Taming Noise-Induced Prototype Degradation for Privacy-Preserving Personalized Federated Fine-Tuning

📅 2026-04-30
📈 Citations: 0
Influential: 0
📄 PDF

career value

238K/year
🤖 AI Summary
This work addresses the privacy-utility trade-off in prototype-based personalized federated learning, where directly sharing class prototypes risks privacy leakage and existing isotropic Gaussian perturbation methods struggle to balance privacy preservation with representation fidelity. To this end, the authors propose VPDR, a client-side privacy plugin that introduces Variance-adaptive Prototype Perturbation (VPP), which dynamically allocates noise intensity according to dimension-wise class variances. VPDR further incorporates Distillation-guided Clipping Regularization (DCR) to encourage feature norms to adaptively concentrate near the clipping threshold. Evaluated under the local differential privacy framework, the proposed method significantly enhances model utility, outperforms existing perturbation strategies across multiple benchmark domains, and maintains robustness against realistic attacks, thereby achieving a superior privacy-utility trade-off.
📝 Abstract
Prototype-based Personalized Federated Learning (ProtoPFL) enables efficient multi-domain adaptation by communicating compact class prototypes, but directly sharing them poses privacy risks. A common defense involves per-example $\ell_2$ clipping before prototype computation to bound sensitivity, followed by isotropic Gaussian noise to enforce Local Differential Privacy (LDP). However, Isotropic Gaussian Prototype Perturbation (IGPP) typically over-perturbs discriminative dimensions and struggles to balance the clipping threshold with representation fidelity. In this paper, we propose VPDR, a client-side privacy plug-in that seamlessly integrates into existing ProtoPFLs. Motivated by the observation that dimension-wise class variance reflects discriminability, we introduce Variance-adaptive Prototype Perturbation (VPP), which allocates less noise to discriminative subspaces, preserving semantic separability while ensuring privacy. We further develop Distillation-guided Clipping Regularization (DCR), which enables feature norms to adaptively concentrate near the predefined clipping threshold while maintaining prediction consistency. Theoretical analysis shows that our groupwise mechanism provides privacy guarantees no weaker than the isotropic baseline under the same privacy constraints. Extensive experiments on multi-domain benchmarks demonstrate that VPDR achieves a superior privacy-utility trade-off, outperforming IGPP in personalized federated fine-tuning without sacrificing robustness against realistic attacks.
Problem

Research questions and friction points this paper is trying to address.

Prototype Degradation
Privacy-Preserving
Personalized Federated Learning
Noise Perturbation
Differential Privacy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Variance-adaptive Prototype Perturbation
Distillation-guided Clipping Regularization
Local Differential Privacy
Prototype-based Personalized Federated Learning
Privacy-Utility Trade-off
🔎 Similar Papers
No similar papers found.
Yuhua Wang
Yuhua Wang
Ford Foundation Professor of Modern China Studies at Harvard University
Political Science
Q
Qinnan Zhang
School of Artificial Intelligence, Beihang University
X
Xiaodong Li
School of Statistics, Renmin University of China
H
Huan Zhang
School of Artificial Intelligence, Beihang University
Y
Yifan Sun
School of Statistics, Renmin University of China
W
Wangjie Qiu
School of Artificial Intelligence, Beihang University
Hainan Zhang
Hainan Zhang
Beihang University
Dialogue GenerationText GenerationFederated LearningNatural Language Processing
Y
Yongxin Tong
School of Computer Science and Engineering, Beihang University
Z
Zhiming Zheng
School of Artificial Intelligence, Beihang University