使用同态加密对开源 LLM 进行私有 LoRA 微调
Private LoRA Fine-tuning of Open-Source LLMs with Homomorphic Encryption
- institutetext: Zama(Zama)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文提出结合 LoRA、同态加密与远程工作节点的开源 LLM 私有微调协议,并在 Llama-3.2-1B 上验证其可行性。
AI中文摘要:
在开源大型语言模型(LLM)微调过程中保护数据机密性,对于敏感应用至关重要。本工作提出一种交互式协议,将低秩适配(LoRA)技术用于私有微调。同态加密(HE)保护由远程工作节点处理的训练数据和梯度的机密性;这些节点承担涉及基础模型权重的大部分计算。数据所有者负责编排训练,只需要极少的本地计算能力和内存,从而缓解了对昂贵客户端 GPU 的需求。我们通过微调 Llama-3.2-1B 模型证明了可行性,给出了使用兼容 HE 的量化得到的收敛结果,以及在 GPU 硬件上进行 HE 计算的性能基准。该方法支持多种应用,例如机密知识库问答、面向 AI 代码助手的私有代码库微调、基于公司电子邮件归档草拟邮件的 AI 智能体,以及调整模型以分析敏感法律或医疗文档。
英文摘要:
Preserving data confidentiality during the fine-tuning of open-source Large Language Models (LLMs) is crucial for sensitive applications. This work introduces an interactive protocol adapting the Low-Rank Adaptation (LoRA) technique for private fine-tuning. Homomorphic Encryption (HE) protects the confidentiality of training data and gradients handled by remote worker nodes performing the bulk of computations involving the base model weights. The data owner orchestrates training, requiring minimal local computing power and memory, thus alleviating the need for expensive client-side GPUs. We demonstrate feasibility by fine-tuning a Llama-3.2-1B model, presenting convergence results using HE-compatible quantization and performance benchmarks for HE computations on GPU hardware. This approach enables applications such as confidential knowledge base question answering, private codebase fine-tuning for AI code assistants, AI agents for drafting emails based on a company's email archive, and adapting models to analyze sensitive legal or healthcare documents.