Training Privacy Is Not Inference Privacy: Evaluating Embedding Leakage in Private Federated LLM Fine-Tuning
Ruyang Xiao, Jinguo Li
Shanghai University of Electric Power
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
Privacy-preserving federated fine-tuning of large language models (LLMs) is commonly evaluated through the lens of training-time protection, typically by perturbing gradients or parameter updates with differential privacy. However, this perspective leaves a deployment-stage question underexplored: do the intermediate embeddings exposed by the resulting model remain private at inference time? We revisit this issue through a compact evaluation paper rather than a new defense proposal. Specifically, we formulate a training-vs.-inference privacy gap, define a lightweight protocol for measuring embedding inversion and client-attribute inference risk, and instantiate the protocol in a pilot federated fine-tuning study on two text classification tasks. Our observations show a consistent pattern: baselines that reduce training leakage can still expose semantically rich intermediate representations during deployment, especially when utility remains high. These findings suggest that training privacy and inference privacy should be reported as separate dimensions in privacy-preserving federated LLM systems.
逐年被引趋势
暂无年度引用数据
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIPrivacy-Preserving Technologies in Data
Cryptography and Data Security · Internet Traffic Analysis and Secure E-voting
参考文献 8
此处列出前 3 条