paper-with-me

홈 › Papers

An Invariant Latent Space Perspective on Language Model Inversion

2025-11-24 · Wentao Ye, Jiaqi Hu, Haobo Wang, Xinpeng Ti, Zhiqing Xiao, Hao Chen, Liyao Li, Lei Feng, Sai Wu, Junbo Zhao arxiv

Language model inversion (LMI), i.e., recovering hidden prompts from outputs, emerges as a concrete threat to user privacy and system security. We recast LMI as reusing the LLM's own latent space and propose the Invariant Latent Space Hypothesis (ILSH): (1) diverse outputs from the same source prompt should preserve consistent semantics (source invariance), and (2) input<->output cyclic mappings should be self-consistent within a shared latent space (cyclic invariance). Accordingly, we present Inv^2A, which treats the LLM as an invariant decoder and learns only a lightweight inverse encoder that maps outputs to a denoised pseudo-representation. When multiple outputs are available, they are sparsely concatenated at the representation layer to increase information density. Training proceeds in two stages: contrastive alignment (source invariance) and supervised reinforcement (cyclic invariance). An optional training-free neighborhood search can refine local performance. Across 9 datasets covering user and system prompt scenarios, Inv^2A outperforms baselines by an average of 4.77% BLEU score while reducing dependence on large inverse corpora. Our analysis further shows that prevalent defenses provide limited protection, underscoring the need for stronger strategies. The source code and data involved in this paper can be found in https://github.com/yyy01/Invariant_Attacker.

📄 PDF Abstract BibTeX arXiv:2511.19569

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

3D-Aware Encoding for Style-based Neural Radiance Fields

2022-11-12 · Yu-Jhe Li, Tao Xu, Bichen Wu, Ningyuan Zheng 외

We tackle the task of NeRF inversion for style-based neural radiance fields, (e.g., StyleNeRF). In the task, we aim to learn an inversion function to project an input image to the latent space of a NeRF generator and the…

Contrastive LearningImage ReconstructionNeRF

Invariant Features in Language Models: Geometric Characterization and Model Attribution

2026-05-07 · Agnibh Dasgupta, Abdullah Tanvir, Xin Zhong arxiv

Language models exhibit strong robustness to paraphrasing, suggesting that semantic information may be encoded through stable internal representations, yet the structure and origin of such invariance remain unclear. We p…

What Your Features Reveal: Data-Efficient Black-Box Feature Inversion Attack for Split DNNs

2025-11-19 · Zhihan Ren, Lijun He, Jiaxi Liang, Xinzhu Fu 외 arxiv

Split DNNs enable edge devices by offloading intensive computation to a cloud server, but this paradigm exposes privacy vulnerabilities, as the intermediate features can be exploited to reconstruct the private inputs via…

Image Reconstruction

Latent Diffusion Inversion Requires Understanding the Latent Space

2025-11-25 · Mingxing Rao, Bowen Qu, Daniel Moyer arxiv

The recovery of training data from generative models ("model inversion") has been extensively studied for diffusion models in the data domain as a memorization/overfitting phenomenon. Latent diffusion models (LDMs), whic…

On a Hidden Property in Computational Imaging

2024-10-11 · Yinan Feng, Yinpeng Chen, Yueh Lee, Youzuo Lin

Computational imaging plays a vital role in various scientific and medical applications, such as Full Waveform Inversion (FWI), Computed Tomography (CT), and Electromagnetic (EM) inversion. These methods address inverse …

Computed Tomography (CT)