{"id":"https://openalex.org/W4403345391","doi":"https://doi.org/10.48550/arxiv.2410.06704","title":"PII-Scope: A Comprehensive Study on Training Data PII Extraction Attacks in LLMs","display_name":"PII-Scope: A Comprehensive Study on Training Data PII Extraction Attacks in LLMs","publication_year":2024,"publication_date":"2024-10-09","ids":{"openalex":"https://openalex.org/W4403345391","doi":"https://doi.org/10.48550/arxiv.2410.06704"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2410.06704","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.06704","pdf_url":"https://arxiv.org/pdf/2410.06704","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2410.06704","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5008425976","display_name":"Krishna Kanth Nakka","orcid":"https://orcid.org/0000-0002-2381-6593"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Nakka, Krishna Kanth","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049059309","display_name":"Ahmed Frikha","orcid":"https://orcid.org/0000-0001-9772-853X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Frikha, Ahmed","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035107329","display_name":"Ricardo Mendes","orcid":"https://orcid.org/0000-0002-9259-4576"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mendes, Ricardo","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100763211","display_name":"Xue Jiang","orcid":"https://orcid.org/0000-0002-1422-9258"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jiang, Xue","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5102141512","display_name":"Xuebing Zhou","orcid":"https://orcid.org/0000-0001-6883-3453"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhou, Xuebing","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5008425976"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11719","display_name":"Data Quality and Management","score":0.958299994468689,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T11719","display_name":"Data Quality and Management","score":0.958299994468689,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9297000169754028,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9225999712944031,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/scope","display_name":"Scope (computer science)","score":0.7344576120376587},{"id":"https://openalex.org/keywords/leakage","display_name":"Leakage (economics)","score":0.6540223360061646},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5951306819915771},{"id":"https://openalex.org/keywords/training","display_name":"Training (meteorology)","score":0.5823820233345032},{"id":"https://openalex.org/keywords/risk-assessment","display_name":"Risk assessment","score":0.44304215908050537},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.43363478779792786},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.37616580724716187},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.37137484550476074},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.20639213919639587},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.18471866846084595},{"id":"https://openalex.org/keywords/economics","display_name":"Economics","score":0.181831955909729},{"id":"https://openalex.org/keywords/geography","display_name":"Geography","score":0.0869256854057312}],"concepts":[{"id":"https://openalex.org/C2778012447","wikidata":"https://www.wikidata.org/wiki/Q1034415","display_name":"Scope (computer science)","level":2,"score":0.7344576120376587},{"id":"https://openalex.org/C2777042071","wikidata":"https://www.wikidata.org/wiki/Q6509304","display_name":"Leakage (economics)","level":2,"score":0.6540223360061646},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5951306819915771},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.5823820233345032},{"id":"https://openalex.org/C12174686","wikidata":"https://www.wikidata.org/wiki/Q1058438","display_name":"Risk assessment","level":2,"score":0.44304215908050537},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.43363478779792786},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.37616580724716187},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.37137484550476074},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.20639213919639587},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.18471866846084595},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.181831955909729},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0869256854057312},{"id":"https://openalex.org/C139719470","wikidata":"https://www.wikidata.org/wiki/Q39680","display_name":"Macroeconomics","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C153294291","wikidata":"https://www.wikidata.org/wiki/Q25261","display_name":"Meteorology","level":1,"score":0.0},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2410.06704","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.06704","pdf_url":"https://arxiv.org/pdf/2410.06704","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2410.06704","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2410.06704","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2410.06704","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.06704","pdf_url":"https://arxiv.org/pdf/2410.06704","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4403345391.pdf"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W2378211422","https://openalex.org/W4241523039","https://openalex.org/W2360028903","https://openalex.org/W4280543773","https://openalex.org/W178231042","https://openalex.org/W4321353415","https://openalex.org/W2745001401","https://openalex.org/W2366083136","https://openalex.org/W2387622493","https://openalex.org/W2130974462"],"abstract_inverted_index":{"In":[0,94],"this":[1,46],"work,":[2],"we":[3,48,96,123],"introduce":[4],"PII-Scope,":[5],"a":[6,27,84,104,145,159],"comprehensive":[7],"benchmark":[8,148],"designed":[9],"to":[10,41,52,115,136],"evaluate":[11,124],"state-of-the-art":[12],"methodologies":[13],"for":[14,74,149,162],"PII":[15,58,76,88,108,125,150],"extraction":[16,109,151],"attacks":[17,32,59,152],"targeting":[18,118],"LLMs":[19],"across":[20],"diverse":[21,68],"threat":[22,155],"settings.":[23],"Our":[24],"study":[25,51],"provides":[26,158],"deeper":[28],"understanding":[29],"of":[30,87],"these":[31],"by":[33,113],"uncovering":[34],"several":[35],"hyperparameters":[36],"(e.g.,":[37],"demonstration":[38],"selection)":[39],"crucial":[40],"their":[42],"effectiveness.":[43],"Building":[44],"on":[45,127],"understanding,":[47],"extend":[49],"our":[50,81,142],"more":[53,134],"realistic":[54,154],"attack":[55],"scenarios,":[56],"exploring":[57],"that":[60,98,131],"employ":[61],"advanced":[62],"adversarial":[63,101],"strategies,":[64],"including":[65],"repeated":[66],"and":[67,70,103,157],"querying,":[69],"leveraging":[71],"iterative":[72],"learning":[73],"continual":[75],"extraction.":[77],"Through":[78],"extensive":[79],"experimentation,":[80],"results":[82],"reveal":[83],"notable":[85],"underestimation":[86],"leakage":[89,126,137],"in":[90,153],"existing":[91],"single-query":[92],"attacks.":[93],"fact,":[95],"show":[97],"with":[99],"sophisticated":[100],"capabilities":[102],"limited":[105],"query":[106],"budget,":[107],"rates":[110],"can":[111],"increase":[112],"up":[114],"fivefold":[116],"when":[117],"the":[119],"pretrained":[120,139],"model.":[121],"Moreover,":[122],"finetuned":[128],"models,":[129],"showing":[130],"they":[132],"are":[133],"vulnerable":[135],"than":[138],"models.":[140],"Overall,":[141],"work":[143],"establishes":[144],"rigorous":[146],"empirical":[147],"scenarios":[156],"strong":[160],"foundation":[161],"developing":[163],"effective":[164],"mitigation":[165],"strategies.":[166]},"counts_by_year":[],"updated_date":"2026-03-11T14:59:36.786465","created_date":"2024-10-12T00:00:00"}
