arXiv:cs.AI· Ali Satvaty, Narjes Sharafi, Jirui Qi, Suzan Verberne, Fatih Turkmen·· 3 小时前
LLM 记忆是否受上下文影响?基于前缀的抽取超越孤立前缀
Is Memorization Context-Sensitive? Prefix-Based Extraction Beyond Isolated Prefixes
AI 导读
研究通过成对逐样本测量 LLM 的概率化后缀抽取发现,可抽取记忆由上下文鲁棒的核心与上下文敏感的边界组成。在三个开源指令微调模型上,检索上下文并未抹除记忆,前缀越长,无需上下文即可抽取的样本在检索上下文下仍多可抽取。上下文主要影响抽取阈值附近的边缘样本,既抑制部分暴露,也带来前缀单独评估遗漏的新暴露,说明 RAG 降低记忆风险的观点需被限定。
正文
Abstract:Large language models (LLMs) can expose memorized training sequences under prefix-based extraction: given a prefix from a training example, the model may assign high probability to the original continuation. In deployed systems, however, prefixes are rarely evaluated in isolation. They often appear together with instructions, retrieved documents, or other task-specific context, as in retrieval-augmented generation (RAG). This motivates examining whether contextual conditioning mitigates memorization or merely changes the set of memorized samples that become extractable. We investigate this issue through paired item-level measurements of probabilistic suffix extraction. For each prefix-suffix pair, we score the target suffix under an empty prompt and under retrieved contexts of varying relevance, across three open-weight instruction-tuned models. We find that context does not simply erase memorization. Instead, extractable memorization consists of a context-robust core and a context-sensitive boundary. Many samples that are extractable without context remain extractable under the retrieved context, especially as the prefix length increases. At the same time, context mainly affects marginal samples near the extraction threshold: it suppresses some exposures, but also enables new ones that are missed by prefix-only evaluation. These findings qualify the view that RAG reduces memorization risk. Context can lower aggregate extraction by suppressing boundary cases, yet robustly extractable samples persist, and context-enabled extractability remains security-relevant.
| Comments: | Accepted at EMNLP 2026 |
| Subjects: | Artificial Intelligence (cs.AI) |
| Cite as: | arXiv:2610.12085 [cs.AI] |
| (or arXiv:2610.12085v1 [cs.AI] for this version) | |
| https://doi.org/10.48550/arXiv.2610.12085 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Ali Satvaty [view email]
[v1]
Thu, 8 Oct 2026 14:57:33 UTC (611 KB)
来源:arXiv:cs.AI · arxiv.org