USENIX Security2025Top-tier venue
Unlocking the Power of Differentially Private Zeroth-order Optimization for Fine-tuning LLMs
Ergute Bao, Yangfan Jiang, Fei Wei, Xiaokui Xiao, Zitao Li, Yaliang Li, Bolin Ding
Abstract
Differentially private zeroth-order optimization (DPZO in short) has shown promise in fine-tuning large language models (LLMs) while protecting record-level privacy. Compared with classical first-order methods, such as DPSGD, the main difference is that DPZO replaces the exact first-order gradients that are computed via back-propagation with its random zeroth-order approximations that are computed via querying the model's losses. However, DPZO still lags in the resulting model utility compared to existing methods, indicating that further work is needed to fully realize its potential. In this paper, we make a solid step towards designing a better differentially private algorithm for fine-tuning LLMs based on zeroth-order optimization. Our design is centered around the major performance issue of differentially private optimization for large models caused by artificial clipping, which creates biases in the model updates. Using our method called DP-AggZO, we theoretically prove that this issue can be mitigated, leading to an improved convergence rate over the prior DPZO methods and better model utility under the same privacy constraints. We back up our theory with extensive experiments, validating the performance improvement of DP-AggZO. Surprisingly, our DP-AggZO even outperforms the state-of-the-art method DP-AdamW significantly on some benchmark settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2b678536-8ad5-4d9b-aafe-52e8214a9891Cited by top-tier papers2
- Private Direct Preference Optimization for LLM AlignmentYangfan Jiang, Fei Wei, Ergute Bao, Xiaokui Xiao et al.CCS 2026
- Privacy Amplification in Differentially Private Zeroth-Order Optimization with Hidden StatesEli Chien, Wei-Ning Chen, Pan LiICML 2026
Builds on58
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
Related papers
- DPZero: Private Fine-Tuning of Language Models without BackpropagationLiang Zhang, Bingcong Li, Kiran Koshy Thekumparampil, Sewoong Oh et al.ICML 2024 · 27 citations
- On the Convergence of Zeroth-Order Federated Tuning for Large Language ModelsZhenqing Ling, Daoyuan Chen, Liuyi Yao, Yaliang Li et al.KDD 2024 · 17 citations
- Global Adaptive Momentum Meets Local Personalized Perturbation: Efficient Federated LLM Fine-Tuning with Zeroth-Order GradientsZihan Chen, Howard Hao Yang, Tony Q. S. Quek, Kai Fong Ernest ChongACL 2026
- LOZO+: Provably Efficient Zeroth-Order Fine-Tuning via Greedy Low-Rank Subspace SelectionJinjie Fang, Chengxun Jin, Tianxing Man, Yi Chang et al.ICML 2026
- Zeroth-Order Fine-Tuning of LLMs in Random SubspacesZiming Yu, Pan Zhou, Sike Wang, Jia Li et al.ICCV 2025 · 3 citations
