当隐私损害可合并性:差分隐私下的几何感知模型合并
When Privacy Hurts Mergeability: Geometry-Aware Model Merging under Differential Privacy
- Xidian University(西安电子科技大学)
- Tianjin University(天津大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文针对差分隐私模型合并的几何障碍,提出几何感知框架DP-Merging,可提升差分隐私任务模型可合并性,在保留隐私保障的同时改善私人合并模型性能。
AI中文摘要:
模型合并有望在不访问原始任务数据的情况下,从独立微调的任务模型中构建单个多任务模型,这使得它在无法集中任务数据时颇具吸引力,但发布的任务模型仍可能泄露私人微调数据。差分隐私(Differential Privacy,DP)提供了一种限制此类泄露的原则性机制,然而其对模型合并的影响仍鲜为人知。本文研究差分隐私模型合并的几何特性,识别出两个使私人任务模型难以合并的几何障碍:一是“局部锐度(local sharpness)”,它使任务损失对合并引发的参数位移敏感;二是“参考漂移(reference drift)”,它衡量私人任务模型与共享预训练初始化之间的位移,并放大跨任务干扰。基于这些观察,我们提出了DP-Merging,这是一个几何感知框架,可提升差分隐私任务模型的可合并性。DP-Merging采用与差分隐私兼容的锐度感知目标,引导每个私人任务模型走向更平缓的损失区域,并使用基于参考的对齐正则化器,使任务模型保持接近共享的预训练初始化。我们推导了一个合并差距上界,表明降低局部曲率和参考漂移可收紧合并引发的损失增加的边界。在多个隐私预算下的视觉和语言任务实验显示,DP-Merging在保留底层差分隐私微调流程隐私保障的同时,始终提升了私人合并模型的性能。
英文摘要:
Model merging promises to construct a single multi-task model from independently fine-tuned task models without accessing the original task data. This makes it attractive when task data cannot be centralized, but released task models may still leak private fine-tuning data. Differential privacy (DP) provides a principled mechanism for limiting such leakage, yet its effect on model merging remains poorly understood. In this paper, we study the geometry of differentially private model merging and identify two geometric obstacles that make private task models difficult to merge: \emph{local sharpness}, which makes task losses sensitive to the parameter displacement induced by merging, and \emph{reference drift}, which measures the displacement of private task models from the shared pretrained initialization and amplifies cross-task interference. Based on these observations, we propose \textbf{DP-Merging}, a geometry-aware framework that improves the mergeability of differentially private task models. DP-Merging uses a DP-compatible sharpness-aware objective to guide each private task model toward flatter loss regions, and a reference-based alignment regularizer to keep task models close to the shared pretrained initialization. We derive a merge-gap upper bound showing that reducing local curvature and reference drift tightens the bound on the loss increase induced by merging. Experiments on vision and language tasks across multiple privacy budgets show that DP-Merging consistently improves private merged-model performance while preserving the privacy guarantees of the underlying DP fine-tuning procedures.