PISA: Privacy-Preserving Split Adaptation with Model IP Protection
Haocheng Yang, Xiang Cheng, ZONGDA HAN, Pengjie Wang, Changkang Chi, Pengfei Zhang, Sen Su
摘要
Fine-tuning Large Language Models (LLMs) enables data holders to construct proprietary, task-specific models by leveraging external high-performance computing infrastructure. However, existing paradigms typically address data privacy and model intellectual property (IP) in isolation, failing to simultaneously uphold both constraints. Privacy-prioritized methods compromise model IP by hosting parameters remotely, while IP-oriented collaborative schemes relying on end-to-end gradient flows inherently violate strict data privacy standards. To address these challenges, we present PISA ( P rivacy-preserving and I P-protected S plit A daptation), a split fine-tuning framework designed to preserve both data privacy and model IP while maintaining high utility. In PISA, we propose three methods: a Manifold Rectification Pre-training (MRP) method to equip the server-side model with intrinsic robustness against privacy-induced distribution shifts; a Dual-Stream Semantic Compensation (DSC) method to recover feature utility using local clean data as priors; and a Utility-Aware Gradient Rectification (UGR) method to adaptively maximize the performance of the parameter-constrained local model. Experiments on GLUE show that PISA ensures dual protection and delivers a substantial 23.0% performance gain over the privacy-prioritized baseline under strict privacy budgets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- DP-Forward: Fine-tuning and Inference on Language Models with Differential Privacy in Forward PassMinxin Du, Xiang Yue, Sherman S. M. Chow, Tianhao Wang 等CCS 2023 · 被引用 35 次
- Initialization Matters: Privacy-Utility Analysis of Overparameterized Neural NetworksJiayuan Ye, Zhenyu Zhu, Fanghui Liu, Reza Shokri 等NeurIPS 2023 · 被引用 19 次
- Unleashing the Tiger: Inference Attacks on Split LearningDario Pasquini, Giuseppe Ateniese, Massimo BernaschiCCS 2021 · 被引用 14 次
- Can Watermarks be Used to Detect LLM IP Infringement For Free?Zhengyue Zhao, Xiaogeng Liu, Somesh Jha, Patrick McDaniel 等ICLR 2025
- Split Adaptation for Pre-trained Vision TransformersLixu Wang, Bingqi Shang, Yi Li, Payal Mohapatra 等CVPR 2025
相关 Paper
- From Prompts to Responses: Dual-Sided Data Leakage and Defense in Split Large Language ModelsZixuan GU, Xiaojun Ye, Yang LiuICML 2026
- Unveiling the Vulnerability of Private Fine-Tuning in Split-Based Frameworks for Large Language Models: A Bidirectionally Enhanced AttackGuanzhong Chen, Zhenghan Qin, Mingxin Yang, Yajie Zhou 等CCS 2024 · 被引用 7 次
- DualGuard: A Parameter Space Transformation Approach for Bidirectional Defense in Split-Based LLM Fine-TuningZihan Liu, Yizhen Wang, Rui Wang, Sai WuACL 2025
- Large Language Models Can Be Contextual Privacy Protection LearnersYijia Xiao, Yiqiao Jin, Yushi Bai, Yue Wu 等EMNLP 2024 · 被引用 18 次
- Towards Privacy-Preserving Large Language Model: Text-free Inference Through Alignment and AdaptationJeongho Yoon, Chanhee Park, Yongchan Chun, Hyeonseok Moon 等ACL 2026
