Extracting memorized pieces of (copyrighted) books from open-weight language models
- 通过首词提示法系统检测模型对书籍的复现程度
- 14个模型中仅少数对特定书籍实现近乎全文复刻
- 结果为版权诉讼提供量化依据,但不偏袒任一方
在生成式AI版权诉讼中,原告与被告常就大语言模型(LLMs)是否记忆受版权保护的内容做出极端对立的声明。我们发现这种二元对立严重简化了记忆与版权之间的关系。为此,我们开发了一种测量书籍记忆程度的技术,并应用于200本图书和14个开源权重的LLM上。通过超过3000次实验,我们发现记忆程度在模型与书籍之间存在显著差异。以特定提取方法而言,大多数模型并未完整或部分记忆大多数书籍;然而存在明显例外:例如,Llama 3.1 70B模型完全记住了《哈利·波特与魔法石》一书,仅需书名开头几个词作为提示,即可确定性地几乎逐字复现全书内容。我们讨论这些结果对版权案件的重大意义,尽管其影响并非明确有利于任一方。
原文摘要 · Abstract (English)
Plaintiffs and defendants in copyright lawsuits over generative AI often make sweeping, opposing claims about the extent to which large language models (LLMs) memorize protected expression from books in their training data. We show that these polarized positions dramatically oversimplify the relationship between memorization and copyright. To do so, we develop a technique to measure memorization of books, which we apply to 200 books and 14 open-weight LLMs. Through over 3000 experiments, we show that memorization varies both by model and book. With respect to our specific extraction methodology, we find that most LLMs do not memorize most books -- either in whole or in part; however, there are notable exceptions. For instance, Llama 3.1 70B entirely memorizes some books, like Harry Potter and the Sorcerer's Stone; memorization is so extensive that one can deterministically extract the whole book almost verbatim using the book's first few words as an initial prompt. We discuss why our results have significant implications for copyright cases, though not ones that unambiguously favor either side.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。