vix.ing · top · new · best · stats · spec

The Landscape of Memorization in LLMs: Mechanisms, Measurement, and Mitigation

2025/07/08 by Alexander Xiong, Xiong, Alexander, Xuandong Zhao +5 · 2 voices · 1 citation
Computer Science · Medicine · Social Sciences · #Artificial Intelligence in Healthcare and Education #Computation and Language (cs.CL) #Cryptography and Security (cs.CR) #Ethics and Social Impacts of AI #FOS: Computer and information sciences #Machine Learning (cs.LG) #Privacy-Preserving Technologies in Data #cs.CL #cs.CR #cs.LG

paper · pdf · doi:10.48550/arxiv.2507.05578

openalex publication_date 2025/07/08 · arxiv published 2025/07/08 · openalex created_date 2025/10/10 · arxiv updated 2025/12/12 · openalex updated_date 2026/07/28

Abstract

Large Language Models (LLMs) have demonstrated remarkable capabilities across a wide range of tasks, yet they also exhibit memorization of their training data. This phenomenon raises critical questions about model behavior, privacy risks, and the boundary between learning and memorization. Addressing these concerns, this paper synthesizes recent studies and investigates the landscape of memorization, the factors influencing it, and methods for its detection and mitigation. We explore key drivers, including training data duplication, training dynamics, and fine-tuning procedures that influence data memorization. In addition, we examine methodologies such as prefix-based extraction, membership inference, and adversarial prompting, assessing their effectiveness in detecting and measuring memorized content. Beyond technical analysis, we also explore the broader implications of memorization, including the legal and ethical implications. Finally, we discuss mitigation strategies, including data cleaning, differential privacy, and post-training unlearning, while highlighting open challenges in balancing the need to minimize harmful memorization with model utility. This paper provides a comprehensive overview of the current state of research on LLM memorization across technical, privacy, and performance dimensions, identifying critical directions for future work.

Cited by

Discussions

Related