Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Loss Landscape Poisoning: Targeted Extraction of Unseen Training Data from LLMs

About

Large Language Models are increasingly trained on proprietary or sensitive data, from private healthcare and financial records to user conversations containing secrets. Ensuring the privacy of such data against extraction attacks has become a central concern. In this paper, we ask whether an attacker who can poison a portion of the training data can facilitate the leakage of a separate target record they have no access to. We answer in the affirmative and show that such leakage can be induced by a poisoning mechanism that reshapes the model's local loss landscape around the target completion. Our key insight is that poisoning to create a sharp loss minimum at the target, surrounded by elevated loss on nearby alternatives, forces the model to memorize the target as the unique low-loss solution in its neighborhood. The attack requires no architectural changes, and generalizes across centralized and federated learning settings. We demonstrate that the attack amplifies privacy leakage across language (up to 100% successful extraction), and vision-language models (up 90% successful extraction). We show that the attack is thwarted when the model is trained to be differentially private. However, we introduce a new attack that directly probes the loss landscape bypassing even differential privacy defenses.

Md Abdullah Al Mamun, Ngoc Phu Doan, Pedram Zaree, Nael Abu-Ghazaleh, Ihsen Alouani• 2026

Related benchmarks

TaskDatasetResultRank
Secret Data Extraction100 Targeted Secrets OKVQA DocVQA VQAv2
P(s|x) > 0.10 Rate100
18
Secret data extraction attackFedLLM 100 target secrets
Success Rate (P > .10)100
18
Secret Data Extraction100 different secrets
Success Rate (P > 0.10)100
12
Privacy AttackGPT-2 Small (124M)
Validation CE Loss0.71
12
Showing 4 of 4 rows

Other info

Follow for update