LLM推荐系统可能泄露用户隐私,攻击者可推断其是否在系统中被记录。
Membership Inference Attacks on In-Context Examples in LLM-based Recommender Systems
- 利用提示中的独特结构设计新型隐私攻击
- 在三个数据集上攻击成功率超80%
- 适合关注大模型推荐系统安全的研究者
基于大语言模型(LLM)的推荐系统可通过上下文学习(ICL)灵活适应不同领域,使用包含用户敏感历史交互信息的提示来定制推荐功能。然而,尚无研究探讨此类私密信息是否可能通过新型隐私攻击暴露。本文设计了两种成员推理攻击(MIAs):ItemMem 和 RecInertia,旨在判断系统提示中是否包含目标用户的个人信息。我们在最新的开源LLM及三个知名推荐系统数据集上进行了全面评估。结果表明,针对LLM推荐系统的成员推理威胁真实存在,且比提示提取攻击更为复杂。这些攻击利用ICL推荐系统中独特的提示结构,难以通过现有提示提取防御方法有效缓解。
原文摘要 · Abstract (English)
Large language models (LLMs) based recommender systems (RecSys) can adapt flexibly across different domains. It uses in-context learning (ICL), i.e., prompts, including sensitive historical user-specific item interactions, to customize the recommendation functions. However, no study has examined whether such private information may be exposed by novel privacy attacks. We design two membership inference attacks (MIAs): \emph{ItemMem}, and \emph{RecInertia}, aiming to identify whether system prompts contain the victim's information. We have carefully evaluated them on the latest open-source LLMs and three well-known RecSys datasets. The results confirm that the MIA threat to LLM RecSys is realistic and can be more sophisticated than prompt extraction. They utilize the unique prompt structures in ICL RecSys and cannot be easily mitigated with existing defense methods on prompt extraction.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。