arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.09794cs.LG

面向联邦大语言模型微调的隐私保护分割学习

Privacy-Preserving Split Learning for Federated LLM Fine-Tuning

Heng Jin, Chaoyu Zhang, Hexuan Yu, Wenjing Lou, Y. Thomas Hou

首次发表
浏览论文内容

中文总结 AI 辅助

针对联邦大语言模型微调中分割学习导致的激活值泄露输入隐私问题,提出一种学习式混淆-恢复方案,在保护参与者私有数据的同时实现强隐私保护与适度效用损失,使分割式联邦微调切实可行。

中文摘要 AI 辅助

在领域特定数据上微调大语言模型(LLM)对于下游适配至关重要。在许多部署场景中,参与者无法在本地持有完整模型,这要么是因为模型所有者保持完整模型的专有性,要么是因为参与者缺乏足够的计算资源。分割学习(Split Learning, SL)通过在参与者和服务器之间划分模型来解决这一问题,使得只有一小部分模型在本地运行。当底层数据还分布在多个具有隐私要求的机构之间时,联邦学习(Federated Learning, FL)通过仅共享模型更新而非原始数据,进一步支持跨参与者的协作训练。在这种组合设置中,每个客户端向服务器传输中间激活值,而对于大语言模型微调而言,这种交换带来了固有的隐私悖论。大语言模型的自回归特性导致传输的激活值泄露输入信息,而现有的基于扰动的防御方法在此场景下根本无效。我们通过一种学习到的混淆-恢复方案来解决这种泄露,该方案保护参与者的私有数据集,同时仍允许在服务器端训练一个可独立部署的模型。实验表明,我们的方法在实现强隐私保护的同时,仅带来适度的效用损失和系统开销,使得基于分割的联邦大语言模型微调在实践中切实可行。

英文摘要

Fine-tuning large language models (LLMs) on domain-specific data is essential for downstream adaptation. In many deployments, a participant cannot hold the complete model locally. This happens because the model owner keeps the full model proprietary, or because the participant lacks sufficient compute resources. Split Learning (SL) addresses this by partitioning the model between the participant and a server so that only a small portion runs locally. When the underlying data is additionally distributed across multiple institutions with privacy requirements, Federated Learning (FL) further enables collaborative training across participants by sharing only model updates instead of raw data. In this combined setting, each client transmits intermediate activations to the server, and for LLM fine-tuning, this exchange poses an inherent privacy paradox. The autoregressive nature of LLMs causes the transmitted activations to leak the input, and existing perturbation-based defenses are fundamentally ineffective in this setting. We address this leakage through a learned obfuscate-and-recover scheme that protects participants' private datasets while still allowing an independently deployable model to be trained on the server side. Experiments demonstrate that our approach achieves strong privacy protection with modest utility loss and system overhead, making split-based federated LLM fine-tuning practically viable.

发表机构

  • Virginia Tech(弗吉尼亚理工大学)

机构由 AI 辅助整理,请以论文原文为准。

↑