arXiv:2601.21719cs.LGstat.ML2026-01被引 1

随机投影可提升模型隐私,但需加噪才有效

LoRA and Privacy: When Random Projections Help (and When They Don't)

  • 用威沙特分布随机投影实现无加噪差分隐私
  • 无噪时矩阵查询易遭近完美成员推断攻击(AUC>0.99)
  • LoRA微调虽有随机性,但需额外加噪才更私密

我们提出威沙特投影机制,形式为 $S \mapsto M f(S)$,其中 $M \sim W_d(1/r I_d, r)$,并研究其差分隐私性质。对于向量查询,无需添加噪声即可获得非渐近的差分隐私保证;但对于矩阵查询,在无噪情况下该机制不满足差分隐私,且实验证明可实施近乎完美的成员推断攻击(AUC > 0.99)。随后分析带噪变体,证明随机性与低秩投影共同带来隐私放大效应,无论大秩或小秩情形均优于仅靠加噪。最后表明LoRA式更新是矩阵机制的实例,说明其本身并非固有私密,但低秩微调在同等噪声水平下比全参数微调更具隐私优势。初步实验显示更紧的隐私会计可降低噪声并提升精度。

原文摘要 · Abstract (English)

We introduce the (Wishart) projection mechanism, a randomized map of the form $S \mapsto M f(S)$ with $M \sim W_d(1/r I_d, r)$ and study its differential privacy properties. For vector-valued queries $f$, we prove non-asymptotic DP guarantees without any additive noise, showing that Wishart randomness alone can suffice. For matrix-valued queries, however, we establish a sharp negative result: in the noise-free setting, the mechanism is not DP, and we demonstrate its vulnerability by implementing a near perfect membership inference attack (AUC $> 0.99$). We then analyze a noisy variant and prove privacy amplification due to randomness and low rank projection, in both large- and small-rank regimes, yielding stronger privacy guarantees than additive noise alone. Finally, we show that LoRA-style updates are an instance of the matrix-valued mechanism, implying that LoRA is not inherently private despite its built-in randomness, but that low-rank fine-tuning can be more private than full fine-tuning at the same noise level. Preliminary experiments suggest that tighter accounting enables lower noise and improved accuracy in practice.

差分隐私低秩微调成员推断攻击随机投影

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。