Memorization for Good: Encryption with Autoregressive Language Models
Samuel Stevens, Yu Su
OpenReview ground truth
TL;DR — We propose SELM, a novel symmetric encryption algorithm based on pre-trained language models' memorization capabilities
Abstract
Over-parameterized neural language models (LMs) can memorize and recite long sequences of training data. While such memorization is normally associated with undesired properties such as overfitting and information leaking, our work casts memorization as an unexplored capability of LMs. We propose the first symmetric encryption algorithm with autoregressive language models (SELM). We show that autoregressive LMs can encode arbitrary data into a compact real-valued vector (i.e., encryption) and then losslessly decode the vector to the original message (i.e., decryption) via random subspace optimization and greedy decoding. While SELM is not amenable to conventional cryptanalysis, we investigate its security through a novel empirical variant of the classic IND-CPA (indistinguishability under chosen-plaintext attack) game.
Author context
Most prolific author: 8 submissions (credibility 1.00).
No mass-submission penalty for this paper (authors within normal submission volume).
Aggregate statistics only — no individual author rankings.
Ranking trajectory
Percentile by tournament round — convergence indicates rating stability.
Battle history — 30 comparisons
Ranked above opponent in 43% of matchups.
- ▼ lost to PromptAgent: Strategic Planning with Langu… ×4
- ▼ lost to Reinforced UI Instruction Grounding: Towar… ×4
- ▲ beat TIGERScore: Building Explainable Metric fo… ×4
- ▲ beat PPTSER: A Plug-and-Play Tag-guided Method … ×4
- ▲ beat On Trajectory Augmentations for Off-Policy… ×4
Judge assessments
Mean overall score 0.0 ± 0.0 (n = 30)