{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:FMBNGL5BHN4P4EPXKVZTVWZV7J","short_pith_number":"pith:FMBNGL5B","schema_version":"1.0","canonical_sha256":"2b02d32fa13b78fe11f755733adb35fa40d5b9f49d7e14a5405acc6dac5da52d","source":{"kind":"arxiv","id":"2407.07737","version":1},"attestation_state":"computed","paper":{"title":"Fine-Tuning Large Language Models with User-Level Differential Privacy","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.CR","cs.DC"],"primary_cat":"cs.LG","authors_text":"Arun Ganesh, H. Brendan McMahan, Keith Rush, Krishna Pillutla, Nicole Mitchell, Ryan McKenna, Zachary Charles","submitted_at":"2024-07-10T15:07:58Z","abstract_excerpt":"We investigate practical and scalable algorithms for training large language models (LLMs) with user-level differential privacy (DP) in order to provably safeguard all the examples contributed by each user. We study two variants of DP-SGD with: (1) example-level sampling (ELS) and per-example gradient clipping, and (2) user-level sampling (ULS) and per-user gradient clipping. We derive a novel user-level DP accountant that allows us to compute provably tight privacy guarantees for ELS. Using this, we show that while ELS can outperform ULS in specific settings, ULS generally yields better resul"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.07737","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-07-10T15:07:58Z","cross_cats_sorted":["cs.CL","cs.CR","cs.DC"],"title_canon_sha256":"c9e1bd5558c147c16e080701dbeb7668d62423162eca97eac373b52f63ce3859","abstract_canon_sha256":"b7b02dbe15f4f016e3addb71c9576a6abf7dce66275e11e10b2ed14e574db59a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:42:24.616619Z","signature_b64":"YRrgsZkq7RpRLfJTZxT7G0TjVUziBPqvJ9VEVTjUSqUB5s+DN9vdDNx0rGLZt0CcXhOQAKMINQja2LaT7gsFDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2b02d32fa13b78fe11f755733adb35fa40d5b9f49d7e14a5405acc6dac5da52d","last_reissued_at":"2026-07-05T08:42:24.616136Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:42:24.616136Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Fine-Tuning Large Language Models with User-Level Differential Privacy","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.CR","cs.DC"],"primary_cat":"cs.LG","authors_text":"Arun Ganesh, H. Brendan McMahan, Keith Rush, Krishna Pillutla, Nicole Mitchell, Ryan McKenna, Zachary Charles","submitted_at":"2024-07-10T15:07:58Z","abstract_excerpt":"We investigate practical and scalable algorithms for training large language models (LLMs) with user-level differential privacy (DP) in order to provably safeguard all the examples contributed by each user. We study two variants of DP-SGD with: (1) example-level sampling (ELS) and per-example gradient clipping, and (2) user-level sampling (ULS) and per-user gradient clipping. We derive a novel user-level DP accountant that allows us to compute provably tight privacy guarantees for ELS. Using this, we show that while ELS can outperform ULS in specific settings, ULS generally yields better resul"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.07737","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.07737/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.07737","created_at":"2026-07-05T08:42:24.616199+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.07737v1","created_at":"2026-07-05T08:42:24.616199+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.07737","created_at":"2026-07-05T08:42:24.616199+00:00"},{"alias_kind":"pith_short_12","alias_value":"FMBNGL5BHN4P","created_at":"2026-07-05T08:42:24.616199+00:00"},{"alias_kind":"pith_short_16","alias_value":"FMBNGL5BHN4P4EPX","created_at":"2026-07-05T08:42:24.616199+00:00"},{"alias_kind":"pith_short_8","alias_value":"FMBNGL5B","created_at":"2026-07-05T08:42:24.616199+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.09145","citing_title":"PrivCode++: Latent-Conditioned Differentially Private Code Generation for Comprehensive Guarantees","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2509.12958","citing_title":"Forget What's Sensitive, Remember What Matters: Token-Level Differential Privacy in Memory Sculpting for Continual Learning","ref_index":7,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J","json":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J.json","graph_json":"https://pith.science/api/pith-number/FMBNGL5BHN4P4EPXKVZTVWZV7J/graph.json","events_json":"https://pith.science/api/pith-number/FMBNGL5BHN4P4EPXKVZTVWZV7J/events.json","paper":"https://pith.science/paper/FMBNGL5B"},"agent_actions":{"view_html":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J","download_json":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J.json","view_paper":"https://pith.science/paper/FMBNGL5B","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.07737&json=true","fetch_graph":"https://pith.science/api/pith-number/FMBNGL5BHN4P4EPXKVZTVWZV7J/graph.json","fetch_events":"https://pith.science/api/pith-number/FMBNGL5BHN4P4EPXKVZTVWZV7J/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J/action/timestamp_anchor","attest_storage":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J/action/storage_attestation","attest_author":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J/action/author_attestation","sign_citation":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J/action/citation_signature","submit_replication":"https://pith.science/pith/FMBNGL5BHN4P4EPXKVZTVWZV7J/action/replication_record"}},"created_at":"2026-07-05T08:42:24.616199+00:00","updated_at":"2026-07-05T08:42:24.616199+00:00"}