User Inference Attacks on Large Language Models
Nikhil Kandpal, Krishna Pillutla, Alina Oprea, Peter Kairouz, Christopher A. Choquette-Choo, Zheng Xu
Abstract
Text written by humans makes up the vast majority of the data used to pre-train and finetune large language models (LLMs). Many sources of this data-like code, forum posts, personal websites, and books-are easily attributed to one or a few "users". In this paper, we ask if it is possible to infer if any of a user's data was used to train an LLM. Not only would this constitute a breach of privacy, but it would also enable users to detect when their data was used for training. We develop the first effective attacks for user inferenceat times, with near-perfect success-against LLMs. Our attacks are easy to employ, requiring only black-box access to an LLM and a few samples from the user, which need not be the ones that were trained on. We find, both theoretically and empirically, that certain properties make users more susceptible to user inference: being an outlier, having highly correlated examples, and contributing a larger fraction of data. Based on these findings, we identify several methods for mitigating user inference including training with example-level differential privacy, removing within-user duplicate examples, and reducing a user's contribution to the training data. Though these provide partial mitigation, our work highlights the need to develop methods to fully protect LLMs from user inference. Pre-trained LLM Finetuned LLM ๐ ! User-level finetuned data Training samples Samples known by attacker Query access Adversary Target User ๐ 2. For each ๐ฅ (#) compute ๐ ! (๐ฅ (#) ) 3. Test statistic 4. ๐ was in training if 4 ๐ ๐ฅ (%) , โฆ , ๐ฅ (&) > ๐ 1. Sample ๐ฅ (%) , โฆ , ๐ฅ & from ๐ท + User ๐ User ๐ด User ๐ต Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018. Privacy risk in machine learning: Analyzing the connection to overfitting. In IEEE Computer Security Foundations Symposium.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers16
- Exploring the limits of strong membership inference attacks on large language modelsJamie Hayes, Ilia Shumailov, Christopher A. Choquette-Choo, Matthew Jagielski et al.NeurIPS 2025 ยท 26 citations
- InvisibleInk: High-Utility and Low-Cost Text Generation with Differential PrivacyVishnu Vinod, Krishna Pillutla, Abhradeep Guha ThakurtaNeurIPS 2025 ยท 12 citations
- Membership Inference Attacks Against Fine-tuned Diffusion Language ModelsYuetian Chen, Kaiyuan Zhang, Yuntao Du, Edoardo Stoppa et al.ICLR 2026 ยท 6 citations
- Analyzing Inference Privacy Risks Through Gradients In Machine LearningZhuohang Li, Andrew Lowy, Jing Liu, Toshiaki Koike-Akino et al.CCS 2024 ยท 5 citations
- ArtistAuditor: Auditing Artist Style Pirate in Text-to-Image Generation ModelsLinkang Du, Zheng Zhu, Min Chen, Zhou Su et al.WWW 2025 ยท 5 citations
Builds on27
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 ยท 5,137 citations
- Adaptive Federated OptimizationSashank J. Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett et al.ICLR 2021 ยท 1,917 citations
- Few-Shot Parameter-Efficient Fine-Tuning is Better and Cheaper than In-Context LearningHaokun Liu, Derek Tam, Mohammed Muqeeth, Jay Mohta et al.NeurIPS 2022 ยท 1,483 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 ยท 1,049 citations
- Deduplicating Training Data Makes Language Models BetterKatherine Lee, Daphne Ippolito, Andrew Nystrom, Chiyuan Zhang et al.ACL 2022 ยท 844 citations
Related papers
- Beyond Memorization: Violating Privacy via Inference with Large Language ModelsRobin Staab, Mark Vero, Mislav Balunovic, Martin T. VechevICLR 2024 ยท 211 citations
- Did the Neurons Read your Book? Document-level Membership Inference for Large Language ModelsMatthieu Meeus, Shubham Jain, Marek Rei, Yves-Alexandre de MontjoyeUSENIX Security 2024 ยท 67 citations
- LLM Dataset Inference: Did you train on my dataset?Pratyush Maini, Hengrui Jia, Nicolas Papernot, Adam DziedzicNeurIPS 2024 ยท 162 citations
- Membership Inference Attacks on Tokenizers of Large Language ModelsMeng Tong, Yuntao Du, Kejiang Chen, Weiming Zhang et al.USENIX Security 2026
- Private Attribute Inference from Images with Vision-Language ModelsBatuhan Tรถmekรงe, Mark Vero, Robin Staab, Martin T. VechevNeurIPS 2024 ยท 54 citations
