ExplorerStatistics & MLStatistics
Research PaperResearchia:202601.29199

LoRA and Privacy: When Random Projections Help (and When They Don't)

Yaxi Hu

Abstract

We introduce the (Wishart) projection mechanism, a randomized map of the form $S \mapsto M f(S)$ with $M \sim W_d(1/r I_d, r)$ and study its differential privacy properties. For vector-valued queries $f$, we prove non-asymptotic DP guarantees without any additive noise, showing that Wishart randomness alone can suffice. For matrix-valued queries, however, we establish a sharp negative result: in the noise-free setting, the mechanism is not DP, and we demonstrate its vulnerability by implementing...

Submitted: January 29, 2026Subjects: Statistics; Statistics & ML

Description / Details

We introduce the (Wishart) projection mechanism, a randomized map of the form SMf(S)S \mapsto M f(S) with MWd(1/rId,r)M \sim W_d(1/r I_d, r) and study its differential privacy properties. For vector-valued queries ff, we prove non-asymptotic DP guarantees without any additive noise, showing that Wishart randomness alone can suffice. For matrix-valued queries, however, we establish a sharp negative result: in the noise-free setting, the mechanism is not DP, and we demonstrate its vulnerability by implementing a near perfect membership inference attack (AUC >0.99> 0.99). We then analyze a noisy variant and prove privacy amplification due to randomness and low rank projection, in both large- and small-rank regimes, yielding stronger privacy guarantees than additive noise alone. Finally, we show that LoRA-style updates are an instance of the matrix-valued mechanism, implying that LoRA is not inherently private despite its built-in randomness, but that low-rank fine-tuning can be more private than full fine-tuning at the same noise level. Preliminary experiments suggest that tighter accounting enables lower noise and improved accuracy in practice.


Source: arXiv:2601.21719v1 - http://arxiv.org/abs/2601.21719v1 PDF: https://arxiv.org/pdf/2601.21719v1 Original Link: http://arxiv.org/abs/2601.21719v1

Please sign in to join the discussion.

No comments yet. Be the first to share your thoughts!

Access Paper
View Source PDF
Submission Info
Date:
Jan 29, 2026
Topic:
Statistics & ML
Area:
Statistics
Comments:
0
Bookmark
LoRA and Privacy: When Random Projections Help (and When They Don't) | Researchia