TY - GEN
T1 - Per-Attribute Privacy in Large Language Models Using Matrix-Variate Gaussian Mechanism
AU - Monir, Islam A.
AU - Ghinita, Gabriel
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025/8/28
Y1 - 2025/8/28
N2 - Large Language Models (LLMs) have become central to modern NLP applications, yet their reliance on sensitive training data introduces significant privacy risks. Traditional approaches to differential privacy, such as DP-SGD, apply uniform noise at the gradient level and treat all features equally, ignoring the inherent correlations in structured sequence data. In this work, we propose a novel forward-pass privacy mechanism that applies per-attribute differential privacy across correlated sequence inputs. Our framework leverages the Matrix-Variate Gaussian (MVG) mechanism to inject structured, directional noise during the forward computation, enabling fine-grained privacy control that aligns with attribute sensitivity. Privacy budgets are assigned on a per-token basis using an Inverse Gaussian Distribution, allowing position-aware adaptation across input sequences. To propagate these budgets through the model, we introduce a data-independent Layer-Wise Contribution Propagation (LCP) algorithm that maps input sensitivity to output features, even in transformer architectures. We validate our method on the SST-2 sentiment classification benchmark, demonstrating improved utility over existing approaches such as DPSGD and DP-Forward, particularly under strict privacy regimes. Our results highlight the benefits of structured noise in preserving utility while ensuring strong, attribute-level privacy in models trained on correlated sequential data.
AB - Large Language Models (LLMs) have become central to modern NLP applications, yet their reliance on sensitive training data introduces significant privacy risks. Traditional approaches to differential privacy, such as DP-SGD, apply uniform noise at the gradient level and treat all features equally, ignoring the inherent correlations in structured sequence data. In this work, we propose a novel forward-pass privacy mechanism that applies per-attribute differential privacy across correlated sequence inputs. Our framework leverages the Matrix-Variate Gaussian (MVG) mechanism to inject structured, directional noise during the forward computation, enabling fine-grained privacy control that aligns with attribute sensitivity. Privacy budgets are assigned on a per-token basis using an Inverse Gaussian Distribution, allowing position-aware adaptation across input sequences. To propagate these budgets through the model, we introduce a data-independent Layer-Wise Contribution Propagation (LCP) algorithm that maps input sensitivity to output features, even in transformer architectures. We validate our method on the SST-2 sentiment classification benchmark, demonstrating improved utility over existing approaches such as DPSGD and DP-Forward, particularly under strict privacy regimes. Our results highlight the benefits of structured noise in preserving utility while ensuring strong, attribute-level privacy in models trained on correlated sequential data.
UR - https://www.scopus.com/pages/publications/105030492517
U2 - 10.1109/PST65910.2025.11268877
DO - 10.1109/PST65910.2025.11268877
M3 - Conference contribution
AN - SCOPUS:105030492517
SN - 979-8-3315-0344-4
T3 - Annual Conference On Privacy Security And Trust-pst
SP - 319
EP - 328
BT - 2025 22nd Annual International Conference On Privacy, Security, And Trust, Pst
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 22nd Annual International Conference on Privacy, Security, and Trust, PST 2025
Y2 - 26 August 2025 through 28 August 2025
ER -