TY - GEN
T1 - Many-Shot Regurgitation Prompting
AU - Sonkar, Shashank
AU - Liu, Naiming
AU - Baraniuk, Richard
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.
PY - 2025
Y1 - 2025
N2 - We introduce Many-Shot Regurgitation (MSR) prompting, a new black-box membership inference attack framework for examining verbatim content reproduction in large language models (LLMs). MSR prompting involves dividing the input text into multiple segments and creating a single prompt that includes a series of faux conversation rounds between a user and a language model to elicit verbatim regurgitation. We apply MSR prompting to diverse text sources, including open educational resources textbooks and Wikipedia articles, which provide high-quality, factual content and are continuously updated over time. For each source, we curate two dataset types: one that LLMs were likely exposed to during training (Dpre) and another consisting of documents published after the models’ training cutoff dates (Dpost). To quantify the occurrence of verbatim matches, we employ the Longest Common Substring algorithm and count the frequency of matches at different length thresholds. We then use statistical measures such as Cliff’s delta, Kolmogorov-Smirnov (KS) distance, and Kruskal-Wallis H test to determine whether the distribution of verbatim matches differs significantly between Dpre and Dpost. Our findings reveal a striking difference in the distribution of verbatim matches between Dpre and Dpost, with the frequency of verbatim reproduction being significantly higher when LLMs (e.g. GPT models and LLaMAs) are prompted with text from datasets they were likely trained on. Our results provide compelling evidence that LLMs are more prone to reproducing verbatim content when the input text is likely sourced from their training data. Code is available here.
AB - We introduce Many-Shot Regurgitation (MSR) prompting, a new black-box membership inference attack framework for examining verbatim content reproduction in large language models (LLMs). MSR prompting involves dividing the input text into multiple segments and creating a single prompt that includes a series of faux conversation rounds between a user and a language model to elicit verbatim regurgitation. We apply MSR prompting to diverse text sources, including open educational resources textbooks and Wikipedia articles, which provide high-quality, factual content and are continuously updated over time. For each source, we curate two dataset types: one that LLMs were likely exposed to during training (Dpre) and another consisting of documents published after the models’ training cutoff dates (Dpost). To quantify the occurrence of verbatim matches, we employ the Longest Common Substring algorithm and count the frequency of matches at different length thresholds. We then use statistical measures such as Cliff’s delta, Kolmogorov-Smirnov (KS) distance, and Kruskal-Wallis H test to determine whether the distribution of verbatim matches differs significantly between Dpre and Dpost. Our findings reveal a striking difference in the distribution of verbatim matches between Dpre and Dpost, with the frequency of verbatim reproduction being significantly higher when LLMs (e.g. GPT models and LLaMAs) are prompted with text from datasets they were likely trained on. Our results provide compelling evidence that LLMs are more prone to reproducing verbatim content when the input text is likely sourced from their training data. Code is available here.
KW - Large Language Models
KW - Membership Inference Attacks
UR - https://www.scopus.com/pages/publications/105012033945
UR - https://www.scopus.com/inward/citedby.url?scp=105012033945&partnerID=8YFLogxK
U2 - 10.1007/978-3-031-98462-4_26
DO - 10.1007/978-3-031-98462-4_26
M3 - Conference contribution
AN - SCOPUS:105012033945
SN - 9783031984617
T3 - Lecture Notes in Computer Science
SP - 203
EP - 211
BT - Artificial Intelligence in Education - 26th International Conference, AIED 2025, Proceedings
A2 - Cristea, Alexandra I.
A2 - Walker, Erin
A2 - Lu, Yu
A2 - Santos, Olga C.
A2 - Isotani, Seiji
PB - Springer Science and Business Media Deutschland GmbH
T2 - 26th International Conference on Artificial Intelligence in Education, AIED 2025
Y2 - 22 July 2025 through 26 July 2025
ER -