PRISM: Gauge-Invariant Tangent-Space Differentially Private LoRA
Shihao Wang, Xueru Zhang
Abstract
Applying differential privacy (DP) via DP-SGD to Low-Rank Adaptation (LoRA) is a natural approach for privacy-preserving fine-tuning. However, applying DP-SGD to LoRA poses a fundamental challenge due to its low-rank parameterization. In LoRA, each trainable update is represented as a low-rank matrix , but this factorization is non-identifiable. As a result, applying DP-SGD directly to factors induces gauge-dependent perturbations on , leading to uncontrolled noise amplification. We propose PRISM, an intrinsic DP mechanism for LoRA that is gauge invariant by construction, avoids bilinear noise amplification, and admits an efficient low-dimensional noise sampler. Moreover, PRISM yields a closed-form characterization for the effective intrinsic noise on , and enables stable privacy–utility trade-offs by being gauge invariant and keeping noise amplification bounded. We further characterize the noise amplification incurred by naive DP-LoRA and show that it can be unbounded, establish standard -DP guarantees for PRISM, and introduce a DP-aware, gauge-invariant adaptive update that avoids amplifying injected privacy noise under adaptive optimization, improving numerical stability in practice.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Few-Shot Parameter-Efficient Fine-Tuning is Better and Cheaper than In-Context LearningHaokun Liu, Derek Tam, Mohammed Muqeeth, Jay Mohta et al.NeurIPS 2022 · 1,483 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
Related papers
- Differentially Private Federated Low Rank Adaptation Beyond Fixed-MatrixMing Wen, Jiaqi Zhu, Yuedong Xu, Yipeng Zhou et al.NeurIPS 2025 · 6 citations
- FedSVD: Adaptive Orthogonalization for Private Federated Learning with LoRASeanie Lee, Sangwoo Park, Dong Bok Lee, Dominik Wagner et al.NeurIPS 2025 · 18 citations
- Improving LoRA in Privacy-preserving Federated LearningYoubang Sun, Zitao Li, Yaliang Li, Bolin DingICLR 2024 · 173 citations
- Efficient and Differentially Private Federated LLM Fine-Tuning on Heterogeneous ClientsNan Yan, Yuqing Li, Xiong Wang, Jing Chen et al.KDD 2026
- Benchmarking Empirical Privacy Protection for Adaptations of Large Language ModelsBartlomiej Marek, Lorenzo Rossi, Vincent Hanke, Xun Wang et al.ICLR 2026 · 8 citations
