Ziyi Tong, Feifei Sun, Nguyen Minh Le
This is the first survey paper that integrates and analyzes the pretraining data exposure problem in LLMs from two domains: data contamination and membership inference.
LLMs' pretraining data is vast and opaque, making it difficult to determine whether specific data was used in training. This leads to overestimation of performance due to evaluation data contamination and risks of privacy leakage.
We systematize Pretraining Data Exposure (PDE) by exposure levels and comprehensively review membership inference attacks and defenses, as well as data contamination detection techniques. Empirical findings are synthesized, and open challenges and future research directions are presented.
We provide a unified framework for PDE, revealing connections between the two research areas and laying the foundation for future work. Additionally, we offer practical insights for evaluation integrity and privacy protection.