الملخص
Beyond adapting Large Language Models (LLMs) to specialized applications, fine-tuning has recently been shown to recover private information that is no longer accessible through direct queries. Previous fine-tuning recovery attacks, however, require genuine private supervision drawn from the same distribution, i.e., the previous training dataset. We argue that such recovery remains possible without such impractical knowledge. We show that LLM-generated candidates can provide sufficient supervision to recover previously learned private associations. Based on this, we propose ReGap, a data-free attack that recovers private associations using task structure, filters them by answer-token likelihood, and updates the target model via low-rank adaptation. Specifically, ReGap requires neither target answers nor auxiliary genuine private supervision. Across six GPT-2, OPT, and Qwen3 models, ReGap improves target-association recovery by 6-21 percentage points over the post-training target model. Recovery remains substantial even when the adaptation identities are disjoint from all memorized and evaluation identities, with no exact target answers appearing in the generated or selected supervision. Moreover, the same trained adapters increase recovery from 42\% to 63\% on a previously exposed checkpoint, but produce no gain on a matched checkpoint that never encountered the targets. This contrast shows that adaptation alone is insufficient to explain the observed recovery and that prior target exposure strongly affects post-adaptation recoverability. Our findings highlight that routine model customization can reawaken latent privacy risks, warranting urgent attention from the academic and industrial communities.
الكلمات المفتاحية
الموضوع
بيانات النشر
- المجلة
- غير متاح
- وصول مفتوح
- وصول مفتوح أخضر
اقتبس هذه المقالة
APA 7
Li, J., Chen, J., Pu, Y., Zhou, C., Ma, O., Feng, Z., Zhang, H., Bi, J., & Hu, C. (2026). Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models. https://omanscience.com/ar/articles/sleeping-secrets-how-fine-tuning-reawakens-privacy-risks-in-language-models
MLA 9
Li, Jianhong, et al. "Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models." https://omanscience.com/ar/articles/sleeping-secrets-how-fine-tuning-reawakens-privacy-risks-in-language-models.
شيكاغو (المؤلف–التاريخ)
Li, Jianhong, Jiahao Chen, Yuwen Pu, Chunyi Zhou, Oubo Ma, Zhou Feng, Hangtao Zhang, Jichao Bi, and Chunqiang Hu. 2026. "Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models." https://omanscience.com/ar/articles/sleeping-secrets-how-fine-tuning-reawakens-privacy-risks-in-language-models.
هارفارد
Li, J., Chen, J., Pu, Y., Zhou, C., Ma, O., Feng, Z., Zhang, H., Bi, J. and Hu, C. (2026) 'Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models', Available at: https://omanscience.com/ar/articles/sleeping-secrets-how-fine-tuning-reawakens-privacy-risks-in-language-models.
فانكوفر
Li J, Chen J, Pu Y, Zhou C, Ma O, Feng Z, et al. Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models. https://omanscience.com/ar/articles/sleeping-secrets-how-fine-tuning-reawakens-privacy-risks-in-language-models
IEEE
J. Li, J. Chen, Y. Pu, C. Zhou, O. Ma, Z. Feng, H. Zhang, J. Bi, and C. Hu, "Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models," https://omanscience.com/ar/articles/sleeping-secrets-how-fine-tuning-reawakens-privacy-risks-in-language-models.