arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.05770cs.LGcs.CL

RAPTOR:面向混合专家模型的角色感知私有训练

RAPTOR: Role-Aware Private Training for Mixture-of-Experts

Duc Dm, Khai Le-Duc, Nguyen Do, Minh Son Hoang, Florent Draye, Thai Hoang, Hoang Phuong Dam, Jiarui Liu, Chris Ngo, Terry Jingchen Zhang, Anh Le Duc Tran, Nhat … 展开作者

Duc Dm, Khai Le-Duc, Nguyen Do, Minh Son Hoang, Florent Draye, Thai Hoang, Hoang Phuong Dam, Jiarui Liu, Chris Ngo, Terry Jingchen Zhang, Anh Le Duc Tran, Nhat Do Minh, Minh Ngoc Le, My T. Thai, Ran Xu, Silvio Savarese, Mona Diab, Bernhard Schölkopf, Zhijing Jin, Huy L. Nguyen, Daeyoung Kim

首次发表
浏览论文内容

中文总结 AI 辅助

针对差分隐私微调中稀疏混合专家模型被当作稠密块处理导致的三种失败模式,提出角色感知私有训练框架RAPTOR,通过专家特定裁剪、噪声和公共分母等机制,在多个隐私级别上提升性能。

中文摘要 AI 辅助

差分隐私(DP)微调方法将稀疏混合专家(MoE)模型视为一个单一的稠密块,忽略了共享层会看到所有数据,而专家层只看到被路由的记录。我们识别并正式刻画了由此产生的三种失败模式:全局裁剪抑制了专家梯度,批级归一化稀释了稀疏专家更新,固定的隐私噪声降低了低负载专家的信噪比。我们提出了RAPTOR——一个角色感知的私有训练框架,它交替进行共享和专家优化,并直接针对每种失败模式,使用专家特定的裁剪和噪声,以及一个公共的期望归属者分母和一个与计数无关的更新调度,该调度避免依赖于私有的、实际实现的专家计数。我们证明了所提出的机制满足$(\varepsilon,\delta)$-DP:因为每条记录被分配给恰好一个归属专家,层内的每个专家机制并行组合,因此在隐私方面,更新所有$E$个专家的成本不超过更新一个专家的成本,而共享和专家流在训练过程中顺序组合。我们进一步推导了公共分母估计器的偏差-方差分解,表明其偏差随路由不平衡度可预测地增长,从而产生一个无隐私的规则,用于选择保护哪一层免受在小公共语料库上测量的路由熵的影响。在Switch Transformer和OLMoE上对GLUE任务进行微调,以及在DeepSeek-VL2-Tiny上的实验表明,在多个隐私级别($\varepsilon$)上,与标准DP基线相比,性能持续提升,最大的提升幅度通常出现在最严格的预算下。代码和模型公开可用:此https URL

英文摘要

Differentially private (DP) fine-tuning methods treat sparse Mixture-of-Experts (MoE) models as a single dense block, ignoring that shared layers see all data while experts only see routed records. We identify and formally characterize three resulting failure modes: global clipping suppresses expert gradients, batch-level normalization dilutes sparse expert updates, and fixed privacy noise degrades signal-to-noise ratio on low-load experts. We introduce RAPTOR - a Role-Aware Private Training framework, which alternates shared and expert optimization and targets each failure directly, using expert-specific clipping and noise together with a public expected-owner denominator and a count-independent update schedule that avoids conditioning on private, realized expert counts. We prove the resulting mechanism satisfies $(\varepsilon,δ)$-DP: because each record is assigned to exactly one owner expert, per-expert mechanisms within a layer compose in parallel, so updating all $E$ experts costs no more, in privacy terms, than updating one, with shared and expert streams composing sequentially across training. We further derive a bias-variance decomposition of the public-denominator estimator showing its bias grows predictably with routing imbalance, yielding a privacy-free rule for selecting which layer to protect from routing entropy measured on a small public corpus. Experiments on Switch Transformer and OLMoE fine-tuning across GLUE tasks, and on DeepSeek-VL2-Tiny, show consistent gains over standard DP baselines across several privacy levels ($\varepsilon$), with the largest margins typically at the tightest budgets. Code and models are publicly available: https://github.com/leduckhai/RAPTOR

发表机构

  • Vector Institute(向量研究所)
  • Knovel Engineering Lab(Knovel 工程实验室)
  • KAIST(韩国科学技术院)
  • MPI for Intelligent Systems, Tübingen(马克斯·普朗克智能系统研究所(蒂宾根))
  • Salesforce AI Research(Salesforce AI 研究院)
  • Carnegie Mellon University(卡内基梅隆大学)
  • University of Toronto(多伦多大学)
  • University of Oxford(牛津大学)
  • Jinesis Lab, University of Toronto & Vector Institute(多伦多大学与向量研究所 Jinesis 实验室)
  • Hanoi University of Science and Technology(河内理工大学)
  • Vietnam National University, Hanoi(越南河内国家大学)
  • University of Florida(佛罗里达大学)
  • Stanford University(斯坦福大学)
  • ELLIS Institute Tübingen(ELLIS 蒂宾根研究所)
  • Northeastern University(东北大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑