Beyond Coordinate Sparsity: Controlling Module Exposure Against Gradient Reconstruction in Federated LoRA
Abstract
Federated Low-Rank Adaptation (LoRA) reduces the communication cost of language-model fine-tuning, yet shared LoRA updates can still expose private training text to gradient-based reconstruction attacks. Existing sparsification methods primarily control how many update coordinates remain visible, but this does not capture which attack-relevant LoRA modules are exposed. We introduce module exposure to characterize this distinction and propose MU-BEC, a module-level upload-control method that uses public-data training dynamics to select a fixed subset of LoRA modules for communication. Under a matched MineGrad evaluation with the same audited attack base and 3,072 nominal retained slots, Top-k yields 95% unconditional content-token recovery, whereas MU-BEC yields 0% under both Fixed Attack and Known-Mask Attack. Mechanism analyses further show that aggressive Top-k sparsification can preserve nearly all target-gradient energy, indicating that coordinate count alone does not characterize MineGrad recovery in the evaluated setting. In normal federated training, MU-BEC reduces upload communication by 36.0% relative to Top-k and Random-k, while introducing a measurable utility trade-off. These results motivate module-level observability as a complementary perspective for analyzing privacy leakage in Federated LoRA.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.