Demystifying Verbatim Memorization in Large Language Models
Jing Huang, Diyi Yang, Christopher Potts
摘要
Large Language Models (LLMs) frequently memorize long sequences verbatim, often with serious legal and privacy implications.Much prior work has studied such verbatim memorization using observational data.To complement such work, we develop a framework to study verbatim memorization in a controlled setting by continuing pre-training from Pythia checkpoints with injected sequences.We find that (1) non-trivial amounts of repetition are necessary for verbatim memorization to happen; (2) later (and presumably better) checkpoints are more likely to verbatim memorize sequences, even for out-of-distribution sequences; (3) the generation of memorized sequences is triggered by distributed model states that encode high-level features and makes important use of general language modeling capabilities.Guided by these insights, we develop stress tests to evaluate unlearning methods and find they often fail to remove the verbatim memorized information, while also degrading the LM.Overall, these findings challenge the hypothesis that verbatim memorization stems from specific model weights or mechanisms.Rather, verbatim memorization is intertwined with the LM's general capabilities and thus will be very difficult to isolate and suppress without degrading model quality.* Equal advising.M i M (X) M () Pre-training s steps with injected sequences X Causal Interventions Pre-training s steps Model at pre-training step iThe Original Trigger Prefix Mr and Mrs Dursley, of number four, Privet Drive, were proud to say that they were perfectly normal, thank you very much Trigger Prefixes with Similar High-level FeaturesMrs and Mr Dursley, of number four, Privet Drive, were proud to say that they were perfectly normal, thank you very much The Dursley family, of number four, Privet Drive, were proud to say that they were perfectly normal, thank you very much Mr and Mrs Weasley, residing at four Privet Drive, were proud to say they were perfectly normal, thank you very much Mr and Mrs Slytherin, of number twenty-one, Privet Drive, were proud to say that they were perfectly normal, thank you very much Mr and Mrs Dursley, of #4, Privet Drive, were proud to say that they were perfectly normal, thank you very much Mr and Mrs Dursley, of number ten, Privet Drive, were proud to say that they were perfectly normal, thank you very much Mr and Mrs Dursley, of Privet Drive, were proud to say that they were perfectly normal, thank you very much Mr and Mrs Dursley, of number four, Oak Street, were proud to say that they were perfectly normal, thank you very much Mr and Mrs Dursley, residing at four Privet Drive, were delighted to assert they were perfectly normal, thank you very much The Dursley family, of number four, Privet Drive, were pleased to declare that they were perfectly normal, thank you very much Non-Trigger Prefixes with Similar or Different High-level FeaturesMr and Mrs Kingsley, of number four, Privet Drive, were proud to say that they were the proud parents of a bouncing baby boy.Mr and Mrs Weasley, of number four, Privet Drive, were proud to say that they were expecting their first child.Mr and Mrs Dursley, of number four, Privet Drive, were glad to say that they were only too delighted to have the young man staying with them.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper23
- Hubble: a Model Suite to Advance the Study of LLM MemorizationJohnny Wei, Ameya Godbole, Mohammad Aflah Khan, Ryan Yixiang Wang 等ICLR 2026 · 被引用 22 次
- Data Mixing Can Induce Phase Transitions in Knowledge AcquisitionXinran Gu, Kaifeng Lyu, Jiazheng Li, Jingzhao ZhangNeurIPS 2025 · 被引用 16 次
- Blackbox Model Provenance via Palimpsestic Membership InferenceRohith Kuditipudi, Jing Huang, Sally Zhu, Diyi Yang 等NeurIPS 2025 · 被引用 12 次
- Extracting alignment data in open modelsFederico Barbero, Xiangming Gu, Christopher A. Choquette Choo, Chawin Sitawarin 等ICML 2026 · 被引用 9 次
- Empty Shelves or Lost Keys? Recall Is the Bottleneck for Parametric FactualityNitay Calderon, Eyal Ben-David, Zorik Gekhman, Eran Ofek 等ICML 2026 · 被引用 8 次
它引用的顶会 Paper25
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Locating and Editing Factual Associations in GPTKevin Meng, David Bau, Alex Andonian, Yonatan BelinkovNeurIPS 2022 · 被引用 3,415 次
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos 等USENIX Security 2019 · 被引用 1,386 次
- Investigating Gender Bias in Language Models Using Causal Mediation AnalysisJesse Vig, Sebastian Gehrmann, Yonatan Belinkov, Sharon Qian 等NeurIPS 2020 · 被引用 851 次
- What Neural Networks Memorize and Why: Discovering the Long Tail via Influence EstimationVitaly Feldman, Chiyuan ZhangNeurIPS 2020 · 被引用 674 次
相关 Paper
- Quantifying Memorization Across Neural Language ModelsNicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee 等ICLR 2023 · 被引用 158 次
- Positional Fragility in LLMs: How Offset Effects Reshape Our Understanding of Memorization RisksYixuan Even Xu, Antoine Bosselut, Imanol SchlagNeurIPS 2025 · 被引用 2 次
- Emergent and Predictable Memorization in Large Language ModelsStella Biderman, USVSN Sai Prashanth, Lintang Sutawika, Hailey Schoelkopf 等NeurIPS 2023 · 被引用 205 次
- Memorization Sinks: Isolating Memorization during LLM TrainingGaurav Rohit Ghosal, Pratyush Maini, Aditi RaghunathanICML 2025
- Knowledge Unlearning for Mitigating Privacy Risks in Language ModelsJoel Jang, Dongkeun Yoon, Sohee Yang, Sungmin Cha 等ACL 2023 · 被引用 48 次
