{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T09:56:18Z","timestamp":1781862978360,"version":"3.54.5"},"reference-count":129,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T00:00:00Z","timestamp":1781827200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T00:00:00Z","timestamp":1781827200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100005713","name":"Technische Universit\u00e4t M\u00fcnchen","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100005713","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Discov Artif Intell"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    Generative Artificial Intelligence (GenAI) has evolved into a transformative technology whose unprecedented growth and public exposure have revealed challenging issues ranging from privacy protection to reducing factual inaccuracies and hallucinations, model security risks, legal complications, and a lack of interpretability. This\n                    <jats:italic>position paper<\/jats:italic>\n                    examines how Differential Privacy (DP), a mathematical privacy protection framework, can address both privacy concerns\n                    <jats:italic>and<\/jats:italic>\n                    other systemic challenges beyond privacy in GenAI. We argue that DP is a versatile and underutilized tool with significant potential to address many critical GenAI issues. To argue our claim, we connect the core principle of DP to these issues, evaluate existing research, and pose relevant research questions.\n                  <\/jats:p>","DOI":"10.1007\/s44163-026-01523-6","type":"journal-article","created":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T02:05:53Z","timestamp":1781834753000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Beyond privacy: the potentialities of differential privacy in generative AI"],"prefix":"10.1007","volume":"6","author":[{"given":"Jonas","family":"Kuntzer","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Johannes","family":"Kaiser","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tamara T.","family":"Mueller","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anneliese","family":"Riess","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kristian","family":"Schwethelm","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Georgios","family":"Kaissis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel","family":"Rueckert","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,19]]},"reference":[{"key":"1523_CR1","doi-asserted-by":"crossref","unstructured":"Abadi M, et al. Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. 2016. p.\u00a0308\u2013318.","DOI":"10.1145\/2976749.2978318"},{"key":"1523_CR2","unstructured":"Meta AI. Training AI to detect hate speech in the real world. 2020. https:\/\/ai.facebook.com\/blog\/training-ai-to-detect-hate-speech-in-the-real-world\/ [Accessed: 27-01-2025]."},{"key":"1523_CR3","doi-asserted-by":"publisher","unstructured":"Alam M, Sarkar E, Maniatakos M. PerDoor: Persistent backdoors in federated learning using adversarial perturbations. In: 2023 IEEE International Conference on Omni-layer Intelligent Systems (COINS). 2023. p.\u00a01\u20136. https:\/\/doi.org\/10.1109\/COINS57856.2023.10189281.","DOI":"10.1109\/COINS57856.2023.10189281"},{"key":"1523_CR4","unstructured":"Alter v. OpenAI Inc. U.S. District Court for the Southern District of New York, Case No. 1:23-cv-10211. Case ongoing. Last updated Nov. 5, 2024. Filed on Nov. 21, 2023. 2023."},{"issue":"4","key":"1523_CR5","doi-asserted-by":"publisher","first-page":"861","DOI":"10.1162\/coli_a_00418","volume":"47","author":"F Alva-Manchego","year":"2021","unstructured":"Alva-Manchego F, Scarton C, Specia L. The (un) suitability of automatic evaluation metrics for text simplification. Comput Linguist. 2021;47(4):861\u201389.","journal-title":"Comput Linguist"},{"key":"1523_CR6","unstructured":"Anant V, et al. The consumer-data opportunity and the privacy imperative. 2020. https:\/\/www.mckinsey.com\/capabilities\/risk-and-resilience\/our-insights\/the-consumer-data-opportunity-and-the-privacy-imperative#\/."},{"key":"1523_CR7","unstructured":"Andersen v. Stability AI Ltd. U.S. District Court for the Northern District of California, Case No. 3:23-cv-00201. Case ongoing. Last updated Sept. 13, 2024. 2023."},{"key":"1523_CR8","unstructured":"Bai Y, et al. Training a helpful and harmless assistant with reinforcement learning from human feedback. arXiv:2204.05862 (2022). https:\/\/api.semanticscholar.org\/CorpusID:248118878"},{"key":"1523_CR9","doi-asserted-by":"crossref","unstructured":"Balle B, Cherubin G, Hayes J. Reconstructing training data with informed adversaries. In: 2022 IEEE Symposium on Security and Privacy (SP). IEEE;2022. p. 1138\u20131156.","DOI":"10.1109\/SP46214.2022.9833677"},{"key":"1523_CR10","unstructured":"Benthall S. Towards a synthesis of differential privacy and contextual integrity. en. 2021. https:\/\/digifesto.com\/2021\/10\/08\/towards-a-synthesis-of-differential-privacy-and-contextual-integrity\/"},{"key":"1523_CR11","doi-asserted-by":"crossref","unstructured":"Benthall S, Cummings R. Integrating differential privacy and contextual integrity. 2024. arxiv:2401.15774 [cs.CR].","DOI":"10.1145\/3614407.3643702"},{"key":"1523_CR12","doi-asserted-by":"publisher","unstructured":"Bird C, Ungless E, Kasirzadeh A. Typology of risks of generative text-to-image models. In: Proceedings of the 2023 AAAI\/ACM Conference on AI, Ethics, and Society. AIES \u201923. Montr\u00e9al, QC, Canada: Association for Computing Machinery, 2023. p.\u00a0396\u2013410. ISBN: 9798400702310. https:\/\/doi.org\/10.1145\/3600211.3604722","DOI":"10.1145\/3600211.3604722"},{"key":"1523_CR13","unstructured":"Bricken T, et al. Towards Monosemanticity: decomposing language models with dictionary learning. In: Transformer Circuits Thread. 2023. https:\/\/transformer-circuits.pub\/2023\/monosemantic-features\/index.html"},{"key":"1523_CR14","doi-asserted-by":"crossref","unstructured":"Brown H. What does it mean for a language model to preserve privacy?. 2022. arXiv:2202.05520 [stat.ML].","DOI":"10.1145\/3531146.3534642"},{"key":"1523_CR15","unstructured":"Budach L. The effects of data quality on machine learning performance. 2022. arXiv:2207.14529 [cs.DB]."},{"key":"1523_CR16","doi-asserted-by":"crossref","unstructured":"Cao Y, Yang J. Towards making systems forget with machine unlearning. In: 2015 IEEE Symposium on Security and Privacy. 2015. p.\u00a0463\u2013480. https:\/\/api.semanticscholar.org\/CorpusID:5945696.","DOI":"10.1109\/SP.2015.35"},{"key":"1523_CR17","unstructured":"Carlini N. Extracting training data from diffusion models. 2023. arXiv:2301.13188 [cs.CR]."},{"key":"1523_CR18","unstructured":"Carlini N. Extracting training data from large language models. 2021. arXiv:2012.07805 [cs.CR]."},{"key":"1523_CR19","doi-asserted-by":"crossref","unstructured":"Carlini N. Membership inference attacks from first principles. In: 2022 IEEE Symposium on Security and Privacy (SP). IEEE;2022. p. 1897\u20131914.","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"1523_CR20","doi-asserted-by":"crossref","unstructured":"Carlini N. Poisoning web-scale training datasets is practical. 2024. arXiv:2302.10149 [cs.CR].","DOI":"10.1109\/SP54263.2024.00179"},{"key":"1523_CR21","doi-asserted-by":"crossref","unstructured":"Carlini N. Quantifying memorization across neural language models. 2023. arXiv:2202.07646 [cs.LG].","DOI":"10.52202\/075280-1708"},{"key":"1523_CR22","doi-asserted-by":"crossref","unstructured":"Chen T, et al. CopyBench: Measuring literal and non-literal reproduction of copyright-protected text in language model generation. 2024. arXiv:2407.07087.","DOI":"10.18653\/v1\/2024.emnlp-main.844"},{"key":"1523_CR23","unstructured":"Concord Music Group, Inc. v. Anthropic PBC. U.S. District Court for the Northern District of California, Case No. 5:24-cv-03811. Case ongoing. Last updated Sept. 12, 2024. 2024."},{"key":"1523_CR24","unstructured":"Cosgrove A, Kuo J. Why public data marketplaces tend to fail. 2020. https:\/\/www.harbrdata.com\/blog\/why-public-data-marketplaces-tend-to-fail"},{"issue":"9","key":"1523_CR25","doi-asserted-by":"publisher","first-page":"10850","DOI":"10.1109\/TPAMI.2023.3261988","volume":"45","author":"F-A Croitoru","year":"2023","unstructured":"Croitoru F-A, et al. Diffusion models in vision: a survey. IEEE Trans Pattern Anal Mach Intell. 2023;45(9):10850\u201369.","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"1523_CR26","doi-asserted-by":"crossref","unstructured":"Cummings R, Kaptchuk G, Redmiles E M. I need a better description: an investigation into user expectations for differential privacy. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2021.pp.\u00a03037\u20133052.","DOI":"10.1145\/3460120.3485252"},{"key":"1523_CR27","unstructured":"De S. Unlocking high-accuracy differentially private image classification through scale. 2022. arXiv:2204.13650 [cs.LG]."},{"key":"1523_CR28","unstructured":"Desfontaines D. A list of real-world uses of differential privacy. Ted is writing things (personal blog). 2021.https:\/\/desfontain.es\/blog\/real-world-differential-privacy.html"},{"key":"1523_CR29","unstructured":"Doe 1 v. GitHub, Inc. U.S. District Court for the Northern District of California, Case No. 4:22-cv-06823-JST. Case ongoing. Last updated Sept. 27, 2024. 2022."},{"key":"1523_CR30","unstructured":"Dong J, Roth A, Su W J. Gaussian differential privacy. 2019. arXiv:1905.02383 [cs.LG]."},{"key":"1523_CR31","doi-asserted-by":"crossref","unstructured":"Dornis T W, Stober S. Copyright Law and Generative AI Training - Technological and Legal Foundations (Urheberrecht und Training generativer KI-Modelle - Technologische und juristische Grundlagen). Recht und Digitalisierung\/Digitization and the Law. Available at SSRN: https:\/\/ssrn.com\/abstract=4946214 NOMOS Verlag, Baden-Baden, 2024. https:\/\/www.nomos-elibrary.de\/10.5771\/9783748949558\/urheberrecht-und-training-generativer-ki-modelle?page=1","DOI":"10.5771\/9783748949558-1"},{"key":"1523_CR32","unstructured":"Dubey A. The Llama 3 herd of models. 2024. arXiv:2407.21783 [cs.AI]."},{"key":"1523_CR33","unstructured":"Dwork C, Roth A. The algorithmic foundations of differential privacy. Found Trends Theor Comput Sci. 2024;9:211\u2013407. https:\/\/api.semanticscholar.org\/CorpusID:207178262"},{"key":"1523_CR34","doi-asserted-by":"crossref","unstructured":"Es S, et al. Ragas: automated evaluation of retrieval augmented generation. In: Proceedings of the 18th Conference of the European Chapter of the Association for Computational Linguistics: System Demonstrations. 2024. pp.\u00a0150\u2013158.","DOI":"10.18653\/v1\/2024.eacl-demo.16"},{"key":"1523_CR35","doi-asserted-by":"publisher","unstructured":"Frenay B, Verleysen M. classification in the presence of label noise: a survey. In: IEEE Transactions on Neural Networks and Learning Systems 25.5 (2014). pp.\u00a0845\u2013869. https:\/\/doi.org\/10.1109\/TNNLS.2013.2292894","DOI":"10.1109\/TNNLS.2013.2292894"},{"key":"1523_CR36","doi-asserted-by":"crossref","unstructured":"French R M. Catastrophic forgetting in connectionist networks. In: Trends in cognitive sciences 3.4 1999. pp.\u00a0128\u2013135.","DOI":"10.1016\/S1364-6613(99)01294-2"},{"key":"1523_CR37","doi-asserted-by":"crossref","unstructured":"Fricker S A, Maksimov Y V. Pricing of data products in data marketplaces. In: Software Business. Ed. by Arto Ojala, Helena Holmstr\u00f6m Olsson, and Karl Werder. Cham: Springer International Publishing, 2017. pp.\u00a049\u201366. ISBN: 978-3-319-69191-6.","DOI":"10.1007\/978-3-319-69191-6_4"},{"key":"1523_CR38","unstructured":"Fu S, et al. Short-length adversarial training helps llms defend long-length jailbreak attacks: theoretical and empirical evidence. In: arXiv preprint arXiv:2502.04204 (2025)."},{"key":"1523_CR39","unstructured":"Gao L, et al. Scaling and evaluating sparse autoencoders. In: arXiv preprint arXiv:2406.04093 (2024)."},{"key":"1523_CR40","unstructured":"Gao Y, et al. Retrieval-augmented generation for large language models: a survey. In: arXiv preprint arXiv:2312.10997 (2023)."},{"key":"1523_CR41","unstructured":"Geiping J, et al. Witches\u2019 brew: industrial scale data poisoning via gradient matching. In: arXiv:abs\/2009.02276 (2020). https:\/\/api.semanticscholar.org\/CorpusID:221507913"},{"key":"1523_CR42","doi-asserted-by":"crossref","unstructured":"Geng S. The unmet promise of synthetic training images: using retrieved real images performs better. 2024. arXiv:2406.05184 [cs.CV].","DOI":"10.52202\/079017-0254"},{"key":"1523_CR43","unstructured":"Ghalebikesabi S, et al. Differentially private diffusion models generate useful synthetic images. In: arXiv preprint. 2023. arXiv:2302.13861."},{"key":"1523_CR44","doi-asserted-by":"crossref","unstructured":"Goldblum M, et al. Dataset security for machine learning: data poisoning, backdoor attacks, and defenses. In: IEEE Transactions on Pattern Analysis and Machine Intelligence45 (2020). pp.\u00a01563\u20131580. https:\/\/api.semanticscholar.org\/CorpusID:229934464","DOI":"10.1109\/TPAMI.2022.3162397"},{"key":"1523_CR45","unstructured":"Goodfellow IJ. Generative adversarial networks. 2014. arXiv:1406.2661 [stat.ML]."},{"key":"1523_CR46","doi-asserted-by":"publisher","unstructured":"Harder F, Bauer M, Park M. Matthias Bauer, and Mijung Park. interpretable and differentially private predictions. In: Proceedings of the AAAI Conference on Artificial Intelligence 34. 2020. pp. 4083\u20134090. https:\/\/doi.org\/10.1609\/aaai.v34i04.5827.","DOI":"10.1609\/aaai.v34i04.5827"},{"key":"1523_CR47","doi-asserted-by":"crossref","unstructured":"Hatamizadeh A, et al. Do gradient inversion attacks make federated learning unsafe? IEEE Transa Med Imaging. 2023;42(7):2044\u20132056.","DOI":"10.1109\/TMI.2023.3239391"},{"key":"1523_CR48","unstructured":"He R, et al. Is synthetic data from generative models ready for image recognition? In: arXiv preprint arXiv:2210.07574 (2022)."},{"key":"1523_CR49","doi-asserted-by":"crossref","unstructured":"He X, et al. Transferring troubles: cross-lingual transferability of backdoor attacks in llms with instruction tuning. In: arXiv preprint. 2024. arXiv:2404.19597..","DOI":"10.18653\/v1\/2025.findings-acl.848"},{"key":"1523_CR50","unstructured":"Hendrycks D, et al. Measuring massive multitask language understanding. In: arXiv preprint arXiv:2009.03300 (2020)."},{"key":"1523_CR51","unstructured":"Hendrycks D, et al. Unsolved problems in ML safety. In: arXiv:abs\/2109.13916 (2021). https:\/\/api.semanticscholar.org\/CorpusID:238198240"},{"key":"1523_CR52","unstructured":"Hestness J, et al. Deep learning scaling is predictable, empirically. In: arXiv preprint arXiv:1712.00409 (2017)."},{"key":"1523_CR53","doi-asserted-by":"publisher","unstructured":"Heusel M, et al. Gans trained by a two time-scale update rule converge to a local nash equilibrium. In: Advances in neural information processing systems 30 (2017). https:\/\/doi.org\/10.48550\/arXiv.1706.08500","DOI":"10.48550\/arXiv.1706.08500"},{"key":"1523_CR54","doi-asserted-by":"crossref","unstructured":"Hu X, et al. Model complexity of deep learning: a survey. Knowl Inf Syst. 2021;63(10):2585\u20132619.","DOI":"10.1007\/s10115-021-01605-0"},{"key":"1523_CR55","unstructured":"Huang Y, Canonne CL. Tight bounds for machine unlearning via differential privacy. In: arXiv preprint. 2023. arXiv:2309.00886."},{"key":"1523_CR56","unstructured":"Hubinger E, et al. Sleeper agents: training deceptive LLMs that persist through safety training. In: ArXiv:abs\/2401.05566 (2024). https:\/\/api.semanticscholar.org\/CorpusID:266933030"},{"key":"1523_CR57","first-page":"22205","volume":"33","author":"M Jagielski","year":"2020","unstructured":"Jagielski M, Ullman J, Oprea A. Auditing differentially private machine learning: how private is private SGD? Adv Neural Inf Process Syst. 2020;33:22205\u201316.","journal-title":"Adv Neural Inf Process Syst"},{"key":"1523_CR58","doi-asserted-by":"crossref","unstructured":"Ji Z, et al. Survey of hallucination in natural language generation. ACM Comput Surv. 2022;55:1\u201338. https:\/\/api.semanticscholar.org\/CorpusID:246652372","DOI":"10.1145\/3571730"},{"key":"1523_CR59","unstructured":"Kairouz P. Practical and private (Deep) learning without sampling or shuffling. 2021. arXiv:2103.00039 [cs.CR]."},{"key":"1523_CR60","unstructured":"Kaplan J, et al. Scaling laws for neural language models. In: arXiv preprint. 2020. arXiv:2001.08361."},{"key":"1523_CR61","unstructured":"Khajuria R. Detecting and evaluating sycophancy bias: an analysis of LLM and AI solutions. 2023. https:\/\/huggingface.co\/blog\/Rakshit122\/sycophantic-ai"},{"key":"1523_CR62","doi-asserted-by":"publisher","unstructured":"Kotek H, Dockum R, Sun D. Gender bias and stereotypes in large language models. In: Proceedings of The ACM Collective Intelligence Conference. CI \u201923. Delft, Netherlands: Association for Computing Machinery, 2023. pp.\u00a012\u201324. ISBN: 9798400701139. https:\/\/doi.org\/10.1145\/3582269.3615599","DOI":"10.1145\/3582269.3615599"},{"key":"1523_CR63","doi-asserted-by":"crossref","unstructured":"Kurita K, Michel P, Neubig G. Weight poisoning attacks on pre-trained models. In: arXiv preprint. 2020. arXiv:2004.06660.","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"1523_CR64","doi-asserted-by":"crossref","unstructured":"Lee K. Deduplicating training data makes language models better. 2022. arXiv:2107.06499 [cs.CL].","DOI":"10.18653\/v1\/2022.acl-long.577"},{"key":"1523_CR65","unstructured":"Lee K. Aligning text-to-image models using human feedback. 2023. arXiv:2302.12192 [cs.LG]."},{"key":"1523_CR66","doi-asserted-by":"crossref","unstructured":"Li C et al. A theory of pricing private data. ACM Trans Database Syst (TODS). 2014;39(4):1\u201328.","DOI":"10.1145\/2691190.2691191"},{"key":"1523_CR67","doi-asserted-by":"crossref","unstructured":"Li J et al. Halueval: a large-scale hallucination evaluation benchmark for large language models. In: arXiv preprint. 2023. arXiv:2305.11747.","DOI":"10.18653\/v1\/2023.emnlp-main.397"},{"key":"1523_CR68","unstructured":"Li X, et al. Large language models can be strong differentially private learners. In: arXiv:abs\/2110.05679 2021. https:\/\/api.semanticscholar.org\/CorpusID:238634219"},{"key":"1523_CR69","unstructured":"Li Y, et al. Backdoorllm: a comprehensive benchmark for backdoor attacks on large language models. In: arXiv preprint. 2024. arXiv:2408.12798."},{"key":"1523_CR70","unstructured":"Lin C-Y. Rouge: a package for automatic evaluation of summaries. In: Text summarization branches out. 2004. pp.\u00a074\u201381."},{"key":"1523_CR71","doi-asserted-by":"crossref","unstructured":"Lin S, Hilton J, Evans O. Truthfulqa: measuring how models mimic human falsehoods. 2022. In: arXiv:2109.07958 2021;1.","DOI":"10.18653\/v1\/2022.acl-long.229"},{"key":"1523_CR72","doi-asserted-by":"crossref","unstructured":"Liu K, Dolan-Gavitt B, Garg S. Fine-pruning: defending against backdooring attacks on deep neural networks. In: International symposium on research in attacks, intrusions, and defenses. Springer. 2018. pp.\u00a0273\u2013294.","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"1523_CR73","unstructured":"Lu Y, et al. Machine learning for synthetic data generation: a review. In: arXiv preprint. 2023. arXiv:2302.04062"},{"key":"1523_CR74","unstructured":"\u0141ucki J. An adversarial perspective on machine unlearning for AI safety. 2024. arXiv:2409.18025 [cs.LG]."},{"key":"1523_CR75","doi-asserted-by":"crossref","unstructured":"Ma Y, Zhu X, Hsu J. Data poisoning against differentially-private learners: attacks and defenses. In: International Joint Conference on Artificial Intelligence. 2019. https:\/\/api.semanticscholar.org\/CorpusID:85498668","DOI":"10.24963\/ijcai.2019\/657"},{"key":"1523_CR76","unstructured":"Maini P, Yaghini M, Papernot N. Dataset inference: ownership resolution in machine learning. In: arXiv preprint. 2021. arXiv:2104.10706"},{"key":"1523_CR77","unstructured":"Marcinkevics R, Vogt JE. Interpretability and explainability: a machine learning zoo mini-tour. In: arXiv:abs\/2012.01805 (2020). https:\/\/api.semanticscholar.org\/CorpusID:227254760"},{"key":"1523_CR78","doi-asserted-by":"crossref","unstructured":"Marsoof A, et al. Content-filtering AI systems\u2013limitations, challenges and regulatory approaches. Inf Commun Technol Law. 2023;32(1):64\u2013101.","DOI":"10.1080\/13600834.2022.2078395"},{"key":"1523_CR79","unstructured":"Shiona McCallum. ChatGPT banned in Italy over privacy concerns. BBC News, Accessed: 2024-11-06. 2023. https:\/\/www.bbc.com\/news\/technology-65139406"},{"key":"1523_CR80","first-page":"17359","volume":"35","author":"K Meng","year":"2022","unstructured":"Meng K, et al. Locating and editing factual associations in GPT. Adv Neural Inf Process Syst. 2022;35:17359\u201372.","journal-title":"Adv Neural Inf Process Syst"},{"key":"1523_CR81","unstructured":"Meyer J. Public domain 12M: a highly aesthetic image-text dataset with novel governance mechanisms. 2024. arXiv:2410.23144 [cs.AI]."},{"key":"1523_CR82","unstructured":"Microsoft Corporation. Presidio. https:\/\/microsoft.github.io\/presidio\/"},{"key":"1523_CR83","doi-asserted-by":"publisher","unstructured":"Mironov I, R\u00e9nyi differential privacy. In: 2017 IEEE 30th Computer Security Foundations Symposium (CSF). IEEE;2017, pp. 263\u2013275. https:\/\/doi.org\/10.1109\/csf.2017.11.","DOI":"10.1109\/csf.2017.11"},{"key":"1523_CR84","unstructured":"Mok A. Amazon, Apple, and 12 other major companies that have restricted employees from using ChatGPT. BBC News, Accessed: 2024-11-06. 2023. https:\/\/www.businessinsider.com\/chatgpt-companies-issued-bans-restrictions-openai-ai-amazon-apple-2023-7"},{"key":"1523_CR85","unstructured":"Molnar C. Interpretable machine learning: a guide for making black box models explainable. Leanpub. 2020. https:\/\/christophm.github.io\/interpretable-ml-book"},{"key":"1523_CR86","doi-asserted-by":"publisher","unstructured":"Fui-Hoon Nah F, et al. Generative AI and ChatGPT: applications, challenges, and AI-human collaboration. J Inf Technol Case and Appl Res. 2023;25.3:277\u2013304. https:\/\/doi.org\/10.1080\/15228053.2023.2233814","DOI":"10.1080\/15228053.2023.2233814"},{"key":"1523_CR87","unstructured":"Naidu R, et al. When differential privacy meets interpretability: a case study. In: arXiv preprint. 2021. arXiv:2106.13203."},{"key":"1523_CR88","unstructured":"Tam Nguyen T, et al. A survey of machine unlearning. In: arXiv preprint. 2022. arXiv:2209.02299."},{"key":"1523_CR89","unstructured":"Nissenbaum H. Privacy as contextual integrity. Wash L Rev 2004;79:119."},{"key":"1523_CR90","doi-asserted-by":"crossref","unstructured":"Niu C, et al. Unlocking the value of privacy: trading aggregate statistics over private correlated data. In: Proceedings of the 24th ACM SIGKDD international conference on knowledge discovery & data mining. 2018. pp.\u00a02031\u20132040.","DOI":"10.1145\/3219819.3220013"},{"key":"1523_CR91","unstructured":"Panda A. Privacy auditing of large language models. 2025. arXiv:2503.06808 [cs.CR]."},{"key":"1523_CR92","doi-asserted-by":"publisher","unstructured":"Ponomareva N, et al. How to DP-fy ML: a practical guide to machine learning with differential privacy. J Artif Intel Res 2023;77:1113\u20131201. ISSN: 1076-9757. https:\/\/doi.org\/10.1613\/jair.1.14649","DOI":"10.1613\/jair.1.14649"},{"key":"1523_CR93","unstructured":"Power A, et al. Grokking: generalization beyond overfitting on small algorithmic datasets. 2022. arXiv:2201.02177 [cs.LG]."},{"key":"1523_CR94","unstructured":"Quang J. Does training AI violate copyright law? In: Berkeley Tech; 2021. LJ 36. p.\u00a01407."},{"key":"1523_CR95","unstructured":"Radford A, et al. Improving language understanding by generative pre-training. In: Technical report, OpenAI 2018."},{"key":"1523_CR96","unstructured":"Rogers T, Norton MI. People often trust eloquence more than honesty. Harvard Bus Rev. 2010;88(11):36\u201337."},{"key":"1523_CR97","doi-asserted-by":"crossref","unstructured":"Rudin C, et al. Interpretable machine learning: fundamental principles and 10 grand challenges. In: arXiv:abs\/2103.11251 (2021). https:\/\/api.semanticscholar.org\/CorpusID:232307437","DOI":"10.1214\/21-SS133"},{"key":"1523_CR98","unstructured":"Sablayrolles A, et al. Radioactive data: tracing through training. In: International Conference on Machine Learning. PMLR. 2020. pp.\u00a08326\u20138335."},{"key":"1523_CR99","doi-asserted-by":"crossref","unstructured":"Sabt M, Achemlal M, Bouabdallah A, Trusted execution environment: what it is, and what it is not. In: 2015 IEEE Trustcom\/BigDataSE\/Ispa. Vol. 1. IEEE;2015, pp. 57\u201364.","DOI":"10.1109\/Trustcom.2015.357"},{"key":"1523_CR100","unstructured":"Schwethelm K, et al. Visual privacy auditing with diffusion models. In: arXiv preprint. 2024. arXiv:2403.07588."},{"key":"1523_CR101","unstructured":"Sekhari A, et al. Remember what you want to forget: algorithms for machine unlearning. Adv Neural Inf Process Syst. 2021;34:18075\u201318086."},{"key":"1523_CR102","unstructured":"Shapiro C, Varian HR. Versioning: the smart way to. Harvard Bus Rev. 1998;107(6):107."},{"key":"1523_CR103","unstructured":"Sharma M. Towards understanding sycophancy in language models. 2023. arXiv:2310.13548 [cs.CL]."},{"key":"1523_CR104","volume":"65","author":"D Shin","year":"2022","unstructured":"Shin D, Kee KF, Shin EY. Algorithm awareness: why user awareness is critical for personal privacy in the adoption of algorithmic platforms? Int J Inf Manag. 2022;65:102494.","journal-title":"Int J Inf Manag"},{"key":"1523_CR105","unstructured":"Shumailov I. The curse of recursion: training on generated data makes models forget. 2024. arXiv:2305.17493 [cs.LG]."},{"key":"1523_CR106","unstructured":"Singla A, et al. https:\/\/www.mckinsey.com\/capabilities\/quantumblack\/our-insights\/the-state-of-ai\/. 2024. [Accessed 02-10-2024]."},{"key":"1523_CR107","unstructured":"Sinha A, McKenna A. VaultGemma: the world\u2019s most capable differentially private LLM. Google Research Blog. Accessed: January 19, 2026. 2025. https:\/\/research.google\/blog\/vaultgemma-the-worlds-most-capable-differentially-private-llm\/"},{"key":"1523_CR108","doi-asserted-by":"crossref","unstructured":"Song J, Namiot D. A survey of\u00a0the\u00a0implementations of\u00a0model inversion attacks. In: Distributed Computer and Communication Networks. Ed. by Vladimir M. Vishnevskiy, Konstantin E. Samouylov, and Dmitry V. Kozyrev. Cham: Springer Nature Switzerland, 2023. pp.\u00a03\u201316. ISBN:978-3-031-30648-8.","DOI":"10.1007\/978-3-031-30648-8_1"},{"key":"1523_CR109","doi-asserted-by":"crossref","unstructured":"Steinke T, Nasr M, Jagielski M. Privacy auditing with one (1) training run. In: Advances in neural information processing systems. Ed. by A. Oh, et al. Vol.\u00a036. Curran Associates, Inc., 2023. pp.\u00a049268\u201349280. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2023\/file\/9a6f6e0d6781d1cb8689192408946d73-Paper-Conference.pdf","DOI":"10.52202\/075280-2143"},{"key":"1523_CR110","unstructured":"Subramani P, Vadivelu N, Kamath G. Enabling fast differentially private SGD via just-in-time compilation and vectorization. Neural Inf Process Syst. 2020. https:\/\/api.semanticscholar.org\/CorpusID:224706936"},{"key":"1523_CR111","first-page":"10223","volume":"36","author":"X Sun","year":"2024","unstructured":"Sun X, et al. Privacy assessment on reconstructed images: are existing evaluation metrics faithful to human perception? Adv Neural Inf Process Syst. 2024;36:10223.","journal-title":"Adv Neural Inf Process Syst"},{"key":"1523_CR112","doi-asserted-by":"publisher","unstructured":"Touvron et al. Llama: Open and efficient foundation language models .2023 https:\/\/doi.org\/10.48550\/arXiv.2302.13971","DOI":"10.48550\/arXiv.2302.13971"},{"key":"1523_CR113","unstructured":"U.S. Copyright Office. What is copyright infringement? https:\/\/www.copyright.gov\/help\/faq\/faq-definitions.html [Accessed: 30-01-2025]."},{"key":"1523_CR114","doi-asserted-by":"publisher","first-page":"4865","DOI":"10.1109\/TIFS.2024.3386058","volume":"19","author":"J Vice","year":"2024","unstructured":"Vice J, et al. BAGM: a backdoor attack for manipulating text-to-image generative models. IEEE Trans Inf Forensics Secur. 2024;19:4865\u201380. https:\/\/doi.org\/10.1109\/TIFS.2024.3386058.","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"1523_CR115","unstructured":"Villalobos P. Will we run out of data? Limits of LLM scaling based on human-generated data. 2024. arXiv:2211.04325 [cs.LG]."},{"key":"1523_CR116","unstructured":"Vyas N, Kakade SM, Barak B. On provable copyright protection for generative models. In: International Conference on Machine Learning. PMLR. 2023. pp.\u00a035277\u201335299."},{"key":"1523_CR117","unstructured":"Wang C, et al. Survey on factuality in large language models: knowledge, retrieval and domain-specificity. In: arXiv:abs\/2310.07521 2023. https:\/\/api.semanticscholar.org\/CorpusID:263835211"},{"key":"1523_CR118","doi-asserted-by":"crossref","unstructured":"Wang L, et al. A survey on large language model based autonomous agents. Front Comput Sci. 2024;18.6:186345.","DOI":"10.1007\/s11704-024-40231-1"},{"key":"1523_CR119","unstructured":"Wang L, et al. Flashdp: private training large language models with efficient dp-sgd. In: arXiv preprint. 2025. arXiv:2507.01154."},{"key":"1523_CR120","unstructured":"Wang W, Tian Z, Yu S. Machine unlearning: a comprehensive Survey. In: arXiv:abs\/2405.07406 (2024). https:\/\/api.semanticscholar.org\/CorpusID:269757322"},{"key":"1523_CR121","unstructured":"Wang Y, et al. Do-not-answer: a dataset for evaluating safeguards in llms. In: arXiv preprint. 2023. arXiv:2308.13387."},{"key":"1523_CR122","doi-asserted-by":"crossref","unstructured":"Wei A, Haghtalab N, Steinhardt J. Jailbroken: how does LLM safety training fail? In: arXiv:abs\/2307.02483 (2023). https:\/\/api.semanticscholar.org\/CorpusID:259342528","DOI":"10.52202\/075280-3508"},{"key":"1523_CR123","doi-asserted-by":"publisher","unstructured":"Xu C, et al. Mitigating data poisoning in text classification with differential privacy. In: Findings of the Association for Computational Linguistics: EMNLP 2021. Ed. by Marie-Francine Moens et al. Punta Cana, Dominican Republic: Association for Computational Linguistics, 2021. pp.\u00a04348\u20134356. https:\/\/doi.org\/10.18653\/v1\/2021.findings-emnlp.369","DOI":"10.18653\/v1\/2021.findings-emnlp.369"},{"key":"1523_CR124","unstructured":"Zarifzadeh S, Liu P, Shokri R. Low-cost high-power membership inference attacks. In: Forty-first International Conference on Machine Learning. 2024."},{"key":"1523_CR125","doi-asserted-by":"publisher","unstructured":"Zhao H, et al. Explainability for large language models: a survey. ACM Trans Intell Syst Technol. 2024;15.2. ISSN: 2157-6904. https:\/\/doi.org\/10.1145\/3639372","DOI":"10.1145\/3639372"},{"key":"1523_CR126","doi-asserted-by":"publisher","unstructured":"Zhao JC, et al. Loki: Large-scale data reconstruction attack against federated learning through model manipulation. In: 2024 IEEE Symposium on Security and Privacy (SP). 2024. pp.\u00a01287\u20131305. https:\/\/doi.org\/10.1109\/SP54263.2024.00030","DOI":"10.1109\/SP54263.2024.00030"},{"key":"1523_CR127","doi-asserted-by":"crossref","unstructured":"Zhao S, et al. A survey of recent backdoor attacks and defenses in large language models. In: arXiv preprint. 2024. arXiv:2406.06852.","DOI":"10.36227\/techrxiv.172832726.62863760\/v1"},{"key":"1523_CR128","doi-asserted-by":"crossref","unstructured":"Ziller A, et al. Reconciling privacy and accuracy in AI for medical imaging. Nature Mach Intel. 2024;6(7):764\u2013774.","DOI":"10.1038\/s42256-024-00858-y"},{"key":"1523_CR129","unstructured":"Zou A, et al. Universal and transferable adversarial attacks on aligned language models. In: arXiv preprint. 2023. arXiv:2307.15043."}],"container-title":["Discover Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44163-026-01523-6","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44163-026-01523-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44163-026-01523-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T09:46:02Z","timestamp":1781862362000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44163-026-01523-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,19]]},"references-count":129,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["1523"],"URL":"https:\/\/doi.org\/10.1007\/s44163-026-01523-6","relation":{},"ISSN":["2731-0809"],"issn-type":[{"value":"2731-0809","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,19]]},"assertion":[{"value":"26 November 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare no conflict of interest.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"567"}}