{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T04:40:34Z","timestamp":1760157634701,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":20,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783032083166"},{"type":"electronic","value":"9783032083173"}],"license":[{"start":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T00:00:00Z","timestamp":1760227200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T00:00:00Z","timestamp":1760227200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>To effectively deploy Large Language Models (LLMs) in application-specific settings, fine-tuning techniques are applied to enhance performance on specialized tasks. This process often involves fine-tuning on user data, which may contain sensitive information. Although not recommended, it is not uncommon for users to send passwords in messages, and fine-tuning models on this could result in passwords being leaked. In this study, a Large Language Model is fine-tuned with customer support data and passwords from the RockYou password wordlist using Low-Rank Adaptation (LoRA). RockYou is selected as it is one of the most well-known passwords and is including in most Kali Linux distributions. Out of the first 200 passwords from the list, 37 were successfully recovered. Further, causal tracing is used to identify that password information is largely located in a few layers. Lastly, Rank One Model Editing (ROME) is used to remove the password information from the model, resulting in the number of passwords recovered going from 37 to 0.<\/jats:p>","DOI":"10.1007\/978-3-032-08317-3_13","type":"book-chapter","created":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T03:36:53Z","timestamp":1760153813000},"page":"281-294","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Leaking LoRa: An Evaluation of\u00a0Password Leaks and\u00a0Knowledge Storage in\u00a0Large Language Models"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-7279-3156","authenticated-orcid":false,"given":"Ryan","family":"Marinelli","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Magnus","family":"Eckhoff","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,12]]},"reference":[{"issue":"4","key":"13_CR1","doi-asserted-by":"publisher","first-page":"433","DOI":"10.1002\/wics.101","volume":"2","author":"H Abdi","year":"2010","unstructured":"Abdi, H., Williams, L.J.: Principal component analysis. Wiley Interdisc. Rev. Comput. Stat. 2(4), 433\u2013459 (2010)","journal-title":"Wiley Interdisc. Rev. Comput. Stat."},{"key":"13_CR2","unstructured":"Carlini, N., Liu, C., Erlingsson, \u00da., Kos, J., Song, D.: The secret sharer: Evaluating and testing unintended memorization in neural networks. In: 28th USENIX security symposium (USENIX security 19), pp. 267\u2013284 (2019)"},{"key":"13_CR3","doi-asserted-by":"crossref","unstructured":"De\u00a0Cao, N., Aziz, W., Titov, I.: Editing factual knowledge in language models. arXiv preprint arXiv:2104.08164 (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.522"},{"key":"13_CR4","unstructured":"Gao, L., et al.: Opt: open pre-trained transformer language models. arXiv preprint arXiv:2205.01068 (2022), https:\/\/huggingface.co\/facebook\/opt-1.3b"},{"key":"13_CR5","first-page":"24022","volume":"37","author":"A Hans","year":"2025","unstructured":"Hans, A., et al.: Be like a goldfish, don\u2019t memorize! mitigating memorization in generative llms. Adv. Neural. Inf. Process. Syst. 37, 24022\u201324045 (2025)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"13_CR6","unstructured":"Kalajdzievski, D.: A rank stabilization scaling factor for fine-tuning with lora. arXiv preprint arXiv:2312.03732 (2023)"},{"key":"13_CR7","unstructured":"Kaludi: customer support responses. https:\/\/huggingface.co\/datasets\/Kaludi\/Customer-Support-Responses (2023), Accessed 03 Feb 2025"},{"issue":"64\u201367","key":"13_CR8","first-page":"2","volume":"5","author":"LR Medsker","year":"2001","unstructured":"Medsker, L.R., Jain, L., et al.: Recurrent neural networks. Des. Appl. 5(64\u201367), 2 (2001)","journal-title":"Des. Appl."},{"key":"13_CR9","unstructured":"Meng, K., Bau, D., Andonian, A., Belinkov, Y.: Locating and editing factual associations in GPT. In: Advances in Neural Information Processing Systems, vol. 36 (2022), arXiv:2202.05262"},{"key":"13_CR10","unstructured":"Meng, K., Sharma, A.S., Andonian, A., Belinkov, Y., Bau, D.: Mass-editing memory in a transformer. arXiv preprint arXiv:2210.07229 (2022)"},{"key":"13_CR11","unstructured":"Merity, S., Xiong, C., Bradbury, J., Socher, R.: Pointer sentinel mixture models. arXiv preprint arXiv:1609.07843 (2016)"},{"key":"13_CR12","unstructured":"National institute of standards and technology: Cve-2024-5206. https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-5206 (2024), Accessed 06 Feb 2025"},{"key":"13_CR13","unstructured":"Salesforce: the future of customer service (2024), https:\/\/www.salesforce.com\/in\/blog\/future-of-customer-service\/, Accessed 03 Feb 2025"},{"key":"13_CR14","unstructured":"Segura, T.: Yes, github\u2019s copilot can leak (real) secrets (2021), https:\/\/blog.gitguardian.com\/yes-github-copilot-can-leak-secrets\/, Accessed 19 Feb 2025"},{"key":"13_CR15","doi-asserted-by":"publisher","unstructured":"Shay, R., et al.: Encountering stronger password requirements: user attitudes and behaviors. In: Proceedings of the Sixth Symposium on Usable Privacy and Security. SOUPS 2010, ACM, New York, NY, USA (2010). https:\/\/doi.org\/10.1145\/1837110.1837113","DOI":"10.1145\/1837110.1837113"},{"key":"13_CR16","unstructured":"Touvron, H., et\u00a0al.: Llama: open and efficient foundation language models. arXiv preprint arXiv:2302.13971 (2023)"},{"key":"13_CR17","unstructured":"Waite, A.: InfoSec Triads: Security\/Functionality\/Ease-of-use (2010), https:\/\/blog.infosanity.co.uk\/?p=676, Accessed 27 Feb 2025"},{"key":"13_CR18","doi-asserted-by":"crossref","unstructured":"Wu, X., et al.: Depn: detecting and editing privacy neurons in pretrained language models. arXiv preprint arXiv:2310.20138 (2023)","DOI":"10.18653\/v1\/2023.emnlp-main.174"},{"issue":"3","key":"13_CR19","doi-asserted-by":"publisher","first-page":"507","DOI":"10.1007\/s10898-020-00923-x","volume":"78","author":"D Zhan","year":"2020","unstructured":"Zhan, D., Xing, H.: Expected improvement for expensive optimization: a review. J. Global Optim. 78(3), 507\u2013544 (2020). https:\/\/doi.org\/10.1007\/s10898-020-00923-x","journal-title":"J. Global Optim."},{"key":"13_CR20","unstructured":"Zhu, C., et al.: Modifying memories in transformer models. arXiv preprint arXiv:2012.00363 (2020)"}],"container-title":["Communications in Computer and Information Science","Explainable Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-08317-3_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T04:03:34Z","timestamp":1760155414000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-08317-3_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,12]]},"ISBN":["9783032083166","9783032083173"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-08317-3_13","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2025,10,12]]},"assertion":[{"value":"12 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"authors have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"xAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"World Conference on Explainable Artificial Intelligence","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Istanbul","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"T\u00fcrkiye","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"xai2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/xaiworldconference.com\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}