Quantization Does Not Prevent Verbatim Data Extraction from Large Language Models
A new arXiv preprint finds that quantizing large language models (LLMs) does not effectively prevent the extraction of memorized training data. The study shows that, even at low-precision (4-bit) quantization, large models can still reproduce most memorized sequences, while their general language capabilities degrade more quickly. The authors argue that measuring verbatim extraction, rather than membership inference, is a more relevant metric for privacy risk in LLMs.
Why it matters: This result challenges the notion that quantization can serve as a practical privacy defense for LLMs, highlighting ongoing risks of training data leakage even in compressed models.
Full story at: arXiv Cryptography and Security ↗