English

Differentially Private Federated Low Rank Adaptation Beyond Fixed-Matrix

Cryptography and Security 2025-07-15 v1 Artificial Intelligence

Abstract

Large language models (LLMs) typically require fine-tuning for domain-specific tasks, and LoRA offers a computationally efficient approach by training low-rank adapters. LoRA is also communication-efficient for federated LLMs when multiple users collaboratively fine-tune a global LLM model without sharing their proprietary raw data. However, even the transmission of local adapters between a server and clients risks serious privacy leakage. Applying differential privacy (DP) to federated LoRA encounters a dilemma: adding noise to both adapters amplifies synthetic noise on the model, while fixing one adapter impairs the learnability of fine-tuning. In this paper, we propose FedASK (Differentially Private Federated Low Rank Adaptation with Double Sketching) , a novel federated LoRA framework to enable effective updating of both low-rank adapters with robust differential privacy. Inspired by randomized SVD, our key idea is a two-stage sketching pipeline. This pipeline first aggregates carefully sketched, privacy-preserving local updates, and then reconstructs the global matrices on the server to facilitate effective updating of both adapters. We theoretically prove FedASK's differential privacy guarantee and its exact aggregation property. Comprehensive experiments demonstrate that FedASK consistently outperforms baseline methods across a variety of privacy settings and data distributions.

Keywords

Cite

@article{arxiv.2507.09990,
  title  = {Differentially Private Federated Low Rank Adaptation Beyond Fixed-Matrix},
  author = {Ming Wen and Jiaqi Zhu and Yuedong Xu and Yipeng Zhou and Dingding Han},
  journal= {arXiv preprint arXiv:2507.09990},
  year   = {2025}
}

Comments

23 pages, NeurIPS 2025 under review

R2 v1 2026-07-01T03:59:14.529Z