Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models
Jianhong Li, Jiahao Chen, Yuwen Pu, Chunyi Zhou, Oubo Ma, Zhou Feng, Hangtao Zhang, Jichao Bi, Chunqiang Hu
Abstract
Beyond adapting Large Language Models (LLMs) to specialized applications, fine-tuning has recently been shown to recover private information that is no longer accessible through direct queries. Previous fine-tuning recovery attacks, however, require genuine private supervision drawn from the same distribution, i.e., the previous training dataset. We argue that such recovery remains possible without such impractical knowledge. We show that LLM-generated candidates can provide sufficient supervision to recover previously learned private associations. Based on this, we propose ReGap, a data-free attack that recovers private associations using task structure, filters them by answer-token likelihood, and updates the target model via low-rank adaptation. Specifically, ReGap requires neither target answers nor auxiliary genuine private supervision. Across six GPT-2, OPT, and Qwen3 models, ReGap improves target-association recovery by 6-21 percentage points over the post-training target model. Recovery remains substantial even when the adaptation identities are disjoint from all memorized and evaluation identities, with no exact target answers appearing in the generated or selected supervision. Moreover, the same trained adapters increase recovery from 42\% to 63\% on a previously exposed checkpoint, but produce no gain on a matched checkpoint that never encountered the targets. This contrast shows that adaptation alone is insufficient to explain the observed recovery and that prior target exposure strongly affects post-adaptation recoverability. Our findings highlight that routine model customization can reawaken latent privacy risks, warranting urgent attention from the academic and industrial communities.
Create a lesson
Related papers
System-Level Optimization Beyond Cryptographic Kernels: An ML-KEM Case Study on Arm Cortex-M7
Mahmoud Abdelhafeez Sayed, Mostafa Taha, Gurp Nijjer
A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders
Emmanuela Andam, Yasir Abbas Zaidi, Abdelali Hadir et al.
Detection and Resolution of Periodic Artifacts in OpenDP's Discrete Laplace Sampler
Cesare Gerolimetto Fabrello, Valeria Rossi, Alberto Trombetta et al.
A Structured State Space Sequence Model for Multi-Class Classification of Malware
Emmanuela Andam, Rana Shaaban, Emanuel Grant et al.
From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures
Yahya Shahsavari, Sara Rouhani, Kaiwen Zhang
Walking the Embedding Space: Datastore Extraction from Multimodal RAG
Maria Carmen Jica, Ali Satvaty, Suzan Verberne et al.