{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,10]],"date-time":"2026-02-10T17:03:30Z","timestamp":1770743010895,"version":"3.49.0"},"publisher-location":"Singapore","reference-count":39,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819534616","type":"print"},{"value":"9789819534623","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T00:00:00Z","timestamp":1760659200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T00:00:00Z","timestamp":1760659200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-3462-3_8","type":"book-chapter","created":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T17:20:09Z","timestamp":1760635209000},"page":"100-113","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Differentially Private Fine-Tuning of\u00a0Large Language Models: A Survey"],"prefix":"10.1007","author":[{"given":"Manjiang","family":"Yu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Priyanka","family":"Singh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,17]]},"reference":[{"key":"8_CR1","unstructured":"Brown, T., et al.: Language models are few-shot learners. Adv. Neural Inf. Process. Syst. 33, 1877\u20131901 (2020)"},{"key":"8_CR2","unstructured":"Touvron, H., et al.: LLaMA: open and efficient foundation language models (2023). arXiv:2302.13971"},{"key":"8_CR3","unstructured":"Chowdhery, A., et al.: PaLM: scaling language modeling with pathways (2022). arXiv:2204.02311"},{"key":"8_CR4","doi-asserted-by":"publisher","unstructured":"Abadi, M., et al.: Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (2016). https:\/\/doi.org\/10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"8_CR5","doi-asserted-by":"crossref","unstructured":"Dwork, C.: Differential privacy. International Colloquium on Automata, Languages, and Programming, pp. 1\u201312 (2006)","DOI":"10.1007\/11787006_1"},{"key":"8_CR6","doi-asserted-by":"crossref","unstructured":"Du, H.,\u00a0Liu, S.,\u00a0Cao, Y.: Can differentially private fine-tuning LLMs protect against privacy attacks? In: Proceedings of the IFIP Annual Conference on Data and Applications Security and Privacy (DBSec), pp.\u00a0311\u2013329. Springer (2025)","DOI":"10.1007\/978-3-031-96590-6_17"},{"key":"8_CR7","doi-asserted-by":"crossref","unstructured":"Du, H.,\u00a0Liu, S.,\u00a0Zheng, L.,\u00a0Cao, Y., Nakamura, A.,\u00a0Chen, L.: Privacy in fine-tuning large language models: attacks, defenses, and future directions. In: Proceedings of the Pacific-Asia Conference on Knowledge Discovery and Data Mining (PAKDD), pp.\u00a0326\u2013344. Springer (2025)","DOI":"10.1007\/978-981-96-8183-9_25"},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"Mironov, I.: R\u00e9nyi differential privacy. In: 2017 IEEE 30th Computer Security Foundations Symposium (CSF), pp. 263\u2013275. IEEE (2017)","DOI":"10.1109\/CSF.2017.11"},{"key":"8_CR9","unstructured":"Devlin, J., Chang, M.-W., Lee, K., Toutanova, K.: BERT: pre-training of deep bidirectional transformers for language understanding. In: Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics (NAACL-HLT), pp. 4171\u20134186 (2019). arXiv:1810.04805"},{"key":"8_CR10","unstructured":"Dupuy, C., Arava, R., Gupta, R., Rumshisky, A.: An efficient DP-SGD mechanism for large scale NLP models. CoRR. abs\/2107.14586 (2021). arXiv:2107.14586"},{"key":"8_CR11","doi-asserted-by":"crossref","unstructured":"Dupuy, C., Arava, R., Gupta, R., Rumshisky, A.: An efficient DP-SGD mechanism for large scale NLP models. arXiv:2107.14586 (2021)","DOI":"10.1109\/ICASSP43922.2022.9746975"},{"key":"8_CR12","unstructured":"Wang, H., Gao, S., Zhang, H., Shen, M., Su, W.J.: Analytical composition of differential privacy via the Edgeworth accountant. arXiv:2206.04236 (2022)"},{"key":"8_CR13","doi-asserted-by":"crossref","unstructured":"Behnia, R., Ebrahimi, M., Pacheco, J., Padmanabhan, B.: EW-tune: a framework for privately fine-tuning large language models with differential privacy. CoRR (2022)","DOI":"10.1109\/ICDMW58026.2022.00078"},{"key":"8_CR14","unstructured":"Wang, L., Wang, J., Ren, J., Xiang, Z., Keyes, D.E., Wang, D.: FlashDP: memory-efficient and high-throughput DP-SGD training for large language models. In: Proceedings of the Adaptive Foundation Models Workshop at NeurIPS (2024)"},{"key":"8_CR15","unstructured":"Yu, D., Zhang, H., Chen, W., Yin, J., Liu, T.: Large scale private learning via low-rank reparametrization. In: Proceedings of the 38th International Conference on Machine Learning, vol. 139, pp. 12208\u201312218 (2021). https:\/\/proceedings.mlr.press\/v139\/yu21f.html"},{"key":"8_CR16","unstructured":"Yu, D., et al.: Differentially private fine-tuning of language models. In: International Conference on Learning Representations (2022). https:\/\/openreview.net\/forum?id=Q42f0dfjECO"},{"key":"8_CR17","unstructured":"Li, X., Tram\u00e8r, F., Liang, P., Hashimoto, T.: Large language models can be strong differentially private learners. CoRR. abs\/2110.05679 (2021). arXiv:2110.05679"},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"Shi, W., Shea, R., Chen, S., Zhang, C., Jia, R., Yu, Z.: Just fine-tune twice: selective differential privacy for large language models (2022). arXiv:2204.07667","DOI":"10.18653\/v1\/2022.emnlp-main.425"},{"key":"8_CR19","unstructured":"Shi, W., Cui, A., Li, E., Jia, R., Yu, Z.: Selective differential privacy for language modeling. CoRR. abs\/2108.12944 (2021). arXiv:2108.12944"},{"issue":"1","key":"8_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4236\/jsea.2024.171001","volume":"17","author":"T Singh","year":"2024","unstructured":"Singh, T., Aditya, H., Madisetti, V.K., Bahga, A.: Whispered tuning: data privacy preservation in fine-tuning LLMs through differential privacy. J. Softw. Eng. Appl. 17(1), 1\u201322 (2024). https:\/\/doi.org\/10.4236\/jsea.2024.171001","journal-title":"J. Softw. Eng. Appl."},{"key":"8_CR21","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2024.121000","volume":"678","author":"T Wang","year":"2024","unstructured":"Wang, T., Zhai, L., Yang, T., Luo, Z., Liu, S.: Selective privacy-preserving framework for large language models fine-tuning. Inf. Sci. 678, 121000 (2024). https:\/\/doi.org\/10.1016\/j.ins.2024.121000","journal-title":"Inf. Sci."},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"Wu, X., Gong, L., Xiong, D.: Adaptive differential privacy for language modeling. In: Proceedings of the First Workshop on Federated Learning for Natural Language Processing (FL4NLP), pp. 21\u201326. Association for Computational Linguistics (2022). https:\/\/aclanthology.org\/2022.fl4nlp-1.3\/","DOI":"10.18653\/v1\/2022.fl4nlp-1.3"},{"key":"8_CR23","unstructured":"Liu, Y., et al.: RoBERTa: a robustly optimized BERT pretraining approach, arXiv preprint arXiv:1907.11692 (2019)"},{"key":"8_CR24","unstructured":"Radford, A., Wu, J., Child, R., Luan, D., Amodei, D., Sutskever, I.: Language models are unsupervised multitask learners. OpenAI Blog (2019). https:\/\/cdn.openai.com\/better-language-models\/language_models_are_unsupervised_multitask_learners.pdf"},{"key":"8_CR25","unstructured":"Hu, E., et al.: LoRA: low-rank adaptation of large language models. In: International Conference on Learning Representations (ICLR) (2022). arXiv:2106.09685"},{"key":"8_CR26","unstructured":"Mahabadi, R.N., Henderson, J., Ruder, S.: Compacter: efficient low-rank hypercomplex adapter layers. In: Advances in Neural Information Processing Systems (NeurIPS), pp. 1022\u20131035 (2021). arXiv:2106.04647"},{"key":"8_CR27","doi-asserted-by":"crossref","unstructured":"Williams, A., Nangia, N., Bowman, S.R.: A broad-coverage challenge corpus for sentence understanding through inference. In: Proceedings of the 2018 Conference of the North American Chapter of the Association for Computational Linguistics (NAACL), pp. 1112\u20131122 (2018)","DOI":"10.18653\/v1\/N18-1101"},{"key":"8_CR28","doi-asserted-by":"crossref","unstructured":"Socher, R., et al.: Recursive deep models for semantic compositionality over a sentiment treebank. In: Proceedings of the 2013 Conference on Empirical Methods in Natural Language Processing (EMNLP), pp. 1631\u20131642 (2013)","DOI":"10.18653\/v1\/D13-1170"},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"Li, X., Zmigrod, R., Ma, Z., Liu, X., Zhu, X.: Fine-tuning language models with differential privacy through adaptive noise allocation (2024). arXiv preprint arXiv:2410.02912","DOI":"10.18653\/v1\/2024.findings-emnlp.491"},{"key":"8_CR30","doi-asserted-by":"crossref","unstructured":"Yue, X., et al.: A simple and practical recipe, synthetic text generation with differential privacy (2023). arXiv:2210.1434","DOI":"10.18653\/v1\/2023.acl-long.74"},{"key":"8_CR31","unstructured":"Charles, Z., et al.: Fine-tuning large language models with user-level differential privacy (2024). arXiv:2407.07737"},{"key":"8_CR32","unstructured":"Houlsby, N., et al.: Parameter-efficient transfer learning for NLP. In: Proceedings of the 36th International Conference on Machine Learning (ICML), pp. 2790\u20132799 (2019). http:\/\/proceedings.mlr.press\/v97\/houlsby19a.html"},{"key":"8_CR33","doi-asserted-by":"crossref","unstructured":"Al Aziz, M.M., Ahmed, T., Faequa, T., Jiang, X., Yao, Y., Mohammed, N.: Differentially private medical texts generation using generative neural networks. ACM Trans. Comput. Healthc. 3(1), 5:1\u20135:27 (2022)","DOI":"10.1145\/3469035"},{"key":"8_CR34","doi-asserted-by":"publisher","unstructured":"Lee, S., S\u00f8gaard, A.: Private meeting summarization without performance loss. In: Proceedings of the 46th International ACM SIGIR Conference on Research and Development in Information Retrieval, pp. 2282-2286 (2023). https:\/\/doi.org\/10.1145\/3539618.3592042","DOI":"10.1145\/3539618.3592042"},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"Huang, Y., Song, Z., Chen, D., Li, K., Arora, S.: TextHide: tackling data privacy in language understanding tasks. In: Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP) (2020). arXiv:2010.06053","DOI":"10.18653\/v1\/2020.findings-emnlp.123"},{"key":"8_CR36","unstructured":"Chua, L., et al.: Mind the privacy unit! user-level differential privacy for language model fine-tuning. In: Proceedings of the Conference on Language Models (COLM) (2024). arXiv:2406.14322"},{"key":"8_CR37","unstructured":"Tian, Z., Zhao, Y., Huang, Z., Wang, Y.-X., Zhang, N.L., He, H.: SeqPATE: differentially private text generation via knowledge distillation. In: Advances in Neural Information Processing Systems (NeurIPS) (2022). arXiv:2210.04768"},{"key":"8_CR38","doi-asserted-by":"crossref","unstructured":"Mireshghallah, F., Su, Y., Hashimoto, T., Eisner, J., Shin, R.: Privacy-preserving domain adaptation of semantic parsers. arXiv preprint arXiv:2212.10520 (2023)","DOI":"10.18653\/v1\/2023.acl-long.271"},{"key":"8_CR39","doi-asserted-by":"crossref","unstructured":"Wang, A., Singh, A., Michael, J., Hill, F., Levy, O., Bowman, S.: GLUE: a multi-task benchmark and analysis platform for natural language understanding. In: Proceedings of the 2018 EMNLP Workshop BlackboxNLP: Analyzing and Interpreting Neural Networks for NLP, pp. 353\u2013355 (2018). https:\/\/aclanthology.org\/W18-5446","DOI":"10.18653\/v1\/W18-5446"}],"container-title":["Lecture Notes in Computer Science","Advanced Data Mining and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-3462-3_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T22:05:12Z","timestamp":1760738712000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-3462-3_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,17]]},"ISBN":["9789819534616","9789819534623"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-3462-3_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,17]]},"assertion":[{"value":"17 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ADMA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Advanced Data Mining and Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kyoto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"adma2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/adma2025.github.io\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}