acceptodds
Under review as a conference paper at ICLR 2027

Rank-Dependent DP-Noise Bounds for Frozen- LoRA

Abstract

We study differentially private SGD (DP-SGD) for frozen- LoRA, where a random factor is fixed and only is trained. Privacy accounting is dimension independent: the same noise multiplier, Poisson sampling rate, step count, adjacency convention, and accountant yield the same guarantee. Our main result is instead a utility statement for the restricted -objective: when gives , the reparameterization controls both gradient sensitivity and smoothness, and the DP-noise component of the stationarity bound scales with rather than . With inactive clipping, , and respective positive initial gaps , the ratio of the DP-noise terms is bounded by . With active clipping, method-specific bias terms remain and we do not claim an unconditional improvement in total error or practical utility. The guarantee controls , not unrestricted stationarity in -space. A Polyak–Lojasiewicz (PL) assumption is used only for excess-risk and optimal-rank results; we prove it for linear LoRA, while the informed- optimal-rank result is an oracle benchmark. We quantify, without a complete convergence theorem, the product-noise term arising when both factors are trained. A complete 1,800-run controlled synthetic matrix separates restricted error from projection error and demonstrates optimizer-dependent rank orderings; SST-2 experiments remain feasibility checks, not validation of nonlinear PL or the optimal-rank law. A completed 42-run matched-public-start BERT/SST-2 follow-up finds at most 0.153 percentage points mean accuracy difference between frozen and jointly trained factors across six private-stage settings, providing no clear practical advantage for either branch.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.