Unmergeable LoRA: Proactively Protecting Adapters from Unauthorized Merging
Abstract
Public LoRA adapters enable convenient capability sharing, but also allow unauthorized reuse of proprietary capabilities through model merging. Existing proactive defenses for full-model release do not transfer to the fixed-base LoRA setting, leaving released adapters effectively unprotected against unauthorized merging. In this work, we propose LoRA Preservation-Barrier Hardening (LoRA-PBH), a release-time defense that directly protects adapters against post-release merging while preserving their standalone performance. Instead of modifying model representations that become ineffective under LoRA merging, LoRA-PBH optimizes the released adapter to make unauthorized merged models retain little defender performance without requiring changes to the public base model or knowledge of future attacker adapters. Experiments on vision, language, and diffusion models demonstrate that LoRA-PBH consistently preserves standalone performance while substantially degrading merged performance across multiple backbones, merging methods, merge coefficients, and multi-adapter settings. Code is included in the supplementary material.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.