Component-Aware Differential Privacy for Federated Multilingual Speech-LLMs
cs.CL
Submitted: 2026-09-10
Updated: 2026-09-10
Comments: Accepted in SLT2026
License: http://creativecommons.org/licenses/by/4.0/
The gist: Per-layer differential privacy (DP) clipping improves gradient fidelity in federated learning by allocating per-matrix clipping budgets proportional to parameter count.
Terminology
Abstract
Per-layer differential privacy (DP) clipping improves gradient fidelity in federated learning by allocating per-matrix clipping budgets proportional to parameter count. We show that this recipe breaks for speech large language models (speech-LLMs), when the acoustic encoder and the language decoder differ by an order of magnitude in update norm. Single-pool per-layer methods suffer cross-component budget collapse, dragging word error rate (WER) far from flat global clipping or collapsing training entirely. When the norm imbalance is milder, adaptive single-pool methods partially recover, confirming that collapse severity scales with the inter-component norm ratio. We empirically diagnose the root cause across six per-layer methods and three speech-LLM architectures. We then propose α-split, a two-pool allocation that normalises encoder and LLM parameters into independent pools, and show that joint 2 sensitivity and the original (epsilon,δ) -DP guarantee are unchanged. At architecture-calibrated α, our method recovers WER utility compared to flat DP, while granting the encoder 4.47 times tighter per-component noise protection against speaker voice-based gradient-inversion attacks at only +2.6% LLM noise overhead.
Related papers
- Exploring Solution Divergence and Its Effect on Large Language Model Problem Solving
- Ishigaki-IDS-Bench: A Benchmark for Generating Information Delivery Specification from BIM Information Requirements
- Subliminal Steering: Stronger Encoding of Hidden Signals
- MedStruct-S: A Benchmark for Key Discovery, Key-Conditioned QA and Semi-Structured Extraction from OCR Clinical Reports
- The End of Transformers? On Challenging Attention and the Rise of Sub-Quadratic Architectures
- Untangling the Mechanisms of Misleading Context in Medical Question Answering