Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Text Embedding Inversion Attacks on Multilingual Language Models

  • Schematic Overview of a Text Embedding Inversion Attack.

attack

Multilingual Vec2Text supports research in Text Embedding Inversion Security in Language Models, extending Jack Morris' Vec2Text with Ad-hoc Translation and Masking Defense Mechanism. We investigate thoroughly multilingual and cross-lingual text inversion attacks, and defense mechanisms. This repository contains code for the ACL 2024 long paper Text Embedding Inversion Attacks on Multilingual Language Models . The poster is online.

All the trained inversion models are on Huggingface. All the models are trained with T5-base as the external encoder-decoder.

Black-box EncoderTraining DataBase ModelCorrector Model
GTR-base5M Natural Questionsyiyic/t5_gtr_base_nq_32_inverteryiyic/t5_gtr_base_nq_32_corrector
ME5-base5M Natural Questionsyiyic/t5_me5_base_nq_32_inverteryiyic/t5_me5_base_nq_32_corrector
ME5-base5M MTG Spanishyiyic/t5_me5_base_mtg_es_5m_32_inverteryiyic/t5_me5_base_mtg_es_5m_32_corrector
ME5-base5M MTG Frenchyiyic/t5_me5_base_mtg_fr_5m_32_inverteryiyic/t5_me5_base_mtg_fr_5m_32_corrector
ME5-base5M MTG Germanyiyic/t5_me5_base_mtg_de_5m_32_inverteryiyic/t5_me5_base_mtg_de_5m_32_corrector
ME5-base5M MTG Englishyiyic/t5_me5_base_mtg_en_5m_32_inverteryiyic/t5_me5_base_mtg_en_5m_32_corrector
ME5-base5M MTG Multilingualyiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_inverteryiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector
  • Overview of Multilingual Vec2Text.

The tutorials for setting up experiments on supercomputer nodes such as LUMI will be in Wiki pages. All the scripts for running experiments will be provided in the GitHub repository. GitHub is still under construction.

Experiments (Inversion attack simulations)

Setup

  1. download the release from releases and unzip.
  2. pip install -r requirements.txt
  3. donwload punkt package from nltk
import nltk
nltk.download("punkt")

Text Embedding Examples

Usage in interactive environment in a server


from eval_samples import * model_path="yiyic/t5_me5_base_mtg_en_fr_de_es_5m_32_corrector"
samples = ["jack morris is a phd student at cornell tech in new york city",
"it was the best of times, it was the worst of times, it was the age of wisdom",
"in einer stunde erreichen wir kopenhagen."., "comment puis-je vous aider?"
]
experiment, trainer = analyze_utils.load_experiment_and_trainer_from_pretrained(
model_path, use_less_data=3000)
trainer, device = trainer_attributes(trainer, experiment)
trainer.num_gen_recursive_steps = 10
# set sbeam
# trainer.sequence_beam_width = xx
evaluate_samples(trainer, device, samples)

output:


[pred] jack morris is a phd student at cornell tech in new york city
[true] jack morris is a phd student at cornell tech in new york city
[pred] it was the best of times, it was the worst of times, it was the age of wisdom
[true] it was the best of times, it was the worst of times, it was the age of wisdom
[pred] in einer stunde erreichen wir kopenhagen.
[true] in einer stunde erreichen wir kopenhagen.
[pred] comment puis-je vous aider?
[true] comment puis-je vous aider?

Ad-Hoc Translation (AdTrans)

The codes for AdTrans evaluation is in adTrans.

  • translate the $\hat{x}$ from training language to target language and evaluate.
python adTrans/translate_test_results.py $results_output_directory$
python adTrans/eval.py $results_output_directory$ python adTrans/eval_sum_up.py $results_output_directory$

Inversion Models Limitations

  • To analyze the impact of multilingual parallel data training, we used MTG benchmark in English, French, German, and Spanish, the texts in the datasets were given as lower-cased, so our trained inversion ME5-based models work mostly for lower-cased texts as well. Along with dataset limitation, the best performing models invert sentences within the length of 32 tokens. We will address these limitation for future work.

Cite our Paper

@inproceedings{chen-etal-2024-text,
title = "Text Embedding Inversion Security for Multilingual Language Models",
author = "Chen, Yiyi and
Lent, Heather and
Bjerva, Johannes",
editor = "Ku, Lun-Wei and
Martins, Andre and
Srikumar, Vivek",
booktitle = "Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)",
month = aug,
year = "2024",
address = "Bangkok, Thailand",
publisher = "Association for Computational Linguistics",
url = "https://aclanthology.org/2024.acl-long.422",
pages = "7808--7827",
abstract = "Textual data is often represented as real-numbered embeddings in NLP, particularly with the popularity of large language models (LLMs) and Embeddings as a Service (EaaS). However, storing sensitive information as embeddings can be susceptible to security breaches, as research shows that text can be reconstructed from embeddings, even without knowledge of the underlying model. While defence mechanisms have been explored, these are exclusively focused on English, leaving other languages potentially exposed to attacks. This work explores LLM security through multilingual embedding inversion. We define the problem of black-box multilingual and crosslingual inversion attacks, and explore their potential implications. Our findings suggest that multilingual LLMs may be more vulnerable to inversion attacks, in part because English-based defences may be ineffective. To alleviate this, we propose a simple masking defense effective for both monolingual and multilingual models. This study is the first to investigate multilingual inversion attacks, shedding light on the differences in attacks and defenses across monolingual and multilingual settings.",
}

About

Multilingual Vec2Text + Ad-hoc Translation + Masking Defense Mechanism

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages