arXiv:2507.17259cs.CRcs.CL2025-07被引 3

首个面向表格数据的隐私攻击基准,揭示大模型记忆结构化信息的风险

Tab-MIA: A Benchmark Dataset for Membership Inference Attacks on Tabular Data in LLMs

  • 构建五类表格数据的六种编码格式,形成系统评估工具
  • 微调仅3轮,攻击准确率高达90%,暴露严重隐私漏洞
  • 适合研究大模型隐私、数据安全与对抗攻击的学者参考

大型语言模型(LLMs)越来越多地训练于表格数据,这类数据结构清晰、显式包含个人身份信息(PII),易引发隐私泄露风险。尽管现有成员推理攻击(MIA)主要针对非结构化文本,但其在结构化数据上的效果可能不同,因数据内容受限、类型多样、取值分布独特及列级语义复杂。本文提出 Tab-MIA,首个用于评估 LLMs 中表格数据成员推理攻击的基准数据集。该数据集包含五类数据集合,每类以六种不同编码格式表示。我们利用此基准对多种主流 MIA 方法在微调后的表格数据模型上进行首次系统评估。实验基于 Wikipedia 表格提取的结构化数据,分析预训练模型对表格数据的记忆行为。结果表明,模型在不同编码格式下表现出差异化的记忆模式,易被攻击者通过成员推理提取敏感记录。即使仅微调3个周期,多数情况下攻击的 AUROC 仍接近90%。Tab-MIA 支持系统性风险评估,为开发表格数据的隐私保护方法奠定基础。

原文摘要 · Abstract (English)

Large language models (LLMs) are increasingly trained on tabular data, which, unlike unstructured text, often contains personally identifiable information (PII) in a highly structured and explicit format. As a result, privacy risks arise, since sensitive records can be inadvertently retained by the model and exposed through data extraction or membership inference attacks (MIAs). While existing MIA methods primarily target textual content, their efficacy and threat implications may differ when applied to structured data, due to its limited content, diverse data types, unique value distributions, and column-level semantics. In this paper, we present Tab-MIA, a benchmark dataset for evaluating MIAs on tabular data in LLMs and demonstrate how it can be used. Tab-MIA comprises five data collections, each represented in six different encoding formats. Using our Tab-MIA benchmark, we conduct the first evaluation of state-of-the-art MIA methods on LLMs finetuned with tabular data across multiple encoding formats. In the evaluation, we analyze the memorization behavior of pretrained LLMs on structured data derived from Wikipedia tables. Our findings show that LLMs memorize tabular data in ways that vary across encoding formats, making them susceptible to extraction via MIAs. Even when fine-tuned for as few as three epochs, models exhibit high vulnerability, with AUROC scores approaching 90% in most cases. Tab-MIA enables systematic evaluation of these risks and provides a foundation for developing privacy-preserving methods for tabular data in LLMs.

隐私安全大模型成员推理表格数据

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。