Tesi etd-07022026-173624 |
Link copiato negli appunti
Tipo di tesi
Tesi di laurea magistrale
URN
etd-07022026-173624
Titolo
Personal Data Beyond Training: Large Language Models and the Right to be Forgotten
Dipartimento
INGEGNERIA DELL'INFORMAZIONE
Corso di studi
CYBERSECURITY
Relatori
.
relatore Prof.ssa Casarosa, Federica
supervisore Prof. Marcelloni, Francesco
supervisore Prof. Marcelloni, Francesco
Parole chiave
- Artificial Intelligence (AI)
- Data Protection
- General Data Protection Regulation (GDPR)
- Large Language Models
Data inizio appello
22/07/2026
Consultabilità
Non consultabile
Data di rilascio
22/07/2029
Riassunto (Inglese)
Large Language Models have seen a dramatic evolution in the last years, allowing for an unprecedented technological advancement in several application fields. Some of them, such as healthcare, legal service, and customer support involve the processing of personal data. As Generative AI becomes more widespread, it is important to ensure that personal data processing for model training is carried out in compliance with data protection principles. In the European Union the General Data Protection Regulation (GDPR) defines the foundations of lawful personal data processing, including the right of personal data erasure under the Right to be Forgotten. While it can be relatively straightforward to achieve data erasure in traditional information systems, machine learning models encode training data through distributed statistical representations, making the influence of individual samples difficult to identify, remove, and verify.
This thesis investigates the degree of training data influence that persists on trained model after fine-tuning, and analyzes possible solutions to prevent or remove such influence. Membership Inference Attacks are deployed to assess whether a fine-tuned model exhibits a distinguishable behavior when interacting on training samples, measuring membership leakage as an empirical signal of training data influence.
To address compliance with the Right to be Forgotten, two possible technical approaches are considered: first, machine unlearning through Negative Preference Optimization is analyzed as a reactive solution to remove personal data influence after fine-tuning; second, differentially private fine-tuning is deployed as a proactive mechanism to prevent strong data influence in the first place. Experiments are conducted on the Llama 3.2 3B model using different datasets, and a suite of Membership Inference Attacks are employed to evaluate privacy leakage while considering the resulting impact on model utility.
The results achieved provide empirical evidence that training samples leave a lasting influence on a trained model, and that both Negative Preference Optimization and differentially private fine-tuning achieve considerable reduction of training data influence, although at the cost of model utility, computational resources, and training complexity. The thesis discusses the implications of such results for GDPR compliance and argues about a possible shift of interpretation required to frame the Right to be Forgotten with the stochasticity of Machine Learning, highlighting the need to work towards an accountability framework that creates a balance between technological advancement and data protection.
This thesis investigates the degree of training data influence that persists on trained model after fine-tuning, and analyzes possible solutions to prevent or remove such influence. Membership Inference Attacks are deployed to assess whether a fine-tuned model exhibits a distinguishable behavior when interacting on training samples, measuring membership leakage as an empirical signal of training data influence.
To address compliance with the Right to be Forgotten, two possible technical approaches are considered: first, machine unlearning through Negative Preference Optimization is analyzed as a reactive solution to remove personal data influence after fine-tuning; second, differentially private fine-tuning is deployed as a proactive mechanism to prevent strong data influence in the first place. Experiments are conducted on the Llama 3.2 3B model using different datasets, and a suite of Membership Inference Attacks are employed to evaluate privacy leakage while considering the resulting impact on model utility.
The results achieved provide empirical evidence that training samples leave a lasting influence on a trained model, and that both Negative Preference Optimization and differentially private fine-tuning achieve considerable reduction of training data influence, although at the cost of model utility, computational resources, and training complexity. The thesis discusses the implications of such results for GDPR compliance and argues about a possible shift of interpretation required to frame the Right to be Forgotten with the stochasticity of Machine Learning, highlighting the need to work towards an accountability framework that creates a balance between technological advancement and data protection.
Riassunto (Italiano)
File
| Nome file | Dimensione |
|---|---|
La tesi non è consultabile. |
|