Skip to content
Preprint

When Privacy Hurts Mergeability: Geometry-Aware Model Merging under Differential Privacy

Aug 2026 · 0 citations · 45 references
Computer Science

TL;DR

Experiments on vision and language tasks across multiple privacy budgets show that DP-Merging consistently improves private merged-model performance while preserving the privacy guarantees of the underlying DP fine-tuning procedures.

Abstract

Model merging promises to construct a single multi-task model from independently fine-tuned task models without accessing the original task data. This makes it attractive when task data cannot be centralized, but released task models may still leak private fine-tuning data. Differential privacy (DP) provides a principled mechanism for limiting such leakage, yet its effect on model merging remains poorly understood. In this paper, we study the geometry of differentially private model merging and identify two geometric obstacles that make private task models difficult to merge: \emph{local sharpness}, which makes task losses sensitive to the parameter displacement induced by merging, and \emph{reference drift}, which measures the displacement of private task models from the shared pretrained initialization and amplifies cross-task interference. Based on these observations, we propose \textbf{DP-Merging}, a geometry-aware framework that improves the mergeability of differentially private task models. DP-Merging uses a DP-compatible sharpness-aware objective to guide each private task model toward flatter loss regions, and a reference-based alignment regularizer to keep task models close to the shared pretrained initialization. We derive a merge-gap upper bound showing that reducing local curvature and reference drift tightens the bound on the loss increase induced by merging. Experiments on vision and language tasks across multiple privacy budgets show that DP-Merging consistently improves private merged-model performance while preserving the privacy guarantees of the underlying DP fine-tuning procedures.

View source

Similar papers

#artificial intelligence Preprint Sep 2026

CASS: Contribution-Aware Structured Sparsity for Model Merging

Model merging integrates task-specific fine-tuned models into a single multi-task model, but often suffers from parameter interference caused by conflicting task-vector updates. Existing methods typically mitigate conflicts by pruning task vectors based on weight magnitude or random heuristics, treating Transformers as...

Yan Li, Gui-Ping Cao, Meng-Du Xu et al. · 0 citations
2026

Achieving Prior-Aligned Utility-Privacy Trade-Off for Data Sharing

In privacy-aware data sharing, achieving a prior-aligned trade-off between task utility and sensitive information leakage remains a critical and challenging problem. Conventional approaches typically adopt coarse-grained feature selection strategies, often sharing all attributes or fixed subsets without fine differenti...

Xue Chen, Cheng Wang, Changjun Jiang et al. · 0 citations
Preprint Aug 2026

P2Skill: Privacy Preserving Skill Distillation for Cloud-Local LLM Inference Systems

P2Skill is proposed, a prompt-based skill distillation method in which a local small language model (SLM) autonomously performs decomposition, PII-aware routing, paraphrasing, and reconstruction by following the skill prompts.

M. Ryu, Geunpyo Park, Sungjoon Lee et al. · 1 citation · ⚡1
#artificial intelligence Preprint Aug 2026

Decoupling Knowledge and Privacy: Post-Task Self-Distillation Replay for LLM Continual Learning

Privacy-preserving continual learning (PPCL) must reduce the reproduction of sensitive content while retaining useful knowledge across sequential tasks. Formal privacy guarantees characterize randomized mechanisms, whereas operational output control concerns whether a trained model selectively reduces the likelihood of...

Sheng-Tao Wen, Yun-Ying Yang, Xiang Chen et al. · 0 citations
2026

PI-SAFE: Practical Privacy-Preserving LLM Inference With Adversarial Fine-Tuning for Optimized Utility

Cloud-based Large Language Model (LLM) inference services typically require users to submit plain-text inputs, thereby posing severe privacy risks. Existing privacy-preserving paradigms are mostly task-specific and often necessitate pervasive modifications to the entire server-side model. This reliance introduces subst...

Wentao Zhong, Yu-Ting Li, Di-Cong Yu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.