Text Embeddings Reveal (Almost) As Much As Text

John X. MorrisVolodymyr KuleshovVitaly ShmatikovAlexander M. Rush

article2023EMNLP286 citationsOutstanding Paper

Demonstrates that dense text embeddings fail to preserve privacy by introducing an iterative decoding method that reconstructs exact text inputs and extracts sensitive personal information from clinical records.

Listen

Modern artificial intelligence systems frequently convert sensitive text documents into numerical vectors, known as text embeddings, and store them in hosted vector databases for fast retrieval and search. Organizations often operate under the assumption that sending only embeddings—rather than raw source documents—to third-party database providers safeguards data privacy. The article investigates whether an adversary with black-box query access to an embedding model can invert these numerical representations and fully recover the original text, thereby exposing significant data security vulnerabilities.

The main objective of the article is to demonstrate and evaluate a controlled generation method that systematically reconstructs original, full-text sequences from dense text embeddings without requiring direct access to the underlying model's internal weights or gradients.

To achieve this, the authors developed Vec2Text, a multi-step framework based on an encoder-decoder transformer architecture. Instead of relying on a single guessing step, Vec2Text iteratively generates hypothesis text, computes the difference between the hypothesis vector and the target vector, and applies discrete corrections across multiple rounds. The researchers evaluated the approach using 5 million training passages across popular commercial and open-source models, including Google's GTR-base and OpenAI's text-embeddings-ada-002, and tested generalization across 15 standard information retrieval datasets and a pseudo-reidentified clinical database.

The findings reveal that dense text embeddings leak substantial amounts of original text. For short passages of 32 words or word pieces, Vec2Text successfully recovered 92% of inputs with an exact match and reached an average sequence similarity score of 97.3 out of 100 on standard Wikipedia data, outperforming basic non-iterative models which achieved 0% exact recovery. On clinical notes, the method extracted 89% of full patient names and recovered 26% of documents word-for-word. While longer text sequences presented greater reconstruction difficulty, the model consistently captured underlying semantic content across all tested domains. Furthermore, initial defense simulations showed that injecting small amounts of calibrated Gaussian noise into embeddings degraded text reconstruction by nearly 87% while reducing search performance by only about 2%.

These results demonstrate that numerical text embeddings create virtually the same privacy and compliance risks as raw plaintext data. Organizations can no longer assume that transmitting embeddings to external vector database vendors preserves confidentiality. A security breach of an embedding repository could lead to direct leaks of personally identifiable information, intellectual property, or confidential clinical records, posing severe legal and compliance hazards under data privacy frameworks.

Organizations handling sensitive text should immediately treat text embeddings with the same rigorous data governance, access controls, and encryption standards applied to raw text. Engineering teams utilizing third-party vector databases should consider evaluating lightweight noise-injection defenses to mitigate straightforward reconstruction attacks, balancing this against minor decreases in search accuracy. System architects must also monitor query access to embedding APIs, as the reconstruction technique relies on repeated queries to refine text hypotheses.

Confidence in these findings is high for short-to-moderate text inputs up to 32 tokens, supported by consistent performance across multiple datasets and embedding models. Readers should note certain boundaries: the evaluation assumed an adversary possessed query access to the exact embedding model used to create the vectors, tested sequences limited to 128 tokens, and did not examine adaptive attackers trained specifically to counteract noisy defenses. Further analysis is required to determine the feasibility of inverting multi-page documents and developing defenses that withstand adaptive reconstruction techniques.

Cover for Text Embeddings Reveal (Almost) As Much As Text

Abstract

How much private information do text embeddings reveal about the original text? We investigate the problem of embedding \textit{inversion}, reconstructing the full text represented in dense text embeddings. We frame the problem as controlled generation: generating text that, when reembedded, is close to a fixed point in latent space. We find that although a naïve model conditioned on the embedding performs poorly, a multi-step method that iteratively corrects and re-embeds text is able to recover 92%92\% of 32-token32\text{-token} text inputs exactly. We train our model to decode text embeddings from two state-of-the-art embedding models, and also show that our model can recover important personal information (full names) from a dataset of clinical notes. Our code is available on Github: \href{this https URL}{this http URL}.

Table of Contents

  • 1 Introduction
  • 2 Overview: Embedding Inversion
  • 3 Method: Vec2Text
  • 3.1 Base Model: Learning to Invert ϕ\phi
  • 3.2 Controlling Generation for Inversion
  • 4 Experimental Setup
  • 5 Results
  • 5.1 Reconstruction: In-Domain
  • 5.2 Reconstruction: Out-of-Domain
  • 5.3 Case study: MIMIC
  • 6 Defending against inversion attacks
  • 7 Analysis
  • 8 Related work
  • 9 Conclusion
  • 10 Limitations
  • References
  • A Appendix
  • A.1 Additional analysis
  • A.2 Full defense results

Knowls

  1. Knowl 1 — Vec2Text Iterative Text Reconstruction Model

    model/method

    Vec2Text frames text embedding inversion as controlled generation, where an initial hypothesis text is iteratively refined by querying a black-box encoder ϕ\phi and predicting corrections conditioned on embedding discrepancies.

    The probability distribution of generating a text sequence x(t+1)x^{(t+1)} at refinement step t+1t+1 is defined recursively by marginalizing over intermediate sequence hypotheses:

    p(x(t+1)∣e)=∑x(t)p(x(t)∣e)p(x(t+1)∣e,x(t),e^(t))p(x^{(t+1)} \mid e) = \sum_{x^{(t)}} p(x^{(t)} \mid e) p(x^{(t+1)} \mid e, x^{(t)}, \hat{e}^{(t)})

    where e∈Rde \in \mathbb{R}^d is the target embedding, x(t)x^{(t)} is the hypothesis text at step tt, and e^(t)=ϕ(x(t))∈Rd\hat{e}^{(t)} = \phi(x^{(t)}) \in \mathbb{R}^d is the embedding of the current hypothesis obtained from the encoder ϕ\phi.

    The base case t=0t=0 generates an initial hypothesis x(0)x^{(0)} without prior text:

    p(x(0)∣e)=p(x(0)∣e,∅,ϕ(∅))p(x^{(0)} \mid e) = p(x^{(0)} \mid e, \emptyset, \phi(\emptyset))

    Training proceeds in two stages:

    1. A base conditional language model p(x(0)∣e)p(x^{(0)} \mid e) is trained on ground-truth text-embedding pairs (x,ϕ(x))(x, \phi(x)) via maximum likelihood.
    2. Initial hypotheses x(0)x^{(0)} are sampled from the base model for training texts xx, and their embeddings e^(0)=ϕ(x(0))\hat{e}^{(0)} = \phi(x^{(0)}) are computed. The self-correction encoder-decoder model p(x(t+1)∣e,x(t),e^(t))p(x^{(t+1)} \mid e, x^{(t)}, \hat{e}^{(t)}) is then trained with standard sequence-to-sequence cross-entropy loss to reconstruct ground-truth xx given (e,x(0),e^(0))(e, x^{(0)}, \hat{e}^{(0)}).
  2. Knowl 2 — In-Domain Reconstruction Performance on GTR-Base and OpenAI text-embeddings-ada-002

    data/table

    Text reconstruction performance of Vec2Text evaluated on in-domain test sets against baseline inversion models. Models are evaluated on 32-token Wikipedia text embedded with GTR-base (235M parameter T5-based model), and MSMARCO text (up to 32 or 128 tokens) embedded with OpenAI text-embeddings-ada-002.

    Metrics include BLEU score, Token F1 (tf1), Exact Match percentage (exact), and Cosine Similarity (cos) between the ground-truth embedding and the embedding of the reconstructed text.

    Target Model Dataset Method Tokens BLEU Token F1 Exact (%) Cosine Sim
    GTR-base Bag-of-words (Song Raghunathan, 2020) 32 0.3 51 0.0 0.70
    (Natural Questions) GPT-2 Decoder (Li et al., 2023) 32 1.0 47 0.0 0.76
    Base [0 steps] 32 31.9 67 0.0 0.91
    Base (+ beam search) 32 34.5 67 1.0 0.92
    Base (+ nucleus p=0.9p=0.9) 32 25.3 60 0.0 0.88
    Vec2Text [1 step] 32 50.7 80 0.0 0.96
    Vec2Text [20 steps] 32 83.9 96 40.2 0.99
    Vec2Text [50 steps] 32 85.4 97 40.6 0.99
    Vec2Text [50 steps + sbeam] 32 97.3 99 92.0 0.99
    OpenAI ada-002 Base [0 steps] 31.8 26.2 61 0.0 0.94
    (MSMARCO 32 tokens) Vec2Text [1 step] 31.8 44.1 77 5.2 0.96
    Vec2Text [20 steps] 31.8 61.9 87 15.0 0.98
    Vec2Text [50 steps] 31.8 62.3 87 14.8 0.98
    Vec2Text [50 steps + sbeam] 31.8 83.4 96 60.9 0.99
    OpenAI ada-002 Base [0 steps] 80.9 17.0 54 0.6 0.95
    (MSMARCO 128 tokens) Vec2Text [1 step] 80.9 29.9 68 1.4 0.97
    Vec2Text [20 steps] 80.9 43.1 78 3.2 0.99
    Vec2Text [50 steps] 80.9 44.4 78 3.4 0.99
    Vec2Text [50 steps + sbeam] 80.9 55.0 84 8.0 0.99

    Iterative correction substantially outperforms unconditioned and single-step baselines. Applying sequence-level beam search (sbeam) over 50 correction steps increases exact match recovery from 40.6% to 92.0% on GTR-base (32 tokens) and from 14.8% to 60.9% on OpenAI text-embeddings-ada-002 (32 tokens).

  3. Knowl 3 — Sequence-Level Beam Search Algorithm for Vec2Text Inversion

    algorithm

    To infer reconstructed text from target embedding ee without exhaustively marginalizing over intermediate text trajectories, Vec2Text combines greedy token decoding with sequence-level beam search over refinement steps.

    Input: Target embedding e∈Rde \in \mathbb{R}^d, black-box embedding model ϕ\phi, base generator p(x(0)∣e)p(x^{(0)} \mid e), corrective generator p(x′∣e,x,e^)p(x' \mid e, x, \hat{e}), beam width bb, maximum refinement steps TT
    Output: Reconstructed text sequence x^∗\hat{x}^*
    Initialize candidate beam B0B_0 with top-bb initial text hypotheses decoded greedily from p(x(0)∣e)p(x^{(0)} \mid e)
    for each candidate x∈B0x \in B_0:
        e^←ϕ(x)\hat{e} \leftarrow \phi(x)
        s(x)←cos⁡(e^,e)s(x) \leftarrow \cos(\hat{e}, e)
    for step t=1t = 1 to TT:
        C←∅C \leftarrow \emptyset
        for each hypothesis x∈Bt−1x \in B_{t-1}:
            e^←ϕ(x)\hat{e} \leftarrow \phi(x)
            decode top-bb continuation hypotheses x1′,…,xb′x'_1, \dots, x'_b from p(x′∣e,x,e^)p(x' \mid e, x, \hat{e}) using greedy token decoding
            for each continuation x′x' in x1′,…,xb′x'_1, \dots, x'_b:
                e^′←ϕ(x′)\hat{e}' \leftarrow \phi(x')
                s(x′)←cos⁡(e^′,e)s(x') \leftarrow \cos(\hat{e}', e)
                if s(x′)>s(x)s(x') > s(x):
                    C←C∪{x′}C \leftarrow C \cup \{x'\}
                else:
                    C←C∪{x}C \leftarrow C \cup \{x\}
        Bt←B_t \leftarrow select top-bb unique sequences from CC ranked by score s(⋅)s(\cdot) descending
    x^∗←arg⁡max⁡x∈BTs(x)\hat{x}^* \leftarrow \arg\max_{x \in B_T} s(x)
    return x^∗\hat{x}^*
  4. Knowl 4 — Embedding Conditioning via Multi-Vector Projection (EmbToSeq)

    model/method

    To condition a standard encoder-decoder Transformer on dense embedding vectors, Vec2Text maps continuous embedding vectors into pseudo-token sequence representations compatible with the Transformer encoder hidden dimension dencd_{\text{enc}}.

    For an embedding vector v∈Rdv \in \mathbb{R}^d, the projection module EmbToSeq(v)\text{EmbToSeq}(v) is defined as:

    EmbToSeq(v)=W2σ(W1v)\text{EmbToSeq}(v) = W_2 \sigma(W_1 v)

    where W1∈Rd×dW_1 \in \mathbb{R}^{d \times d}, W2∈R(s⋅denc)×dW_2 \in \mathbb{R}^{(s \cdot d_{\text{enc}}) \times d}, σ\sigma is a non-linear activation function, and ss is a sequence length hyperparameter (set to s=16s = 16). The resulting vector in Rs⋅denc\mathbb{R}^{s \cdot d_{\text{enc}}} is reshaped into a sequence of ss vectors in Rdenc\mathbb{R}^{d_{\text{enc}}}.

    At refinement step tt, the Transformer encoder receives a concatenated sequence composed of three projected embedding vectors and the token embeddings of the hypothesis text x(t)=(w1,…,wn)x^{(t)} = (w_1, \dots, w_n):

    Input=[EmbToSeq(e) ; EmbToSeq(e^(t)) ; EmbToSeq(e−e^(t)) ; (w1,…,wn)]\text{Input} = \left[ \text{EmbToSeq}(e) \,;\, \text{EmbToSeq}(\hat{e}^{(t)}) \,;\, \text{EmbToSeq}(e - \hat{e}^{(t)}) \,;\, (w_1, \dots, w_n) \right]

    where ee is the target embedding, e^(t)=ϕ(x(t))\hat{e}^{(t)} = \phi(x^{(t)}) is the hypothesis embedding, and e−e^(t)e - \hat{e}^{(t)} is the difference vector. The total sequence length fed to the encoder is 3s+n3s + n.

  5. Knowl 5 — Extraction of Personally Identifiable Information from Clinical Note Embeddings

    data/table

    Evaluation of privacy leakage on pseudo re-identified clinical notes from the MIMIC-III database. Notes are truncated to 32 tokens and filtered to include at least one name. Notes are embedded with GTR-base and reconstructed using Vec2Text (50 steps with sequence beam search) versus the uncorrected Base model.

    Method First Name (%) Last Name (%) Full Name (%) BLEU Token F1 Exact (%) Cosine Sim
    Base [0 steps] 40.0 27.8 10.8 4.9 33.1 0.0 0.78
    Vec2Text 94.2 95.3 89.2 55.6 80.8 26.0 0.98

    Vec2Text recovers 89.2% of complete personal names (first and last name format) and reconstructs 26.0% of the 32-token clinical documents exactly. Entity analysis shows the highest recovery rate for generic clinical events (such as 'arrived', 'progress', 'transferred') and lower recovery for detailed clinical descriptions (such as 'posterior', 'hypoxic', or complex procedural descriptions).

  6. Knowl 6 — Zero-Shot Cross-Domain Inversion on the BEIR Benchmark

    empirical result

    When evaluated zero-shot across 15 retrieval corpora from the BEIR benchmark without domain-specific fine-tuning (using Vec2Text trained on 128-token MSMARCO embeddings from OpenAI text-embeddings-ada-002), reconstruction accuracy is strongly correlated with text length:

    • Short texts: On Quora (average length 15.7 tokens), Vec2Text achieves 95.5 BLEU, 98.6 Token F1, and 66.0% exact match (vs. Base at 36.2 BLEU, 73.8 Token F1). On Signal-1M (average length 23.7 tokens), Vec2Text achieves 80.7 BLEU and 92.5 Token F1 (vs. Base at 13.2 BLEU, 49.5 Token F1).
    • Medium-length texts (70–100 tokens): On MSMARCO (72.1 tokens), BLEU is 59.6 with 86.1 Token F1; on Climate-FEVER (73.4 tokens), BLEU is 44.9 with 82.6 Token F1; on HotpotQA (94.8 tokens), BLEU is 46.6 with 78.7 Token F1.
    • Long texts (100–128 tokens): On longer corpora including SCIDOCS (125.3 tokens, 17.7 BLEU, 57.6 F1), TREC-COVID (125.4 tokens, 19.3 BLEU, 58.6 F1), Robust04 (127.3 tokens, 15.5 BLEU, 54.5 F1), and NFCorpus (127.7 tokens, 25.8 BLEU, 64.8 F1), the model consistently achieves Token F1 ≥51.5\ge 51.5 and embedding cosine similarity ≥0.95\ge 0.95.

    Across all 15 datasets, Vec2Text outputs match the true sequence lengths with an average error of fewer than 3 tokens.

  7. Knowl 7 — Defense via Gaussian Noise Injection and Retrieval-Inversion Trade-off

    data/table

    To defend against embedding inversion while preserving nearest-neighbor retrieval utility, isotropic Gaussian noise is added to embeddings:

    ϕnoisy(x)=ϕ(x)+λ⋅ϵ,ϵ∼N(0,I)\phi_{\text{noisy}}(x) = \phi(x) + \lambda \cdot \epsilon, \quad \epsilon \sim \mathcal{N}(0, I)

    where λ≥0\lambda \ge 0 is the noise scale parameter.

    The defense is evaluated on GTR-base embeddings across 15 BEIR retrieval benchmark datasets (32 tokens per text) using Vec2Text with 10 correction steps. Retrieval utility is measured by mean NDCG@10 across all 15 datasets, and inversion vulnerability is measured by reconstruction BLEU.

    Noise Level (λ\lambda) Retrieval Utility (Mean NDCG@10) Reconstruction Accuracy (BLEU)
    0.000 0.302 80.372
    0.001 0.302 72.347
    0.010 0.296 10.334
    0.100 0.002 0.148
    1.000 0.001 0.080

    At λ=0.01\lambda = 0.01, retrieval performance is minimally affected (dropping by 2.0% from 0.302 to 0.296), whereas inversion reconstruction accuracy drops by 87.1% (from 80.372 to 10.334 BLEU). Increasing noise to λ≥0.1\lambda \ge 0.1 causes both retrieval utility and reconstruction accuracy to collapse to near zero.

  8. Knowl 8 — Necessity of Embedding Feedback and Robustness to Arbitrary Initialization

    data/table

    Ablations on 32-token Wikipedia text embedded with GTR-base isolate the role of encoder feedback and text initialization in Vec2Text:

    1. Feedback vs. No Feedback: A model trained to edit text iteratively without conditioning on hypothesis embeddings ϕ(x(t))\phi(x^{(t)}) plateaus at 44 BLEU and achieves only 4.2% exact matches after 50 greedy correction rounds. In contrast, Vec2Text with feedback conditioning achieves >80 BLEU and 52.0% exact match under greedy decoding.
    2. Initialization Invariance: When running Vec2Text for 20 correction steps starting from uninformative initial hypotheses x(0)x^{(0)}, reconstruction quality is largely independent of initialization:
    Initialization Hypothesis x(0)x^{(0)} Token F1 Cosine Sim Exact Match (%)
    Random token sequence 0.95 0.99 50.0
    Constant sequence: "the " * 32 0.95 0.99 49.8
    Unrelated fixed sentence 0.96 0.99 52.0
    Base model prediction p(x(0)∣e)p(x^{(0)} \mid e) 0.96 0.99 51.6

    All initializations attain ≥80\ge 80 BLEU, ≥0.95\ge 0.95 Token F1, and ∼50%\sim 50\% exact match after 20 steps, demonstrating that the model corrects trajectory primarily using the embedding difference vectors rather than initial text tokens.

  9. Knowl 9 — Text Embedding Inversion Threat Model and Optimization Objective

    assumption

    The text embedding inversion problem considers a black-box text encoder ϕ:Vn→Rd\phi: \mathcal{V}^n \to \mathbb{R}^d mapping a token sequence x∈Vnx \in \mathcal{V}^n of length nn over vocabulary V\mathcal{V} to a fixed-dimensional dense vector e=ϕ(x)∈Rde = \phi(x) \in \mathbb{R}^d.

    An attacker possesses a target embedding e∈Rde \in \mathbb{R}^d and query access to ϕ\phi, allowing the attacker to compute ϕ(x^)\phi(\hat{x}) and cosine similarity cos⁡(ϕ(x^),e)=ϕ(x^)⊤e∥ϕ(x^)∥2∥e∥2\cos(\phi(\hat{x}), e) = \frac{\phi(\hat{x})^\top e}{\|\phi(\hat{x})\|_2 \|e\|_2} for any generated hypothesis text x^\hat{x}. The attacker has a dataset of text-embedding pairs from ϕ\phi to train inversion models, but does not have access to encoder weights or internal gradients.

    The inversion objective is formulated as combinatorial optimization:

    x^=arg⁡max⁡x∈Vncos⁡(ϕ(x),e)\hat{x} = \arg\max_{x \in \mathcal{V}^n} \cos(\phi(x), e)

    It is assumed that embedding collisions (distinct texts mapping to identical embeddings) are sufficiently rare that obtaining cos⁡(ϕ(x^),e)=1\cos(\phi(\hat{x}), e) = 1 implies exact recovery of the original ground-truth sequence xx.

  10. Knowl 10 — Limitations of Vec2Text Inversion

    limitation

    The Vec2Text inversion methodology exhibits four key limitations:

    1. Sequence Length Scalability: While Vec2Text recovers 92% of 32-token sequences exactly, exact recovery drops to 8% for 128-token texts. Modern embedding models support contexts of several thousand tokens, where the limits of invertibility remain untested.
    2. Query Inefficiency: Refinement requires repeated black-box API calls to ϕ\phi for each candidate generated at every search step, resulting in hundreds of queries per target embedding during beam search.
    3. Non-Adaptive Defense Evaluation: The Gaussian noise defense was evaluated against an inversion model trained exclusively on clean embeddings; noise-aware adaptive inversion training was not evaluated.
    4. Bounded Search Budget: Experiments were capped at 50 refinement rounds and sequence beam width b=8b=8, leaving unexplored whether larger search budgets or advanced heuristic search algorithms could yield higher exact recovery on longer documents.

Coverage note — None omitted; all core contributions, model architectures, algorithms, experimental evaluations (NQ, MSMARCO, BEIR, MIMIC-III), defenses, ablations, and limitations are fully covered.

References

  1. 1.Mohamed Abdalla, Moustafa Abdalla, Graeme Hirst, and Frank Rudzicz. 2020. Exploring the privacy-preserving properties of word embeddings: Algorithmic validation study. J Med Internet Res, 22(7):e18055.
  2. 2.Leonard Adolphs, Michelle Chen Huebscher, Christian Buck, Sertan Girgin, Olivier Bachem, Massimiliano Ciaramita, and Thomas Hofmann. 2022. Decoding a neural retriever's latent space for query suggestion.
  3. 3.Charu C. Aggarwal and ChengXiang Zhai. 2012. A Survey of Text Clustering Algorithms, pages 77–128. Springer US, Boston, MA.
  4. 4.Payal Bajaj, Daniel Campos, Nick Craswell, Li Deng, Jianfeng Gao, Xiaodong Liu, Rangan Majumder, Andrew McNamara, Bhaskar Mitra, Tri Nguyen, Mir Rosenberg, Xia Song, Alina Stoica, Saurabh Tiwary, and Tong Wang. 2018. Ms marco: A human generated machine reading comprehension dataset.
  5. 5.Florian Bordes, Randall Balestriero, and Pascal Vincent. 2021. High fidelity visualization of what your self-supervised representation knows about. Trans. Mach. Learn. Res., 2022.
  6. 6.Sebastian Borgeaud, Arthur Mensch, Jordan Hoffmann, Trevor Cai, Eliza Rutherford, Katie Millican, George van den Driessche, Jean-Baptiste Lespiau, Bogdan Damoc, Aidan Clark, Diego de Las Casas, Aurelia Guy, Jacob Menick, Roman Ring, Tom Hennigan, Saffron Huang, Loren Maggiore, Chris Jones, Albin Cassirer, Andy Brock, Michela Paganini, Geoffrey Irving, Oriol Vinyals, Simon Osindero, Karen Simonyan, Jack W. Rae, Erich Elsen, and Laurent Sifre. 2022. Improving language models by retrieving from trillions of tokens.
  7. 7.Samuel R. Bowman, Luke Vilnis, Oriol Vinyals, Andrew M. Dai, Rafal Jozefowicz, and Samy Bengio. 2016. Generating sentences from a continuous space.
  8. 8.Sumanth Dathathri, Andrea Madotto, Janice Lan, Jane Hung, Eric Frank, Piero Molino, Jason Yosinski, and Rosanne Liu. 2020. Plug and play language models: A simple approach to controlled text generation. In International Conference on Learning Representations.
  9. 9.Alexey Dosovitskiy and Thomas Brox. 2016. Inverting visual representations with convolutional networks.
  10. 10.Chi Nhan Duong, Thanh-Dat Truong, Kha Gia Quach, Hung Bui, Kaushik Roy, and Khoa Luu. 2020. Vec2face: Unveil human faces from their blackbox features in face recognition.
  11. 11.Adam Dziedzic, Franziska Boenisch, Mingjian Jiang, Haonan Duan, and Nicolas Papernot. 2023. Sentence embedding encoders are easy to steal but hard to defend. In ICLR 2023 Workshop on Pitfalls of limited data and computation for Trustworthy ML.
  12. 12.Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, and Michael Moeller. 2020. Inverting gradients – how easy is it to break privacy in federated learning?
  13. 13.Marjan Ghazvininejad, Omer Levy, Yinhan Liu, and Luke Zettlemoyer. 2019. Mask-predict: Parallel decoding of conditional masked language models.
  14. 14.Zhiting Hu, Zichao Yang, Xiaodan Liang, Ruslan Salakhutdinov, and Eric P. Xing. 2018. Toward controlled generation of text.
  15. 15.Vineet John, Lili Mou, Hareesh Bahuleyan, and Olga Vechtomova. 2018. Disentangled representation learning for non-parallel text style transfer.
  16. 16.Alistair E.W. Johnson, Tom J. Pollard, Lu Shen, Li-wei H. Lehman, Mengling Feng, Mohammad Ghassemi, Benjamin Moody, Peter Szolovits, Leo Anthony Celi, and Roger G. Mark. 2016. Mimic-iii, a freely accessible critical care database. Scientific Data, 3(1):160035.
  17. 17.Vladimir Karpukhin, Barlas Oğuz, Sewon Min, Patrick Lewis, Ledell Wu, Sergey Edunov, Danqi Chen, and Wen tau Yih. 2020. Dense passage retrieval for opendomain question answering.
  18. 18.Donggyu Kim, Garam Lee, and Sungwoo Oh. 2022. Toward privacy-preserving text embedding similarity with homomorphic encryption. In Proceedings of the Fourth Workshop on Financial Technology and Natural Language Processing (FinNLP), pages 25–36, Abu Dhabi, United Arab Emirates (Hybrid). Association for Computational Linguistics.
  19. 19.Ryan Kiros, Yukun Zhu, Ruslan Salakhutdinov, Richard S. Zemel, Antonio Torralba, Raquel Urtasun, and Sanja Fidler. 2015. Skip-thought vectors.
  20. 20.Tom Kwiatkowski, Jennimaria Palomaki, Olivia Redfield, Michael Collins, Ankur Parikh, Chris Alberti, Danielle Epstein, Illia Polosukhin, Jacob Devlin, Kenton Lee, Kristina Toutanova, Llion Jones, Matthew Kelcey, Ming-Wei Chang, Andrew M. Dai, Jakob Uszkoreit, Quoc Le, and Slav Petrov. 2019. Natural questions: A benchmark for question answering research. Transactions of the Association for Computational Linguistics, 7:452–466.
  21. 21.LangChain. 2023. Hwchase17/langchain: building applications with llms through composability.
  22. 22.Quoc V. Le and Tomas Mikolov. 2014. Distributed representations of sentences and documents.
  23. 23.Jason Lee, Elman Mansimov, and Kyunghyun Cho. 2018. Deterministic non-autoregressive neural sequence modeling by iterative refinement.
  24. 24.Eric Lehman, Sarthak Jain, Karl Pichotta, Yoav Goldberg, and Byron C. Wallace. 2021. Does bert pretrained on clinical notes reveal sensitive data?
  25. 25.Haoran Li, Mingshi Xu, and Yangqiu Song. 2023. Sentence embedding leaks more information than you expect: Generative embedding inversion attack to recover the whole sentence.
  26. 26.Xiang Lisa Li, John Thickstun, Ishaan Gulrajani, Percy Liang, and Tatsunori B. Hashimoto. 2022. Diffusion-lm improves controllable text generation.
  27. 27.Aravindh Mahendran and Andrea Vedaldi. 2014. Understanding deep image representations by inverting them. 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pages 5188–5196.
  28. 28.Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2018. Exploiting unintended feature leakage in collaborative learning.
  29. 29.Tomas Mikolov, Kai Chen, Greg Corrado, and Jeffrey Dean. 2013. Efficient estimation of word representations in vector space.
  30. 30.Ron Mokady, Amir Hertz, and Amit H. Bermano. 2021. Clipcap: Clip prefix for image captioning.
  31. 31.John X. Morris. 2020. Second-order nlp adversarial examples.
  32. 32.Niklas Muennighoff, Nouamane Tazi, Loïc Magne, and Nils Reimers. 2023. Mteb: Massive text embedding benchmark.
  33. 33.Arvind Neelakantan, Tao Xu, Raul Puri, Alec Radford, Jesse Michael Han, Jerry Tworek, Qiming Yuan, Nikolas Tezak, Jong Wook Kim, Chris Hallacy, Johannes Heidecke, Pranav Shyam, Boris Power, Tyna Eloundou Nekoul, Girish Sastry, Gretchen Krueger, David Schnurr, Felipe Petroski Such, Kenny Hsu, Madeleine Thompson, Tabarak Khan, Toki Sherbakov, Joanne Jang, Peter Welinder, and Lilian Weng. 2022. Text and code embeddings by contrastive pre-training.
  34. 34.Jianmo Ni, Chen Qu, Jing Lu, Zhuyun Dai, Gustavo Hernández Ábrego, Ji Ma, Vincent Y. Zhao, Yi Luan, Keith B. Hall, Ming-Wei Chang, and Yinfei Yang. 2021. Large dual encoders are generalizable retrievers.
  35. 35.Kishore Papineni, Salim Roukos, Todd Ward, and Wei-Jing Zhu. 2002. Bleu: a method for automatic evaluation of machine translation. In Proceedings of the 40th Annual Meeting of the Association for Computational Linguistics, pages 311–318, Philadelphia, Pennsylvania, USA. Association for Computational Linguistics.
  36. 36.Pinecone. 2023. Pinecone.
  37. 37.Qdrant. 2023. Qdrant - vector database.
  38. 38.Colin Raffel, Noam Shazeer, Adam Roberts, Katherine Lee, Sharan Narang, Michael Matena, Yanqi Zhou, Wei Li, and Peter J. Liu. 2020. Exploring the limits of transfer learning with a unified text-to-text transformer.
  39. 39.Ori Ram, Liat Bezalel, Adi Zicher, Yonatan Belinkov, Jonathan Berant, and Amir Globerson. 2023. What are you token about? dense retrieval as distributions over the vocabulary.
  40. 40.Shaina Raza, Deepak John Reji, Femi Shajan, and Syed Raza Bashir. 2022. Large-scale application of named entity recognition to biomedicine and epidemiology. PLOS Digital Health, 1(12):e0000152.
  41. 41.Tao Shen, Xiubo Geng, Chongyang Tao, Can Xu, Xiaolong Huang, Binxing Jiao, Linjun Yang, and Daxin Jiang. 2023. Lexmae: Lexicon-bottlenecked pretraining for large-scale retrieval.
  42. 42.Congzheng Song and Ananth Raghunathan. 2020. Information leakage in embedding models. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security.
  43. 43.Congzheng Song, Alexander M. Rush, and Vitaly Shmatikov. 2020. Adversarial semantic collisions.
  44. 44.Piotr Teterwak, Chiyuan Zhang, Dilip Krishnan, and Michael C. Mozer. 2021. Understanding invariance via feedforward inversion of discriminatively trained classifiers.
  45. 45.Nandan Thakur, Nils Reimers, Andreas Rücklé, Abhishek Srivastava, and Iryna Gurevych. 2021. Beir: A heterogenous benchmark for zero-shot evaluation of information retrieval models.
  46. 46.Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, Lukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need.
  47. 47.Vdaas. 2023. Vdaas/vald: Vald. a highly scalable distributed vector search engine.
  48. 48.Liang Wang, Nan Yang, Xiaolong Huang, Binxing Jiao, Linjun Yang, Daxin Jiang, Rangan Majumder, and Furu Wei. 2023. Simlm: Pre-training with representation bottleneck for dense passage retrieval.
  49. 49.Weaviate. 2023. Weaviate - vector database.
  50. 50.Sean Welleck, Ximing Lu, Peter West, Faeze Brahman, Tianxiao Shen, Daniel Khashabi, and Yejin Choi. 2022. Generating sequences by learning to self-correct.
  51. 51.Shitao Xiao, Zheng Liu, Yingxia Shao, and Zhao Cao. 2022. Retromae: Pre-training retrieval-oriented language models via masked auto-encoder.
  52. 52.Kevin Yang and Dan Klein. 2021. FUDGE: Controlled text generation with future discriminators. In Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. Association for Computational Linguistics.
  53. 53.Shunyu Yao, Jeffrey Zhao, Dian Yu, Nan Du, Izhak Shafran, Karthik Narasimhan, and Yuan Cao. 2023. React: Synergizing reasoning and acting in language models.
  54. 54.Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. 2020. idlg: Improved deep leakage from gradients.
  55. 55.Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients.

Citation

MLA
Morris, J., et al. “Text Embeddings Reveal (Almost) As Much As Text”. Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, 2023, pp. 12448–60, https://doi.org/10.18653/v1/2023.emnlp-main.765.
APA
Morris, J., Kuleshov, V., Shmatikov, V., & Rush, A. M. (2023). Text Embeddings Reveal (Almost) As Much As Text. Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, 12448–12460. https://doi.org/10.18653/v1/2023.emnlp-main.765
Chicago
Morris, J., V. Kuleshov, V. Shmatikov, and A. M. Rush. 2023. “Text Embeddings Reveal (Almost) As Much As Text”. Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, 12448–60. https://doi.org/10.18653/v1/2023.emnlp-main.765.
Harvard
Morris, J. et al. (2023) “Text Embeddings Reveal (Almost) As Much As Text”, Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing. Association for Computational Linguistics, pp. 12448–12460. Available at: https://doi.org/10.18653/v1/2023.emnlp-main.765.
Vancouver
1. Morris J, Kuleshov V, Shmatikov V, Rush AM (2023) Text Embeddings Reveal (Almost) As Much As Text. In: Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing. Association for Computational Linguistics, pp 12448–12460

BibTeX

@inproceedings{morris-etal-2023-text,
    title = "Text Embeddings Reveal (Almost) As Much As Text",
    author = "Morris, John  and
      Kuleshov, Volodymyr  and
      Shmatikov, Vitaly  and
      Rush, Alexander",
    editor = "Bouamor, Houda  and
      Pino, Juan  and
      Bali, Kalika",
    booktitle = "Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing",
    month = dec,
    year = "2023",
    address = "Singapore",
    publisher = "Association for Computational Linguistics",
    url = "https://aclanthology.org/2023.emnlp-main.765/",
    doi = "10.18653/v1/2023.emnlp-main.765",
    pages = "12448--12460"
}
Metadata:ACL Anthology

Source Code

This paper has an official code repository available. Click below to access the source code.

View Repository

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: https://creativecommons.org/licenses/by/4.0/