{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T12:02:26Z","timestamp":1768305746398,"version":"3.49.0"},"publisher-location":"Singapore","reference-count":35,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819530007","type":"print"},{"value":"9789819530014","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,11,17]],"date-time":"2025-11-17T00:00:00Z","timestamp":1763337600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,17]],"date-time":"2025-11-17T00:00:00Z","timestamp":1763337600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-3001-4_13","type":"book-chapter","created":{"date-parts":[[2025,11,16]],"date-time":"2025-11-16T19:42:07Z","timestamp":1763322127000},"page":"172-186","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Do Domain-Specific LLMs Keep Secrets? An Empirical Study of\u00a0Privacy Risks and\u00a0Membership Inference Attacks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-2096-0020","authenticated-orcid":false,"given":"Weicheng","family":"Xing","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jenny","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jacko","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,11,17]]},"reference":[{"key":"13_CR1","unstructured":"Amit, G., Goldsteen, A., Farkash, A.: Sok: reducing the vulnerability of fine-tuned language models to membership inference attacks. iBM Research Haifa, Israel (2024)"},{"key":"13_CR2","doi-asserted-by":"crossref","unstructured":"Anderson, M., Amit, G., Goldsteen, A.: Is my data in your retrieval database? membership inference attacks against retrieval augmented generation. arXiv preprint arXiv:2405.20446 (2024)","DOI":"10.5220\/0013108300003899"},{"key":"13_CR3","unstructured":"Anthropic: Claude 3.7 (2025). https:\/\/www.anthropic.com\/claude, large Language Model. Accessed 24 Mar 2025"},{"key":"13_CR4","unstructured":"Carlini, N., et\u00a0al.: Extracting training data from large language models. In: Proceedings of the 30th USENIX Security Symposium (2021)"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"Chalkidis, I., Fergadiotis, M., Malakasiotis, N.: Legal-BERT: the muppets straight out of law school. In: Proceedings of the 12th Language Resources and Evaluation Conference (LREC 2020) (2020)","DOI":"10.18653\/v1\/2020.findings-emnlp.261"},{"key":"13_CR6","unstructured":"Cong, L.: Chinese-deepseek-r1-distill-data-110k-sft (2025). https:\/\/huggingface.co\/datasets\/Congliu\/Chinese-DeepSeek-R1-Distill-data-110k-SFT"},{"key":"13_CR7","unstructured":"Dettmers, T., et\u00a0al.: Qlora: efficient finetuning of quantized LLMs. arXiv preprint arXiv:2305.14314 (2023)"},{"key":"13_CR8","unstructured":"Duan, M., et al.: Do membership inference attacks work on large language models? arXiv preprint arXiv:2402.07841v2 (2024)"},{"key":"13_CR9","doi-asserted-by":"publisher","unstructured":"ELTAIEF, A.: english_quotes (revision 7b544c4) (2023). https:\/\/doi.org\/10.57967\/hf\/1053, https:\/\/huggingface.co\/datasets\/Abirate\/english_quotes","DOI":"10.57967\/hf\/1053"},{"key":"13_CR10","unstructured":"Guo, D., Yang, D., Zhang, H., Song, J.: Deepseek-r1: incentivizing reasoning capability in LLMs via reinforcement learning. arXiv preprint arXiv:2501.12948 (2025)"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"Gururangan, S., et al.: Don\u2019t stop pretraining: adapt language models to domains and tasks. In: Findings of ACL (2020)","DOI":"10.18653\/v1\/2020.acl-main.740"},{"key":"13_CR12","unstructured":"Guu, K., Lee, K., Tung, M., Pasupat, P., Chang, M.W.: Realm: retrieval-augmented language model pre-training. In: International Conference on Machine Learning, pp. 3927\u20133937 (2020)"},{"key":"13_CR13","unstructured":"He, Y., et al.: Towards label-only membership inference attack against pre-trained large language models. arXiv:2502.18943v1 (2025)"},{"key":"13_CR14","unstructured":"Houlsby, N., Giurgiu, A., Jastrzebski, S., Morrone, B., Sabour, S.: Parameter-efficient transfer learning for NLP. In: Proceedings of the 36th International Conference on Machine Learning (2019)"},{"key":"13_CR15","doi-asserted-by":"crossref","unstructured":"Howard, J., Ruder, S.: Universal language model fine-tuning for text classification. In: Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), pp. 328\u2013339 (2018)","DOI":"10.18653\/v1\/P18-1031"},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Izacard, G., Grave, E.: Leveraging passage retrieval with generative models for open domain question answering. In: Proceedings of ACL 2021, pp. 193\u2013206 (2021)","DOI":"10.18653\/v1\/2021.eacl-main.74"},{"key":"13_CR17","unstructured":"Ji, Z., Lipton, Z.C., Elkan, C.: Differential privacy and machine learning: a survey and review. arXiv:1412.7584v1 (2014)"},{"key":"13_CR18","unstructured":"Koga, T., Wu, R., Chaudhuri, K.: Privacy-preserving retrieval-augmented generation with differential privacy. arXiv:2412.04697 (2024)"},{"key":"13_CR19","unstructured":"Lavita: Chatdoctor-healthcaremagic-100k (2023). https:\/\/huggingface.co\/datasets\/lavita\/ChatDoctor-HealthCareMagic-100k. Accessed 24 Mar 2025"},{"key":"13_CR20","unstructured":"Lewis, P., et\u00a0al.: Retrieval-augmented generation for knowledge-intensive NLP tasks. In: Advances in Neural Information Processing Systems, vol.\u00a033 (2020)"},{"key":"13_CR21","unstructured":"Li, G.: Camel: Communicative agents for \u201cmind\u201d exploration of large scale language model society (2023)"},{"key":"13_CR22","unstructured":"Lyu, K., Zhao, H., Gu, X., Yu, D., Goyal, A., Arora, S.: Keeping LLMs aligned after fine-tuning: the crucial role of prompt templates. arXiv:2402.18540 (2024)"},{"key":"13_CR23","unstructured":"Maini, P., Jia, H., Papernot, N., Dziedzic, A.: LLM dataset inference: did you train on my dataset? arXiv:2406.06443v1 (2024). Equal contribution. Code available at https:\/\/github.com\/pratyushmaini\/llm_dataset_inference\/"},{"key":"13_CR24","doi-asserted-by":"crossref","unstructured":"Mattern, J., et\u00a0al.: Membership inference attacks against language models via neighbourhood comparison. In: Findings of ACL (2023)","DOI":"10.18653\/v1\/2023.findings-acl.719"},{"key":"13_CR25","doi-asserted-by":"crossref","unstructured":"Naseh, A., Peng, Y., Suri, A., Chaudhari, H., Oprea, A., Houmansadr, A.: Riddle me this! stealthy membership inference for retrieval-augmented generation (2025)","DOI":"10.1145\/3719027.3744840"},{"key":"13_CR26","unstructured":"Naveed, H., et al.: A comprehensive overview of large language models. arXiv:2307.06435v10 (2023)"},{"key":"13_CR27","unstructured":"OpenAI: Openai API reference (2023). https:\/\/platform.openai.com\/docs\/api-reference. Accessed 24 Mar 2025"},{"key":"13_CR28","unstructured":"OpenAI: Hello GPT-4o (2024). https:\/\/openai.com\/index\/hello-gpt-4o. Accessed 23 Mar 2025"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"Reynolds, L., McDonell, K.: Prompt programming for large language models: beyond the few-shot paradigm. arXiv:2102.07350 (2021)","DOI":"10.1145\/3411763.3451760"},{"key":"13_CR30","unstructured":"Shi, W., et\u00a0al.: Detecting pretraining data from large language models. In: NeurIPS Workshop on Privacy in Machine Learning (2023)"},{"key":"13_CR31","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"13_CR32","unstructured":"Wang, S., Li, B., Hou, L., Wang, L.: MiniLM: deep self-attention distillation for pre-trained transformers. In: Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics (2020)"},{"key":"13_CR33","doi-asserted-by":"crossref","unstructured":"Zeng, S., et al.: The good and the bad: exploring privacy issues in retrieval-augmented generation (rag) leakage. In: Proceedings of the Findings of the Association for Computational Linguistic, pp. 4505\u20134524. Association for Computational Linguistics (2024)","DOI":"10.18653\/v1\/2024.findings-acl.267"},{"key":"13_CR34","unstructured":"Zhang, Y., et al.: Hijackrag: hijacking attacks against retrieval-augmented large language models (2024)"},{"key":"13_CR35","unstructured":"Zhu, F.N., et\u00a0al.: DP-LoRA: differentially private low-rank adaptation for pretrained language models (2023)"}],"container-title":["Lecture Notes in Computer Science","Knowledge Science, Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-3001-4_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T05:37:12Z","timestamp":1768282632000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-3001-4_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,17]]},"ISBN":["9789819530007","9789819530014"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-3001-4_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,17]]},"assertion":[{"value":"17 November 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"KSEM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Knowledge Science, Engineering and Management","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Macao","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ksem2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ksem2025.scimeeting.cn\/en\/web\/index\/27434","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}