carlini-2021-exact-training-data-extraction-from-llm
IN premise — summaries/2026/08/24/wiki-Large_language_model-chunk-5-chunk-2.md
Created 2026-08-24T17:11:17+00:00
Carlini et al. (USENIX 2021) demonstrated both membership inference and exact extraction of training data from LLMs, establishing a concrete privacy attack vector on deployed language models
Summary
Researchers demonstrated that it is possible to pull exact original training data out of a deployed language model, not merely guess whether a particular passage was in the training set. This turns training-data privacy from a theoretical concern into a concrete, reproducible attack on any live LLM, meaning that serving a model is itself a data-leakage surface that must be actively defended.