Generative Model Memorization Detection Using Local Intrinsic Dimensionality
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deep generative models (DGMs) memorize training data, leading to legal and privacy risks, especially in public-facing or safety-critical applications, due to their ability to reproduce training data samples without generalizing effectively.
Innovation Solution
Evaluate the local intrinsic dimensionality of data samples using the generative model parameters to detect memorization, comparing it with a threshold to identify and prevent the reproduction of training data samples, and modify inputs to generate alternative samples.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If deep generative models are trained to generate realistic and diverse data samples, then the model's generative capability and output diversity are improved, but the model memorizes training data samples, leading to legal and privacy risks
Solution Approach 1:
The patent replaces traditional memorization detection methods (which would require direct comparison with training data) with a geometric/mathematical approach using local intrinsic dimensionality (LID) analysis. This substitution allows detection of memorization through mathematical properties of the model's output space without mechanical comparison to original training samples, thereby maintaining generative capability while reducing memorization risks.
Solution Approach 2:
The patent introduces local intrinsic dimensionality as an intermediary metric to detect memorization. Instead of directly comparing generated samples with training data, the LID serves as a mediator that quantifies the geometric properties of the model's learned manifold. When LID drops below a threshold, it indicates the model is reproducing training samples, enabling indirect detection of memorization while preserving output diversity.
2Reliability
If the model reproduces training data samples, then the model's ability to learn ground truth probability distribution is improved, but the model fails to generalize and may expose private personal information
Solution Approach 1:
The patent applies dynamics by making the dimensionality threshold adaptive rather than fixed. The threshold for detecting memorization is set based on the local intrinsic dimensionality of the ground truth data distribution. This dynamic approach allows the model to learn accurate probability distributions in high-dimensional regions while automatically detecting and preventing memorization in low-dimensional regions where generalization is critical.
3Measurement precision
If traditional methods are used to detect memorization by comparing generated samples with training data, then detection accuracy is improved, but device complexity and computational requirements increase
Solution Approach 1:
The patent extracts the essential geometric property (local intrinsic dimensionality) from the complex task of memorization detection. By taking out only the critical dimensional information from the high-dimensional data space and using it as a detection metric, the system achieves accurate memorization detection without requiring complex comparison mechanisms or storing training data, thereby reducing device complexity while maintaining detection precision.
Data Source
AI summary
Local intrinsic dimensionality (LID), when evaluated on a data sample for a generative model, can be used to detect model memorization by comparing the LID determined according to the model parameters with a threshold. This allows detection of memorization by the generative model that reproduces a training data sample as well as memorization that presents low degrees of freedom relative to a ground truth dimensionality of the data set. When data samples are generated by the generative model, the LID of the data samples is evaluated to detect memorization, and memorized data samples may be prevented from delivery as generated data samples. During training, training data samples are evaluated for memorization and may be used to modify the training process to reduce memorization.


