SLM Privacy-Preserving Fine-Tuning

Arxiv pdf 2026-06-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

CSIRTs increasingly fine-tune language models on vulnerability scans, yet such records expose internal topology and create privacy risk under GDPR/LGPD. We present the first empirical study of how DP-SGD and HMAC pseudonymization compose when fine-tuning 13B SLMs on structured CSIRT data. Across 96 LoRA adapters over four SLMs, four regimes (raw, QLoRA with large-lot batching, DP-SGD at $\epsilon \in \{2, 8\}$, and 20 canaries audited via four extraction attacks plus a dual attack on the HMAC slug: (i) matched-update controls reproduce the memorization reduction in privacy-preserving fine-tuning by reducing optimizer updates alone (66% of the gap, mean 100%, n=3 seeds, 4 models); DP-SGD adds ($\epsilon$ contribution) without further reduction. (ii) HMAC pseudonymization removes the original identifier from the exposure surface (40% reduction) without creating a secondary target: slug exposure remains within 0.65 bits of the chance floor. (iii) F1 stays in [0.19, 0.28] across all 96 adapters and four-shot prompting, indicating a budget-conditional gap: under the evaluated regime, 13B SLMs do not reach operational F1.

Loading executive summary...

LINK COPIED TO CLIPBOARD