Pretraining Data Exposure in Large Language Models: A Survey of Membership Inference, Data Contamination, and Security Implications
Quick Answer
This paper shows that This survey addresses Pretraining Data Exposure (PDE) in Large Language Models (LLMs), highlighting its implications for privacy and data integrity.
Quick Take
It unifies the study of membership inference and data contamination, presenting formal definitions, attack and defense strategies, and outlining future research challenges in the context of .
Key Points
- PDE determines if specific data was included in an LLM's training corpus.
- The paper synthesizes empirical findings and highlights open research challenges.
- Membership inference and data contamination are critical areas intersecting with PDE.
- Unified survey provides a comprehensive framework for understanding PDE.
- Attack and defense methods against PDE are reviewed and formalized.
Paper Resources
Article Excerpt
From source RSS / original summaryarXiv:2605. 26133v1 Announce Type: new Abstract: (LLMs) have become the predominant paradigm in NLP, advancing both research and industry. As model sizes and pretraining data grow, concerns about Pretraining Data Exposure (PDE) increase due to the scale and opacity of training datasets. PDE refers to determining whether specific data appeared in an LLM's pretraining corpus.
It is critical for ensuring evaluation integrity and protecting privacy, intersecting two key areas: data contamination and membership inference. Though conceptually related, these areas have often been studied in isolation. This paper offers the first unified survey of both under the PDE framework. We formalize PDE across exposure levels, review attack and defense methods, synthesize empirical findings, and highlight open challenges and future research directions.
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from arXiv cs.CL
See more →TriAgent: Divergence-Aware Committees for Cost-Efficient Financial Sentiment Analysis
TriAgent introduces a cost-efficient multi-agent system for financial sentiment analysis, combining VADER, FinBERT, and Qwen2.5. It achieves an F1 score of ~0.87 with significant savings of $9.3M/year at a 10M-user scale compared to GPT-4o-mini, while also detecting hallucinations with an AUC of 0.90.