arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

记忆是否具有上下文敏感性?基于前缀的提取超越孤立前缀

Is Memorization Context-Sensitive? Prefix-Based Extraction Beyond Isolated Prefixes

Ali Satvaty, Narjes Sharafi, Jirui Qi, Suzan Verberne, Fatih Turkmen

arXiv 2610.12085首次发表:更新:

发表机构

University of Groningen; Leiden University(格罗宁根大学; 莱顿大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究探究LLM记忆是否具上下文敏感性,通过成对项目级概率后缀提取测量,发现记忆含上下文鲁棒核心与敏感边界,RAG未完全消除记忆风险。

AI 中文摘要

大型语言模型(LLMs)可通过基于前缀的提取暴露训练序列的记忆:给定训练示例中的一个前缀,模型可能会为原始后续内容分配高概率。然而,在部署的系统中,前缀很少被孤立评估,它们通常与指令、检索到的文档或其他特定任务上下文一同出现,如检索增强生成(RAG)中的情况。这促使我们研究上下文条件是减轻了记忆,还是仅仅改变了可提取的记忆样本集合。我们通过概率后缀提取的成对项目级测量来研究该问题:对于每个前缀-后缀对,我们在空提示和不同相关性的检索上下文下,对目标后缀进行评分,涉及三个开放权重的指令调优模型。我们发现,上下文并不会简单消除记忆,相反,可提取的记忆由上下文鲁棒核心和上下文敏感边界组成。许多无上下文时可提取的样本在检索上下文下仍可提取,尤其是随着前缀长度增加。同时,上下文主要影响提取阈值附近的边缘样本:它会抑制一些暴露,但也会产生仅靠前缀评估会遗漏的新暴露。这些发现修正了RAG降低记忆风险的观点:上下文可通过抑制边界情况降低总体提取率,但鲁棒可提取样本依然存在,且上下文启用的可提取性仍与安全相关。

英文摘要

Large language models (LLMs) can expose memorized training sequences under prefix-based extraction: given a prefix from a training example, the model may assign high probability to the original continuation. In deployed systems, however, prefixes are rarely evaluated in isolation. They often appear together with instructions, retrieved documents, or other task-specific context, as in retrieval-augmented generation (RAG). This motivates examining whether contextual conditioning mitigates memorization or merely changes the set of memorized samples that become extractable. We investigate this issue through paired item-level measurements of probabilistic suffix extraction. For each prefix-suffix pair, we score the target suffix under an empty prompt and under retrieved contexts of varying relevance, across three open-weight instruction-tuned models. We find that context does not simply erase memorization. Instead, extractable memorization consists of a context-robust core and a context-sensitive boundary. Many samples that are extractable without context remain extractable under the retrieved context, especially as the prefix length increases. At the same time, context mainly affects marginal samples near the extraction threshold: it suppresses some exposures, but also enables new ones that are missed by prefix-only evaluation. These findings qualify the view that RAG reduces memorization risk. Context can lower aggregate extraction by suppressing boundary cases, yet robustly extractable samples persist, and context-enabled extractability remains security-relevant.

CommentsAccepted at EMNLP 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑