Beyond Public Access in LLM Pre-Training Data: Non-public book content in OpenAI’s Models

📅 2025-04-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study investigates whether OpenAI’s large language models (GPT-4o, GPT-3.5 Turbo, GPT-4o Mini) incorporate copyrighted, non-public technical books from O’Reilly Media in their pretraining data without authorization. Method: We construct a controlled benchmark of 34 paid technical books and conduct the first systematic empirical analysis using membership inference attacks (DE-COP) coupled with AUROC-based evaluation. Contribution/Results: GPT-4o exhibits significant memorization of non-public copyrighted content (AUROC = 0.82), substantially outperforming GPT-3.5 Turbo; GPT-4o Mini shows no detectable memorization (AUROC ≈ 0.5), confirming a positive correlation between model scale and copyright risk. This work provides the first empirical evidence of substantial memorization of non-public copyrighted text in mainstream closed-source LLMs, delivering critical methodological and evidentiary foundations for assessing training data transparency, copyright compliance, and licensing frameworks.

Technology Category

Machine Learning: Large Multimodal Models (LMMs)Natural Language Processing: (Large) Language ModelsComputer Vision: Large Vision Models

Application Category

Web Mining and Content Analysis: Large pretrained models with web dataGraph Algorithms and Modeling for the Web: Foundation models and LLMs for Web-related graphsSecurity and Privacy: Data transparency and provenance
📝 Abstract
Using a legally obtained dataset of 34 copyrighted O’Reilly Media books, we apply the DE-COP membership inference attack method to investigate whether OpenAI’s large language models were trained on copyrighted content without consent. Our AUROC scores show that GPT-4o, OpenAI’s more recent and capable model, demonstrates strong recognition of paywalled O’Reilly book content (AUROC = 82%), compared to OpenAI’s earlier model GPT-3.5 Turbo. In contrast, GPT-3.5 Turbo shows greater relative recognition of publicly accessible O’Reilly book samples. GPT-4o Mini, as a much smaller model, shows no knowledge of public or non-public O’Reilly Media content when tested (AUROC ≈ 0.5). Testing multiple models, with the same cutoff date, helps us account for potential language shifts over time that might bias our findings. These results highlight the urgent need for increased corporate transparency regarding pre-training data sources as a means to develop formal licensing frameworks for AI content training.
Problem

Research questions and friction points this paper is trying to address.

Investigates if OpenAI models used copyrighted books without consent
Compares recognition of paywalled vs public content across GPT versions
Highlights need for transparency in AI training data sources
Innovation

Methods, ideas, or system contributions that make the work stand out.

Used DE-COP method for membership inference
Tested multiple OpenAI models for comparison
Analyzed AUROC scores for copyrighted content
🔎 Similar Papers