{"id":"https://openalex.org/W4412945170","doi":"https://doi.org/10.18653/v1/2025.acl-long.1185","title":"ALGEN: Few-shot Inversion Attacks on Textual Embeddings via Cross-Model Alignment and Generation","display_name":"ALGEN: Few-shot Inversion Attacks on Textual Embeddings via Cross-Model Alignment and Generation","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4412945170","doi":"https://doi.org/10.18653/v1/2025.acl-long.1185"},"language":"en","primary_location":{"id":"doi:10.18653/v1/2025.acl-long.1185","is_oa":false,"landing_page_url":"https://doi.org/10.18653/v1/2025.acl-long.1185","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://vbn.aau.dk/ws/files/815962990/2025.acl-long.1185.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5045638055","display_name":"Yiyi Chen","orcid":"https://orcid.org/0000-0001-9977-8960"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yiyi Chen","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036737229","display_name":"Qiongkai Xu","orcid":"https://orcid.org/0000-0003-3312-6825"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qiongkai Xu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5013472329","display_name":"Johannes Bjerva","orcid":"https://orcid.org/0000-0002-9512-0739"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Johannes Bjerva","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.6508,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.87312111,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"24330","last_page":"24348"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.9781000018119812,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.9781000018119812,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9312999844551086,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6284632682800293},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.5860308408737183},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.48759642243385315},{"id":"https://openalex.org/keywords/shot","display_name":"Shot (pellet)","score":0.46860015392303467},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.3351460099220276},{"id":"https://openalex.org/keywords/geology","display_name":"Geology","score":0.11090171337127686}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6284632682800293},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.5860308408737183},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.48759642243385315},{"id":"https://openalex.org/C2778344882","wikidata":"https://www.wikidata.org/wiki/Q278938","display_name":"Shot (pellet)","level":2,"score":0.46860015392303467},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3351460099220276},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.11090171337127686},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0},{"id":"https://openalex.org/C178790620","wikidata":"https://www.wikidata.org/wiki/Q11351","display_name":"Organic chemistry","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.18653/v1/2025.acl-long.1185","is_oa":false,"landing_page_url":"https://doi.org/10.18653/v1/2025.acl-long.1185","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)","raw_type":"proceedings-article"},{"id":"pmh:oai:pure.atira.dk:publications/b3114a9a-5e43-48e2-9cf0-341ce9e8288e","is_oa":true,"landing_page_url":"https://vbn.aau.dk/da/publications/b3114a9a-5e43-48e2-9cf0-341ce9e8288e","pdf_url":"https://vbn.aau.dk/ws/files/815962990/2025.acl-long.1185.pdf","source":{"id":"https://openalex.org/S4306401731","display_name":"VBN Forskningsportal (Aalborg Universitet)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I891191580","host_organization_name":"Aalborg University","host_organization_lineage":["https://openalex.org/I891191580"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Chen, Y, Xu, Q & Bjerva, J 2025, ALGEN : Few-shot Inversion Attacks on Textual Embeddings via Cross-Model Alignment and Generation. in W Che, J Nabende, E Shutova & M T Pilehvar (eds), Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). Association for Computational Linguistics (ACL), Proceedings of the Annual Meeting of the Association for Computational Linguistics, vol. 1, pp. 24330-24348, 63rd Annual Meeting of the Association for Computational Linguistics, ACL 2025, Vienna, Austria, 27/07/2025. https://doi.org/10.18653/v1/2025.acl-long.1185","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"pmh:oai:pure.atira.dk:publications/b3114a9a-5e43-48e2-9cf0-341ce9e8288e","is_oa":true,"landing_page_url":"https://vbn.aau.dk/da/publications/b3114a9a-5e43-48e2-9cf0-341ce9e8288e","pdf_url":"https://vbn.aau.dk/ws/files/815962990/2025.acl-long.1185.pdf","source":{"id":"https://openalex.org/S4306401731","display_name":"VBN Forskningsportal (Aalborg Universitet)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I891191580","host_organization_name":"Aalborg University","host_organization_lineage":["https://openalex.org/I891191580"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Chen, Y, Xu, Q & Bjerva, J 2025, ALGEN : Few-shot Inversion Attacks on Textual Embeddings via Cross-Model Alignment and Generation. in W Che, J Nabende, E Shutova & M T Pilehvar (eds), Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). Association for Computational Linguistics (ACL), Proceedings of the Annual Meeting of the Association for Computational Linguistics, vol. 1, pp. 24330-24348, 63rd Annual Meeting of the Association for Computational Linguistics, ACL 2025, Vienna, Austria, 27/07/2025. https://doi.org/10.18653/v1/2025.acl-long.1185","raw_type":"info:eu-repo/semantics/publishedVersion"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320320591","display_name":"Macquarie University","ror":"https://ror.org/01sf06y89"},{"id":"https://openalex.org/F4320322975","display_name":"Danish e-Infrastructure Cooperation","ror":"https://ror.org/03ge1nb22"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4412945170.pdf","grobid_xml":"https://content.openalex.org/works/W4412945170.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2074502265","https://openalex.org/W4214877189","https://openalex.org/W2773965352","https://openalex.org/W2381179799","https://openalex.org/W4411535265","https://openalex.org/W2980279061","https://openalex.org/W3204019825"],"abstract_inverted_index":{"With":[0,68,83],"the":[1,124,168,177],"growing":[2],"popularity":[3],"of":[4,53,97,156,179],"Large":[5],"Language":[6],"Models":[7],"(LLMs)":[8],"and":[9,18,116,127,146,161,181],"vector":[10],"databases,":[11],"private":[12],"textual":[13,196],"data":[14,61,73,88],"is":[15,39,75],"increasingly":[16],"processed":[17],"stored":[19],"as":[20,84,86],"numerical":[21],"embeddings.":[22],"However,":[23],"recent":[24],"studies":[25],"have":[26],"proven":[27],"that":[28,137,163,183],"such":[29],"embeddings":[30,122],"are":[31,165],"vulnerable":[32],"to":[33,41,51,55,123,132],"inversion":[34,81,172,180,198],"attacks,":[35],"where":[36],"original":[37],"text":[38],"reconstructed":[40],"reveal":[42],"sensitive":[43],"information.":[44,150],"Previous":[45],"research":[46],"has":[47],"largely":[48],"assumed":[49],"access":[50],"millions":[52],"sentences":[54],"train":[56],"attack":[57,125],"models,":[58],"e.g.,":[59],"through":[60,189],"leakage":[62],"or":[63],"nearly":[64],"unrestricted":[65],"API":[66],"access.":[67],"our":[69],"method,":[70],"a":[71,78,95,107,129,154,194],"single":[72],"point":[74],"sufficient":[76],"for":[77,203],"partially":[79],"successful":[80],"attack.":[82],"little":[85],"1k":[87],"samples,":[89],"performance":[90],"reaches":[91],"an":[92],"optimum":[93],"across":[94,144],"range":[96],"black-box":[98],"encoders,":[99],"without":[100],"training":[101],"on":[102],"leaked":[103],"data.":[104],"We":[105,135,151],"present":[106],"Few-shot":[108],"Textual":[109],"Embedding":[110],"Inversion":[111],"Attack":[112],"using":[113,128],"Cross-Model":[114],"ALignment":[115],"GENeration":[117],"(ALGEN),":[118],"by":[119,171],"aligning":[120],"victim":[121],"space":[126],"generative":[130],"model":[131],"reconstruct":[133],"text.":[134],"find":[136,162],"ALGEN":[138],"attacks":[139],"can":[140,186],"be":[141,187],"effectively":[142],"transferred":[143],"domains":[145],"languages,":[147],"revealing":[148],"key":[149],"further":[152],"examine":[153],"variety":[155],"defense":[157],"mechanisms":[158],"against":[159],"ALGEN,":[160],"none":[164],"effective,":[166],"highlighting":[167],"vulnerabilities":[169],"posed":[170],"attacks.":[173],"By":[174],"significantly":[175],"lowering":[176],"cost":[178],"proving":[182],"embedding":[184,197,204],"spaces":[185],"aligned":[188],"one-step":[190],"optimization,":[191],"we":[192],"establish":[193],"new":[195],"paradigm":[199],"with":[200],"broader":[201],"applications":[202],"alignment":[205],"in":[206],"NLP.":[207]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-06-26T08:34:08.712188","created_date":"2025-10-10T00:00:00"}
