Taming Noise-Induced Prototype Degradation for Privacy-Preserving Personalized Federated Fine-Tuning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Yuhua, Zhang, Qinnan, Li, Xiaodong, Zhang, Huan, Sun, Yifan, Qiu, Wangjie, Zhang, Hainan, Tong, Yongxin, Zheng, Zhiming
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909004509216768
author Wang, Yuhua
Zhang, Qinnan
Li, Xiaodong
Zhang, Huan
Sun, Yifan
Qiu, Wangjie
Zhang, Hainan
Tong, Yongxin
Zheng, Zhiming
author_facet Wang, Yuhua
Zhang, Qinnan
Li, Xiaodong
Zhang, Huan
Sun, Yifan
Qiu, Wangjie
Zhang, Hainan
Tong, Yongxin
Zheng, Zhiming
contents Prototype-based Personalized Federated Learning (ProtoPFL) enables efficient multi-domain adaptation by communicating compact class prototypes, but directly sharing them poses privacy risks. A common defense involves per-example $\ell_2$ clipping before prototype computation to bound sensitivity, followed by isotropic Gaussian noise to enforce Local Differential Privacy (LDP). However, Isotropic Gaussian Prototype Perturbation (IGPP) typically over-perturbs discriminative dimensions and struggles to balance the clipping threshold with representation fidelity. In this paper, we propose VPDR, a client-side privacy plug-in that seamlessly integrates into existing ProtoPFLs. Motivated by the observation that dimension-wise class variance reflects discriminability, we introduce Variance-adaptive Prototype Perturbation (VPP), which allocates less noise to discriminative subspaces, preserving semantic separability while ensuring privacy. We further develop Distillation-guided Clipping Regularization (DCR), which enables feature norms to adaptively concentrate near the predefined clipping threshold while maintaining prediction consistency. Theoretical analysis shows that our groupwise mechanism provides privacy guarantees no weaker than the isotropic baseline under the same privacy constraints. Extensive experiments on multi-domain benchmarks demonstrate that VPDR achieves a superior privacy-utility trade-off, outperforming IGPP in personalized federated fine-tuning without sacrificing robustness against realistic attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2604_27833
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Taming Noise-Induced Prototype Degradation for Privacy-Preserving Personalized Federated Fine-Tuning
Wang, Yuhua
Zhang, Qinnan
Li, Xiaodong
Zhang, Huan
Sun, Yifan
Qiu, Wangjie
Zhang, Hainan
Tong, Yongxin
Zheng, Zhiming
Computer Vision and Pattern Recognition
Machine Learning
Prototype-based Personalized Federated Learning (ProtoPFL) enables efficient multi-domain adaptation by communicating compact class prototypes, but directly sharing them poses privacy risks. A common defense involves per-example $\ell_2$ clipping before prototype computation to bound sensitivity, followed by isotropic Gaussian noise to enforce Local Differential Privacy (LDP). However, Isotropic Gaussian Prototype Perturbation (IGPP) typically over-perturbs discriminative dimensions and struggles to balance the clipping threshold with representation fidelity. In this paper, we propose VPDR, a client-side privacy plug-in that seamlessly integrates into existing ProtoPFLs. Motivated by the observation that dimension-wise class variance reflects discriminability, we introduce Variance-adaptive Prototype Perturbation (VPP), which allocates less noise to discriminative subspaces, preserving semantic separability while ensuring privacy. We further develop Distillation-guided Clipping Regularization (DCR), which enables feature norms to adaptively concentrate near the predefined clipping threshold while maintaining prediction consistency. Theoretical analysis shows that our groupwise mechanism provides privacy guarantees no weaker than the isotropic baseline under the same privacy constraints. Extensive experiments on multi-domain benchmarks demonstrate that VPDR achieves a superior privacy-utility trade-off, outperforming IGPP in personalized federated fine-tuning without sacrificing robustness against realistic attacks.
title Taming Noise-Induced Prototype Degradation for Privacy-Preserving Personalized Federated Fine-Tuning
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2604.27833