acceptodds
Under review as a conference paper at ICLR 2027

Window-Level Differentially Private Fine-Tuning of Vision-Language-Action Models

Abstract

Adapting vision–language–action (VLA) models to local demonstrations creates a training-use privacy risk: generated actions can reveal whether a demonstration contributed to fine-tuning. Addressing this risk requires controlling annotation influence while preserving closed-loop behavior, where each action affects the observations and decisions that follow. We study this problem through window-level differential privacy (DP) for action annotations, with visual observations, instructions, and robot states held public and fixed. We introduce , a fine-tuning recipe that couples tighter gradient clipping with noise-aware second-moment correction while retaining the VLA's native flow-matching objective. Clipping controls window contributions and the absolute Gaussian perturbation; moment correction adjusts AdamW's adaptive scaling for the known privacy-noise variance. Both changes preserve the privacy accounting of the baseline . To audit membership evidence beyond raw prediction accuracy, we complement with the (), which compares action errors against candidate-specific models trained without the annotation. Evaluating \(\pi_0.5\) across 40 tasks in four LIBERO suites, with 800 rollouts per model, achieves higher overall task success than at all seven tested privacy budgets. At \((\epsilon,\delta)=(10^9,10^-5)\), success increases from 9.25% to 46.25%, a gain of 37 percentage points and a fivefold improvement. Fixed-clipping comparisons reproduce the benefits of moment correction across two training seeds at \(\epsilon=10^8\) and \(10^9\). These results identify clipping and adaptive update scaling as consequential design choices for VLA fine-tuning under matched privacy accounting. They establish substantial optimization gains in the evaluated large-\(\epsilon\) regime, while useful control with strong privacy remains an open challenge.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.