{"id":"W4385679821","doi":"10.1109/sp46215.2023.10179300","title":"Analyzing Leakage of Personally Identifiable Information in Language Models","year":2023,"lang":"en","type":"article","venue":"","topic":"Privacy-Preserving Technologies in Data","field":"Computer Science","cited_by":125,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Computer science; Information leakage; Leakage (economics); Natural language processing; Artificial intelligence; Internet privacy; Computer security","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.01327274,0.0009521224,0.001094424,0.001055621,0.001030547,0.002591577,0.001727556,0.002480387,0.001941535],"category_scores_gemma":[0.09125675,0.0009376375,0.001345391,0.001050057,0.003121343,0.00778914,0.005478391,0.004956142,0.0007707503],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.002143189,"about_ca_system_score_gemma":0.001777307,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001957582,"about_ca_topic_score_gemma":0.0018592,"domain_scores_codex":[0.9799674,0.01168893,0.0008708663,0.002159753,0.004189483,0.001123534],"domain_scores_gemma":[0.9219015,0.05346202,0.004250303,0.01754428,0.002124496,0.0007174593],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001736375,0.0005006638,0.03135623,0.0007273731,0.0006901594,0.001792536,0.00277707,0.6017701,0.01928011,0.1598269,0.01278114,0.1667613],"study_design_scores_gemma":[0.00004364679,0.0001251277,0.001329109,0.00005767122,0.00005202226,0.0003722407,0.0001305308,0.8991918,0.008907156,0.08777024,0.001975471,0.00004501198],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.2754697,0.001152224,0.7064011,0.005204171,0.0001415809,0.000243774,0.001499659,0.004512969,0.005374756],"genre_scores_gemma":[0.9525492,0.0002501183,0.0437614,0.0008029001,0.00006021739,0.0001031387,0.0007685171,0.0003017107,0.001402832],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.01327274,"threshold_uncertainty_score":0.07019377,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.02843659952724117,"score_gpt":0.2731366741085866,"score_spread":0.2447000745813454,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}