提出隐私保护微调框架,平衡模型性能、隐私与成本。
Navigating the Designs of Privacy-Preserving Fine-tuning for Large Language Models
- 结合系统架构与隐私增强技术,设计多版本微调方案。
- 在防止数据重建攻击的同时,保持良好微调效果。
- 适合关注隐私与成本的AI模型部署者使用。
指令微调已证明能有效提升大语言模型在下游任务中的表现。然而,实际微调面临模型方知识产权保护、客户数据隐私需求与调优成本之间的固有矛盾。尽管分裂学习和离线微调等方法展示了隐私保护微调的潜力,但现有工作缺乏对多样化实际部署中多维度权衡的系统性应对。本文提出一系列指示性评估指标,用于指导隐私保护微调的设计权衡,并构建了一系列示例性设计,统称为GuardedTuning;这些设计源于系统架构与适配的隐私增强方法及新兴计算技术的创新组合。每个设计在模型效用、隐私保障与成本之间代表不同的权衡。实验结果表明,这些设计在抵御数据重构攻击的同时,仍保持具有竞争力的微调性能。
原文摘要 · Abstract (English)
Instruction tuning has proven effective in enhancing Large Language Models' (LLMs) performance on downstream tasks. However, real-world fine-tuning faces inherent conflicts between model providers' intellectual property protection, clients' data privacy requirements, and tuning costs. While recent approaches like split learning and offsite tuning demonstrate promising architectures for privacy-preserving fine-tuning, there is a gap in systematically addressing the multidimensional trade-offs required for diverse real-world deployments. We propose several indicative evaluation metrics to guide design trade-offs for privacy-preserving fine-tuning and a series of example designs, collectively named GuardedTuning; they result from novel combinations of system architectures with adapted privacy-enhancement methods and emerging computation techniques. Each design represents distinct trade-offs across model utility, privacy guarantees, and costs. Experimental results demonstrate that these designs protect against data reconstruction attacks while maintaining competitive fine-tuning performance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。