Skip to main navigation Skip to search Skip to main content

Per-Attribute Privacy in Large Language Models Using Matrix-Variate Gaussian Mechanism

  • Islam A. Monir*
  • , Gabriel Ghinita
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Large Language Models (LLMs) have become central to modern NLP applications, yet their reliance on sensitive training data introduces significant privacy risks. Traditional approaches to differential privacy, such as DP-SGD, apply uniform noise at the gradient level and treat all features equally, ignoring the inherent correlations in structured sequence data. In this work, we propose a novel forward-pass privacy mechanism that applies per-attribute differential privacy across correlated sequence inputs. Our framework leverages the Matrix-Variate Gaussian (MVG) mechanism to inject structured, directional noise during the forward computation, enabling fine-grained privacy control that aligns with attribute sensitivity. Privacy budgets are assigned on a per-token basis using an Inverse Gaussian Distribution, allowing position-aware adaptation across input sequences. To propagate these budgets through the model, we introduce a data-independent Layer-Wise Contribution Propagation (LCP) algorithm that maps input sensitivity to output features, even in transformer architectures. We validate our method on the SST-2 sentiment classification benchmark, demonstrating improved utility over existing approaches such as DPSGD and DP-Forward, particularly under strict privacy regimes. Our results highlight the benefits of structured noise in preserving utility while ensuring strong, attribute-level privacy in models trained on correlated sequential data.

Original languageEnglish
Title of host publication2025 22nd Annual International Conference On Privacy, Security, And Trust, Pst
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages319-328
Number of pages10
ISBN (Electronic)9798331503437
ISBN (Print)979-8-3315-0344-4
DOIs
Publication statusPublished - 28 Aug 2025
Event22nd Annual International Conference on Privacy, Security, and Trust, PST 2025 - Hybrid, Fredericton, Canada
Duration: 26 Aug 202528 Aug 2025

Publication series

NameAnnual Conference On Privacy Security And Trust-pst

Conference

Conference22nd Annual International Conference on Privacy, Security, and Trust, PST 2025
Country/TerritoryCanada
CityHybrid, Fredericton
Period26/08/2528/08/25

Fingerprint

Dive into the research topics of 'Per-Attribute Privacy in Large Language Models Using Matrix-Variate Gaussian Mechanism'. Together they form a unique fingerprint.

Cite this