Auditing Data Provenance in Text-Generation Models

Congzheng Song, Vitaly Shmatikov

2019 · 180 citations · 31 references

DOIFull text

Open access

Concepts

TL;DR

Text‑generation models are central to popular online services and are often trained on personal data such as users’ messages, searches, chats, and comments. The authors develop a black‑box auditing technique to detect whether a user’s personal texts were used to train a deep‑learning text‑generation model, thereby supporting GDPR compliance. They audit deep‑learning models that generate natural language by issuing few queries to a black‑box and analyze memorization of word sequences to explain auditability. The method successfully audits well‑generalized models that are not overfitted, and the memorization analysis shows why such models are amenable to auditing.

Abstract

To help enforce data-protection regulations such as GDPR and detect unauthorized uses of personal data, we develop a new model auditing technique that helps users check if their data was used to train a machine learning model. We focus on auditing deep-learning models that generate natural-language text, including word prediction and dialog generation. These models are at the core of popular online services and are often trained on personal data such as users' messages, searches, chats, and comments. We design and evaluate a black-box auditing method that can detect, with very few queries to a model, if a particular user's texts were used to train it (among thousands of other users). We empirically show that our method can successfully audit well-generalized models that are not overfitted to the training data. We also analyze how text-generation models memorize word sequences and explain why this memorization makes them amenable to auditing.

References

31