PISA: Privacy-Preserving Split Adaptation with Model IP Protection
Haocheng Yang, Xiang Cheng, ZONGDA HAN, Pengjie Wang, Changkang Chi, Pengfei Zhang, Sen Su
Abstract
Fine-tuning Large Language Models (LLMs) enables data holders to construct proprietary, task-specific models by leveraging external high-performance computing infrastructure. However, existing paradigms typically address data privacy and model intellectual property (IP) in isolation, failing to simultaneously uphold both constraints. Privacy-prioritized methods compromise model IP by hosting parameters remotely, while IP-oriented collaborative schemes relying on end-to-end gradient flows inherently violate strict data privacy standards. To address these challenges, we present PISA ( P rivacy-preserving and I P-protected S plit A daptation), a split fine-tuning framework designed to preserve both data privacy and model IP while maintaining high utility. In PISA, we propose three methods: a Manifold Rectification Pre-training (MRP) method to equip the server-side model with intrinsic robustness against privacy-induced distribution shifts; a Dual-Stream Semantic Compensation (DSC) method to recover feature utility using local clean data as priors; and a Utility-Aware Gradient Rectification (UGR) method to adaptively maximize the performance of the parameter-constrained local model. Experiments on GLUE show that PISA ensures dual protection and delivers a substantial 23.0% performance gain over the privacy-prioritized baseline under strict privacy budgets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7d4ad63c-651e-4e9d-ab32-da49007d6eb9Builds on8
- DP-Forward: Fine-tuning and Inference on Language Models with Differential Privacy in Forward PassMinxin Du, Xiang Yue, Sherman S. M. Chow, Tianhao Wang et al.CCS 2023 · 35 citations
- Initialization Matters: Privacy-Utility Analysis of Overparameterized Neural NetworksJiayuan Ye, Zhenyu Zhu, Fanghui Liu, Reza Shokri et al.NeurIPS 2023 · 19 citations
- Unleashing the Tiger: Inference Attacks on Split LearningDario Pasquini, Giuseppe Ateniese, Massimo BernaschiCCS 2021 · 14 citations
- Can Watermarks be Used to Detect LLM IP Infringement For Free?Zhengyue Zhao, Xiaogeng Liu, Somesh Jha, Patrick McDaniel et al.ICLR 2025
- Split Adaptation for Pre-trained Vision TransformersLixu Wang, Bingqi Shang, Yi Li, Payal Mohapatra et al.CVPR 2025
Related papers
- From Prompts to Responses: Dual-Sided Data Leakage and Defense in Split Large Language ModelsZixuan GU, Xiaojun Ye, Yang LiuICML 2026
- Unveiling the Vulnerability of Private Fine-Tuning in Split-Based Frameworks for Large Language Models: A Bidirectionally Enhanced AttackGuanzhong Chen, Zhenghan Qin, Mingxin Yang, Yajie Zhou et al.CCS 2024 · 7 citations
- DualGuard: A Parameter Space Transformation Approach for Bidirectional Defense in Split-Based LLM Fine-TuningZihan Liu, Yizhen Wang, Rui Wang, Sai WuACL 2025
- Large Language Models Can Be Contextual Privacy Protection LearnersYijia Xiao, Yiqiao Jin, Yushi Bai, Yue Wu et al.EMNLP 2024 · 18 citations
- Towards Privacy-Preserving Large Language Model: Text-free Inference Through Alignment and AdaptationJeongho Yoon, Chanhee Park, Yongchan Chun, Hyeonseok Moon et al.ACL 2026
