{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T17:05:42Z","timestamp":1778864742395,"version":"3.51.4"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031965890","type":"print"},{"value":"9783031965906","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-96590-6_17","type":"book-chapter","created":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T04:57:44Z","timestamp":1750654664000},"page":"311-329","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Can Differentially Private Fine-Tuning LLMs Protect Against Privacy Attacks?"],"prefix":"10.1007","author":[{"given":"Hao","family":"Du","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Cao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,6,24]]},"reference":[{"key":"17_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M., et al.: Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 308\u2013318 (2016)","DOI":"10.1145\/2976749.2978318"},{"key":"17_CR2","unstructured":"awslabs: fast-differential-privacy: Fast, memory-efficient, scalable optimization of deep learning with differential privacy. https:\/\/github.com\/awslabs\/fast-differential-privacy (2024). v2.1 release (2024). Accessed 05 May 2025"},{"key":"17_CR3","doi-asserted-by":"crossref","unstructured":"Ben\u00a0Zaken, E., Goldberg, Y., Ravfogel, S.: BitFit: simple parameter-efficient fine-tuning for transformer-based masked language-models. In: Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics, pp.\u00a01\u20139 (2022)","DOI":"10.18653\/v1\/2022.acl-short.1"},{"key":"17_CR4","unstructured":"Bu, Z., Chiu, J., Liu, R., Zha, S., Karypis, G.: Zero redundancy distributed learning with differential privacy. arXiv preprint arXiv:2311.11822 (2023)"},{"key":"17_CR5","unstructured":"Bu, Z., Wang, Y.X., Zha, S., Karypis, G.: Differentially private bias-term fine-tuning of foundation models. In: Workshop on Trustworthy and Socially Responsible Machine Learning, NeurIPS 2022 (2022)"},{"key":"17_CR6","unstructured":"Bu, Z., Wang, Y.X., Zha, S., Karypis, G.: Differentially private optimization on large model at small cost. In: Proceedings of the 40th International Conference on Machine Learning (2023)"},{"key":"17_CR7","unstructured":"Bu, Z., Wang, Y.X., Zha, S., Karypis, G.: Differentially private optimization on large model at small cost. In: International Conference on Machine Learning, pp. 3192\u20133218. PMLR (2023)"},{"key":"17_CR8","unstructured":"Carlini, N., Liu, C., Kos, J., \u00dalfar Erlingsson, Song, D.: The secret sharer: evaluating and testing unintended memorization in neural networks (2019)"},{"issue":"6","key":"17_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3712001","volume":"57","author":"BC Das","year":"2025","unstructured":"Das, B.C., Amini, M.H., Wu, Y.: Security and privacy challenges of large language models: a survey. ACM Comput. Surv. 57(6), 1\u201339 (2025)","journal-title":"ACM Comput. Surv."},{"key":"17_CR10","unstructured":"Devlin, J.: Bert: pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018)"},{"key":"17_CR11","doi-asserted-by":"crossref","unstructured":"Dwork, C.: Differential privacy. In: International Colloquium on Automata, Languages, and Programming, pp. 1\u201312 (2006)","DOI":"10.1007\/11787006_1"},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"Feyisetan, O., Diethe, T., Drake, T.: Leveraging hierarchical representations for preserving privacy and utility in text . In: 2019 IEEE International Conference on Data Mining, pp. 210\u2013219 (2019)","DOI":"10.1109\/ICDM.2019.00031"},{"key":"17_CR13","doi-asserted-by":"crossref","unstructured":"Fu, W., Wang, H., Gao, C., Liu, G., Li, Y., Jiang, T.: Practical membership inference attacks against fine-tuned large language models via self-prompt calibration. arXiv preprint arXiv:2311.06062 (2023)","DOI":"10.52202\/079017-4290"},{"key":"17_CR14","doi-asserted-by":"crossref","unstructured":"Fu, W., Wang, H., Gao, C., Liu, G., Li, Y., Jiang, T.: Membership inference attacks against fine-tuned large language models via self-prompt calibration. In: The Thirty-Eighth Annual Conference on Neural Information Processing Systems (2024)","DOI":"10.52202\/079017-4290"},{"key":"17_CR15","unstructured":"Han, Z., Gao, C., Liu, J., Zhang, J., Zhang, S.Q.: Parameter-efficient fine-tuning for large models: a comprehensive survey. Trans. Mach. Learn. Res. (2024)"},{"key":"17_CR16","unstructured":"Hu, E.J., et al.: LoRA: low-rank adaptation of large language models. In: International Conference on Learning Representations (2022)"},{"key":"17_CR17","unstructured":"Jagannatha, A., Rawat, B.P.S., Yu, H.: Membership inference attack susceptibility of clinical language models. arXiv preprint arXiv:2104.08305 (2021)"},{"key":"17_CR18","doi-asserted-by":"crossref","unstructured":"Lester, B., Al-Rfou, R., Constant, N.: The power of scale for parameter-efficient prompt tuning. In: Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pp. 3045\u20133059 (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.243"},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Li, X.L., Liang, P.: Prefix-tuning: optimizing continuous prompts for generation. In: Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing, pp. 4582\u20134597 (2021)","DOI":"10.18653\/v1\/2021.acl-long.353"},{"key":"17_CR20","unstructured":"Li, Y., Tan, Z., Liu, Y.: Privacy-preserving prompt tuning for large language model services. arXiv preprint arXiv:2305.06212 (2023)"},{"key":"17_CR21","unstructured":"Liu, H., et al.: Few-shot parameter-efficient fine-tuning is better and cheaper than in-context learning. In: Oh, A.H., Agarwal, A., Belgrave, D., Cho, K. (eds.) Advances in Neural Information Processing Systems (2022)"},{"key":"17_CR22","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1016\/j.aiopen.2023.08.012","volume":"5","author":"X Liu","year":"2024","unstructured":"Liu, X., et al.: GPT understands, too. AI Open 5, 208\u2013215 (2024)","journal-title":"AI Open"},{"key":"17_CR23","doi-asserted-by":"crossref","unstructured":"Lukas, N., Salem, A., Sim, R., Tople, S., Wutschitz, L., Zanella-B\u00e9guelin, S.: Analyzing leakage of personally identifiable information in language models. In: 2023 IEEE Symposium on Security and Privacy, pp. 346\u2013363 (2023)","DOI":"10.1109\/SP46215.2023.10179300"},{"key":"17_CR24","unstructured":"Mangrulkar, S., Gugger, S., Debut, L., Belkada, Y., Paul, S., Bossan, B.: Peft: state-of-the-art parameter-efficient fine-tuning methods (2022). https:\/\/github.com\/huggingface\/peft"},{"key":"17_CR25","unstructured":"Marchyok, L., Carlini, N., Kurakin, A., Hong, S.: Evaluating privacy risks of parameter-efficient fine-tuning (2025)"},{"key":"17_CR26","unstructured":"Merity, S., Xiong, C., Bradbury, J., Socher, R.: Pointer sentinel mixture models (2016)"},{"key":"17_CR27","doi-asserted-by":"crossref","unstructured":"Mireshghallah, F., Uniyal, A., Wang, T., Evans, D., Berg-Kirkpatrick, T.: An empirical analysis of memorization in fine-tuned autoregressive language models. In: Goldberg, Y., Kozareva, Z., Zhang, Y. (eds.) Proceedings of the 2022 Conference on Empirical Methods in Natural Language Processing, pp. 1816\u20131826. Association for Computational Linguistics, Abu Dhabi, United Arab Emirates (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.119"},{"key":"17_CR28","doi-asserted-by":"crossref","unstructured":"Mireshghallah, F., Uniyal, A., Wang, T., Evans, D.K., Berg-Kirkpatrick, T.: An empirical analysis of memorization in fine-tuned autoregressive language models. In: EMNLP, pp. 1816\u20131826 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.119"},{"key":"17_CR29","unstructured":"Panda, A., Tang, X., Choquette-Choo, C.A., Nasr, M., Mittal, P.: Privacy auditing of large language models. In: The Thirteenth International Conference on Learning Representations (2025)"},{"key":"17_CR30","unstructured":"Radford, A., Wu, J., Child, R., Luan, D., Amodei, D., Sutskever, I.: Language models are unsupervised multitask learners (2019)"},{"key":"17_CR31","unstructured":"tsinghua-fib-lab: ANeurIPS2024_SPV-MIA: Practical Membership Inference Attacks against Fine-tuned Large Language Models via Self-prompt Calibration (2024). https:\/\/github.com\/tsinghua-fib-lab\/ANeurIPS2024_SPV-MIA. commit df01b14. Accessed 05 May 2025"},{"key":"17_CR32","unstructured":"Wang, B., Komatsuzaki, A.: GPT-J-6B: a 6 billion parameter autoregressive language model (2021). https:\/\/github.com\/kingoflolz\/mesh-transformer-jax"},{"key":"17_CR33","unstructured":"Wei, J., et al.: Finetuned language models are zero-shot learners. In: International Conference on Learning Representations (2022). https:\/\/openreview.net\/forum?id=gEZrGCozdqR"},{"key":"17_CR34","unstructured":"Wolf, T., et al.: Transformers: state-of-the-art natural language processing. In: Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing: System Demonstrations, pp. 38\u201345. Association for Computational Linguistics (2020)"},{"key":"17_CR35","unstructured":"Xu, L., Xie, H., Qin, S.Z.J., Tao, X., Wang, F.L.: Parameter-efficient fine-tuning methods for pretrained language models: A critical review and assessment. arXiv preprint arXiv:2312.12148 (2023)"},{"key":"17_CR36","unstructured":"Zhang, X., Zhao, J.J., LeCun, Y.: Character-level convolutional networks for text classification. In: NIPS (2015)"}],"container-title":["Lecture Notes in Computer Science","Data and Applications Security and Privacy XXXIX"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-96590-6_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T16:21:38Z","timestamp":1778343698000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-96590-6_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031965890","9783031965906"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-96590-6_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"24 June 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DBSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP Annual Conference on Data and Applications Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Gj\u00f8vik","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Norway","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 June 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 June 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"39","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dbsec2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.ntnu.edu\/web\/dbsec2025\/dbsec2025","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}