利用语言相似性提升少样本跨语言嵌入逆向攻击效果
LAGO: Few-shot Crosslingual Embedding Inversion Attacks via Language Similarity-Aware Graph Optimization
- 构建基于图优化的联合学习框架,融合语法与词汇相似性约束
- 仅用10样本/语言即实现攻击性能提升10-20%(Rouge-L)
- 适用于多语言隐私防护研究,尤其关注跨语言泄露风险
我们提出LAGO——一种基于语言相似性的图优化方法,用于少样本跨语言嵌入逆向攻击,揭示多语言自然语言处理系统中的关键隐私漏洞。不同于以往独立处理各语言的方法,LAGO通过图结构的约束分布式优化框架显式建模语言间关系。结合句法和词汇相似性作为边约束,实现相关语言间的协同参数学习。理论上,该方法推广了已有方案(如ALGEN),当相似性约束松弛时可退化为特例。框架创新性地融合弗罗贝尼乌斯范数正则化与线性不等式或总变差约束,即使在极低数据量(每语言仅10样本)下也能确保跨语言嵌入空间的稳健对齐。多语言与多模型的广泛实验表明,相较基线,LAGO在攻击迁移性上提升10-20% Rouge-L得分。本工作确立语言相似性是逆向攻击迁移性的关键因素,呼吁重新关注语言感知的隐私保护多语言嵌入设计。
原文摘要 · Abstract (English)
We propose LAGO - Language Similarity-Aware Graph Optimization - a novel approach for few-shot cross-lingual embedding inversion attacks, addressing critical privacy vulnerabilities in multilingual NLP systems. Unlike prior work in embedding inversion attacks that treat languages independently, LAGO explicitly models linguistic relationships through a graph-based constrained distributed optimization framework. By integrating syntactic and lexical similarity as edge constraints, our method enables collaborative parameter learning across related languages. Theoretically, we show this formulation generalizes prior approaches, such as ALGEN, which emerges as a special case when similarity constraints are relaxed. Our framework uniquely combines Frobenius-norm regularization with linear inequality or total variation constraints, ensuring robust alignment of cross-lingual embedding spaces even with extremely limited data (as few as 10 samples per language). Extensive experiments across multiple languages and embedding models demonstrate that LAGO substantially improves the transferability of attacks with 10-20% increase in Rouge-L score over baselines. This work establishes language similarity as a critical factor in inversion attack transferability, urging renewed focus on language-aware privacy-preserving multilingual embeddings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。